SAA-C03 Design Secure Architectures Practice Question
A web application is deployed on Amazon EC2 instances within a private subnet. The application must receive traffic from an Application Load Balancer (ALB) in a public subnet and connect to an Amazon RDS MySQL database in a different private subnet. Which TWO steps are required to secure this architecture using security groups?
⚠ Common exam trap
SAA-C03 often tests whether candidates understand that security groups are stateful and can reference other security groups, luring them into picking CIDR-based rules (0.0.0.0/0) or unnecessary outbound rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the EC2 security group to allow inbound traffic on port 80/443 from the ALB security group.
Option A is correct because the EC2 instances must accept HTTP/HTTPS traffic from the ALB, and referencing the ALB's security group as the source on ports 80/443 restricts inbound access to only that load balancer rather than the whole internet. Option B is correct because the application tier must reach the RDS MySQL database on its listener port 3306, and using the EC2 security group as the source in the RDS security group's inbound rule limits database access to only those application instances. Option C is wrong because allowing 0.0.0.0/0 on port 80 would expose the instances directly to the internet, defeating the purpose of placing them in a private subnet behind an ALB. Option D is wrong because security groups are stateful, so return traffic for allowed inbound connections is automatically permitted and no outbound rule to the EC2 instances is needed; moreover, RDS does not initiate connections to the instances. Option E is wrong because it reverses the traffic direction: the ALB receives client traffic from the internet, not from the EC2 instances, so the ALB security group should allow inbound 80/443 from the internet (or appropriate clients), not from the EC2 security group.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the EC2 security group to allow inbound traffic on port 80/443 from the ALB security group.
Why this is correct
Security groups should be configured to allow traffic only from specific sources using security group referencing. By allowing inbound traffic to the EC2 instances only from the ALB's security group, you ensure that the application cannot be accessed directly from other sources, even within the same VPC.
- ✓
Configure the RDS security group to allow inbound traffic on port 3306 from the EC2 security group.
Why this is correct
The RDS security group must be restricted to accept traffic only from the application tier. Referencing the EC2 security group in the RDS inbound rules ensures that only the authorized application instances can communicate with the database, significantly reducing the attack surface for the sensitive data store.
- ✗
Configure the EC2 security group to allow inbound traffic from 0.0.0.0/0 on port 80 to handle web traffic.
Why it's wrong here
Opening the EC2 security group to the entire internet (0.0.0.0/0) is a security risk and unnecessary when using an ALB. The ALB handles public traffic and forwards it to the instances. The instances are in a private subnet and should only accept traffic from the ALB itself.
- ✗
Configure the RDS security group to allow outbound traffic to the EC2 instances on all ports.
Why it's wrong here
Security groups are stateful, meaning if an inbound request is allowed, the outbound response is automatically permitted regardless of outbound rules. Therefore, explicitly configuring outbound traffic from the RDS to the EC2 instances is redundant and does not follow the best practice of restricting outbound traffic to known destinations.
- ✗
Configure the ALB security group to allow inbound traffic from the EC2 security group on port 80.
Why it's wrong here
The traffic flow is from the ALB to the EC2 instances, not the other way around. The ALB security group needs to allow inbound traffic from the internet or clients, while its outbound rules should permit traffic to the EC2 instances. This suggestion reverses the required logic for the architecture.
Visual reference
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 149 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.