SAA-C03 Design Secure Architectures Practice Question
A company is hosting a multi-tier web application on AWS using Amazon EC2 instances in a private subnet behind an Application Load Balancer (ALB). The security team requires that all incoming web traffic is encrypted in transit from the client to the ALB and from the ALB to the backend EC2 instances. Which combination of configurations meets these requirements?
⚠ Common exam trap
SAA-C03 often tests the misconception that an HTTPS listener alone encrypts the entire path; candidates forget that the ALB-to-backend connection is separate and must also be configured for HTTPS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an HTTPS listener on the ALB using an ACM certificate and configure the backend instances to accept HTTPS traffic.
To encrypt traffic from client to ALB, an HTTPS listener with an ACM certificate is required. To encrypt traffic from ALB to backend EC2 instances, the backend must accept HTTPS (TLS) traffic, which means the ALB target group protocol must be HTTPS and the instances must have certificates installed and be listening on the HTTPS port. Option C is the only one that satisfies both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an HTTP listener on the ALB and configure the backend instances to accept HTTP traffic on port 80.
Why it's wrong here
Configuring plain HTTP listeners on the Application Load Balancer leaves traffic entirely unencrypted between the client and the load balancer, which violates core encryption in transit mandates required by modern enterprise security compliance frameworks and regulatory standards.
- ✗
Configure an HTTPS listener on the ALB and route traffic to the backend instances using HTTP on port 80.
Why it's wrong here
While an HTTPS listener secures traffic between the client and the ALB, routing plaintext HTTP from the ALB to backend EC2 instances leaves the internal network segment vulnerable to packet sniffing, failing the strict requirement for end-to-end encryption.
- ✓
Configure an HTTPS listener on the ALB using an ACM certificate and configure the backend instances to accept HTTPS traffic.
Why this is correct
Deploying an HTTPS listener on the ALB terminates client TLS securely using certificates managed by AWS Certificate Manager, while forwarding traffic over HTTPS to backend instances satisfies the explicit requirement for comprehensive end-to-end encryption across all application tiers.
- ✗
Configure a TCP listener on the ALB and install self-signed certificates directly on the target EC2 instances.
Why it's wrong here
A TCP listener cannot terminate TLS, so client-to-ALB encryption is absent. Self-signed certificates on instances also fail public trust requirements. TCP listeners suit non-HTTP protocols such as SMTP or database traffic, where end-to-end TLS passthrough is genuinely needed and certificate management on targets is acceptable.
Visual reference
About these practice questions
One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.