Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A developer needs to access an Amazon RDS database from an EC2 instance within a private subnet. The database must only accept traffic from the instance. Which security configuration is most appropriate?

⚠ Common exam trap

Candidates often suggest using the EC2 instance's private IP address in the RDS security group. This is brittle because IP addresses change when instances are stopped or terminated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the RDS security group to allow inbound traffic from the EC2 instance security group ID.

Configuring the RDS Security Group to allow inbound traffic on the database port exclusively from the security group ID associated with the EC2 instance follows the principle of least privilege. This stateful configuration ensures that only authorized resources can communicate with the database, significantly reducing the attack surface. By referencing the security group ID instead of an IP address, the architecture remains resilient to dynamic IP changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the RDS security group to allow inbound traffic from 0.0.0.0/0 on the database port.

    Why it's wrong here

    Allowing traffic from 0.0.0.0/0 opens the database to the entire internet, which is a major security risk. This violates the principle of least privilege and exposes the database to unauthorized access, brute-force attacks, and potential data breaches. Security groups should always be restricted to specific known sources.

  • ✓

    Configure the RDS security group to allow inbound traffic from the EC2 instance security group ID.

    Why this is correct

    Referencing the EC2 security group ID is a best practice for internal VPC communication. It ensures that any instance associated with that security group can connect to the database. This approach is highly dynamic, as it automatically handles instance IP changes and maintains a secure, restricted network path.

  • ✗

    Configure the RDS security group to allow inbound traffic from the database's own IP address.

    Why it's wrong here

    Allowing traffic from the database's own IP address does not enable external connectivity from the EC2 instance. This configuration is illogical as it only permits self-referential traffic and would prevent the application from successfully reaching the database, resulting in a connection timeout and application failure.

  • ✗

    Configure the RDS security group to allow inbound traffic from the private IP of the EC2 instance.

    Why it's wrong here

    While using a specific private IP is technically possible, it is not recommended. Private IP addresses in AWS can change if an instance is stopped and started. This leads to brittle configurations that require frequent manual updates, making it an inferior solution compared to using security group references.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.