SAA-C03 Design Secure Architectures Practice Question
A security architect is designing a multi-tier application in a VPC. The requirement is to block all traffic from a specific range of malicious IP addresses (CIDR 192.0.2.0/24) while allowing standard web traffic (HTTPS) from all other sources to the web tier. Which TWO actions should the architect take to implement this? (Select TWO.)
⚠ Common exam trap
SAA-C03 often tests the difference between Security Groups (allow-only) and NACLs (allow/deny), and candidates may incorrectly try to add a deny rule to a Security Group.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an inbound rule in the Network ACL to deny traffic from 192.0.2.0/24.
Option A is correct because Network ACLs are stateless, subnet-level firewalls that support explicit deny rules, so an inbound deny rule for 192.0.2.0/24 blocks that malicious CIDR before it can reach any resource in the subnet. Option D is correct because Security Groups are stateful, instance-level firewalls that only support allow rules, so permitting inbound TCP port 443 from 0.0.0.0/0 allows standard HTTPS web traffic from all other sources to the web tier. Together these satisfy both requirements: the NACL denies the malicious range while the Security Group allows HTTPS from everywhere else. Option B is wrong because Security Groups cannot contain deny rules; they are allow-only. Option C is wrong because AWS Shield Standard provides automatic protection against common DDoS attacks and does not let you block a specific CIDR like 192.0.2.0/24. Option E is wrong because route tables control routing, not inbound filtering, and blackholing a destination CIDR would not block inbound traffic from that source to the web tier.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an inbound rule in the Network ACL to deny traffic from 192.0.2.0/24.
Why this is correct
Network ACLs act as a firewall for associated subnets and are stateless, meaning they require rules for both inbound and outbound traffic. They support explicit deny rules, which allow administrators to block specific malicious CIDR blocks from entering the network at the earliest possible entry point.
- ✗
Add a deny rule to the web tier Security Group for CIDR 192.0.2.0/24.
Why it's wrong here
Security Groups are stateful and function at the instance level, but they do not support explicit deny rules. They only allow traffic that is explicitly permitted, making them unsuitable for blocking specific IP ranges while maintaining a broad open port for the rest of the public internet.
- ✗
Configure AWS Shield Standard to automatically block the 192.0.2.0/24 subnet.
Why it's wrong here
AWS Shield Standard provides automatic protection against common infrastructure-level DDoS attacks at no additional cost. However, it does not offer the ability to manually configure custom deny rules for specific IP addresses, as it is designed for automated mitigation of known volumetric and protocol-based threats.
- ✓
Configure the web tier Security Group to allow inbound traffic on port 443 from 0.0.0.0/0.
Why this is correct
Security Groups are used to define the permitted traffic for the application instances. By only allowing traffic from known legitimate sources or common web ports, they complement the Network ACL's ability to block malicious actors, providing a layered defense-in-depth approach to securing the VPC environment.
- ✗
Update the VPC Route Table to blackhole all traffic destined for 192.0.2.0/24.
Why it's wrong here
Route tables determine where network traffic is directed but do not have the capability to filter or block traffic based on security criteria. Using route tables to manage security would lead to complex and unmanageable routing configurations that do not provide actual security enforcement against malicious IPs.
Visual reference
About these practice questions
This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.