SAA-C03 Design Secure Architectures Practice Question
A company's security team identifies that its public-facing web application is being targeted by SQL injection and cross-site scripting (XSS) attacks. The application is running on EC2 instances behind an Application Load Balancer (ALB). Which service should the solutions architect implement to protect the application from these specific web-based attacks?
⚠ Common exam trap
SAA-C03 often tests the confusion between AWS WAF (Layer 7 application attacks like SQLi/XSS) and AWS Shield (Layer 3/4 DDoS), causing candidates to pick Shield Advanced when the question explicitly names web exploits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF
AWS WAF is purpose-built to inspect HTTP/HTTPS requests at Layer 7 and block application-layer exploits such as SQL injection and cross-site scripting. It integrates natively with ALB, CloudFront, and API Gateway, and provides managed rule groups (e.g., AWSManagedRulesSQLiRuleSet, AWSManagedRulesCommonRuleSet) that detect these exact attack patterns. Because the workload sits behind an ALB, WAF can be attached directly to the load balancer to filter malicious requests before they reach the EC2 instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced is primarily focused on protecting applications against Distributed Denial of Service (DDoS) attacks at Layers 3, 4, and 7. While it includes AWS WAF at no extra cost, WAF itself is the specific service that provides the filtering for SQL injection and XSS attacks.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior across your AWS accounts and workloads. It can detect compromised instances or unusual API calls, but it is not an inline firewall capable of blocking SQL injection or XSS in real-time.
- ✓
AWS WAF
Why this is correct
AWS WAF allows users to create web ACLs that contain rules to inspect HTTP/HTTPS requests. It includes pre-configured managed rule groups that specifically target SQL injection and XSS patterns, providing a robust defense layer at the application level to mitigate these common security threats effectively.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is an automated vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure. It is a proactive scanning tool rather than a reactive firewall for blocking incoming web-based attacks like SQL injection or XSS.
About these practice questions
One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.