Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A company is hosting a multi-tier web application on AWS using Amazon EC2 instances in a private subnet behind an Application Load Balancer (ALB). The security team requires that all incoming web traffic is encrypted in transit from the client to the ALB and from the ALB to the backend EC2 instances. Which combination of configurations meets these requirements?

⚠ Common exam trap

SAA-C03 often tests the misconception that an HTTPS listener alone encrypts the entire path; candidates forget that the ALB-to-backend connection is separate and must also be configured for HTTPS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an HTTPS listener on the ALB using an ACM certificate and configure the backend instances to accept HTTPS traffic.

To encrypt traffic from client to ALB, an HTTPS listener with an ACM certificate is required. To encrypt traffic from ALB to backend EC2 instances, the backend must accept HTTPS (TLS) traffic, which means the ALB target group protocol must be HTTPS and the instances must have certificates installed and be listening on the HTTPS port. Option C is the only one that satisfies both requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an HTTP listener on the ALB and configure the backend instances to accept HTTP traffic on port 80.

    Why it's wrong here

    Configuring plain HTTP listeners on the Application Load Balancer leaves traffic entirely unencrypted between the client and the load balancer, which violates core encryption in transit mandates required by modern enterprise security compliance frameworks and regulatory standards.

  • ✗

    Configure an HTTPS listener on the ALB and route traffic to the backend instances using HTTP on port 80.

    Why it's wrong here

    While an HTTPS listener secures traffic between the client and the ALB, routing plaintext HTTP from the ALB to backend EC2 instances leaves the internal network segment vulnerable to packet sniffing, failing the strict requirement for end-to-end encryption.

  • ✓

    Configure an HTTPS listener on the ALB using an ACM certificate and configure the backend instances to accept HTTPS traffic.

    Why this is correct

    Deploying an HTTPS listener on the ALB terminates client TLS securely using certificates managed by AWS Certificate Manager, while forwarding traffic over HTTPS to backend instances satisfies the explicit requirement for comprehensive end-to-end encryption across all application tiers.

  • ✗

    Configure a TCP listener on the ALB and install self-signed certificates directly on the target EC2 instances.

    Why it's wrong here

    A TCP listener cannot terminate TLS, so client-to-ALB encryption is absent. Self-signed certificates on instances also fail public trust requirements. TCP listeners suit non-HTTP protocols such as SMTP or database traffic, where end-to-end TLS passthrough is genuinely needed and certificate management on targets is acceptable.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.