Courseiva

SAA-C03 · topic practice

Design Secure Architectures practice questions

This domain covers how to design identity, network, and data protection controls on AWS. Questions present a scenario and ask you to pick the service or configuration that meets a stated security requirement, such as private S3 access, TLS termination, database isolation, or encryption of data in transit and at rest.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design Secure Architectures

What the exam tests

What to know about Design Secure Architectures

Be able to select the right AWS control for a stated security goal: VPC endpoints for private service access, ACM plus ALB listeners for TLS, security group references for database isolation, and IAM and KMS for least privilege and encryption. Get the source of trust right.

Choosing S3 gateway VPC endpoints to keep traffic off the public internet

Using AWS Certificate Manager certificates with an Application Load Balancer HTTPS listener

Configuring RDS security groups to allow only a specific EC2 instance or security group

Applying IAM roles, KMS keys, and bucket policies for least-privilege access

Watch out for

Common Design Secure Architectures exam traps

  • ▸Assuming an internet gateway or NAT gateway keeps S3 traffic private; a VPC endpoint is required for AWS-private connectivity.
  • ▸Terminating TLS at the ALB but forgetting that backend traffic to EC2 is separate and may need its own encryption.
  • ▸Opening a database security group to a CIDR range instead of referencing the application's security group as the source.

Practice set

Design Secure Architectures questions

20 questions · select your answer, then reveal the explanation

Refer to the exhibit. An IAM user has the following policy attached. The user attempts to download a file named 'config.json' located in the 'secrets' folder of the 'app-logs' S3 bucket. What will be the result of this action?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket",
        "s3:GetObject"
      ],
      "Resource": [
        "arn:aws:s3:::app-logs",
        "arn:aws:s3:::app-logs/*"
      ]
    },
    {
      "Effect": "Deny",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::app-logs/secrets/*"
    }
  ]
}

A company is migrating a legacy application that uses a custom encryption library. They want to move to AWS KMS but must ensure that even the AWS account administrator cannot use the keys unless they are explicitly granted access in the key policy. How should the key policy be configured?

A financial institution stores highly sensitive customer records in Amazon S3 buckets. The Chief Information Security Officer mandates that all uploaded objects must be encrypted at rest using unique keys, and the key material must be fully managed and rotated automatically by AWS. Which TWO actions fulfill these security requirements? (Choose two.)

Question 4hardmultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. A Solutions Architect implemented an Amazon S3 bucket policy to restrict access to corporate network ranges. However, users connecting from corporate laptops inside the approved CIDR block report that they cannot write objects using AWS Lambda functions configured in the same VPC. What is the cause of this access failure?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowSpecificIP",
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": [
        "arn:aws:s3:::confidential-data-bucket",
        "arn:aws:s3:::confidential-data-bucket/*"
      ],
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "192.0.2.0/24"
        }
      }
    }
  ]
}

A company is extending its on-premises data center to AWS and requires a secure, high-bandwidth connection that does not traverse the public internet. The connection must support consistent network performance. Which TWO components are needed to establish this connectivity? (Select TWO)

An organization wants to centralize logging for all AWS accounts within an AWS Organization. Which service should be used to aggregate logs into a single, secure, and immutable location for security analysis?

A company wants to secure its S3 data. The security policy requires that all objects be encrypted at rest and that the company retains full control over the rotation of the encryption keys. Which TWO of the following should the architect choose to satisfy these requirements?

Question 8mediummultiple choice
Read the full DNS explanation →

A company is concerned about unauthorized access and potential data exfiltration within their AWS environment. They need a service that can continuously monitor VPC Flow Logs, AWS CloudTrail management events, and DNS logs to identify suspicious activities using machine learning. Which solution should the architect recommend for centralized threat detection?

An enterprise requires all data stored in Amazon S3 to be encrypted at rest. The security team must maintain full control over the encryption keys, including the ability to rotate them annually and define access policies for the keys themselves. Which encryption method meets these requirements with the least operational overhead?

Question 10mediummulti select
Review the full subnetting walkthrough →

A security architect is designing a multi-tier application in a VPC. The requirement is to block all traffic from a specific range of malicious IP addresses (CIDR 192.0.2.0/24) while allowing standard web traffic (HTTPS) from all other sources to the web tier. Which TWO actions should the architect take to implement this? (Select TWO.)

An application running on an Amazon EC2 instance needs to securely access data in an Amazon DynamoDB table. What is the most secure way to provide the application with the necessary permissions?

A large corporation uses AWS Organizations to manage hundreds of accounts. The security team wants to ensure that no account can provision resources in unauthorized regions and that only approved AWS services can be used. Which TWO features should be used to enforce these constraints across the entire organization? (Select TWO.)

An enterprise organization is planning a centralized logging architecture across hundreds of AWS accounts using AWS CloudTrail and Amazon S3. Security mandates state that all log files delivered to the centralized S3 bucket must be cryptographically verified to ensure they have not been modified or tampered with after delivery. Which TWO actions must a Solutions Architect implement to achieve this mandate? (Choose two.)

A company wants to ensure that no developer can create an Amazon S3 bucket in any AWS region except for us-east-1 and us-west-2 across their entire AWS Organization. Which solution provides the most efficient and centralized way to enforce this across all member accounts?

A financial services firm must store transaction logs in Amazon S3 for seven years to meet regulatory requirements. The logs must be protected against any modification or deletion by any user, including the root user, during this period. Which S3 feature should be implemented?

Question 16mediummulti select
Review the full subnetting walkthrough →

A web application is deployed on Amazon EC2 instances within a private subnet. The application must receive traffic from an Application Load Balancer (ALB) in a public subnet and connect to an Amazon RDS MySQL database in a different private subnet. Which TWO steps are required to secure this architecture using security groups?

Refer to the exhibit. A solutions architect reviews the following IAM policy applied to a user. What is the effect of this policy when the user attempts to access an object in the bucket from an IP address of 198.51.100.5?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": "s3:GetObject",
    "Resource": "arn:aws:s3:::my-bucket/*",
    "Condition": {"IpAddress": {"aws:SourceIp": "203.0.113.0/24"}}
  }]
}

A company is concerned that its database credentials, currently stored as environment variables in AWS Lambda, are not being rotated regularly. Which AWS service should the company use to securely store and automatically rotate these credentials?

A company's public-facing application is experiencing a Distributed Denial of Service (DDoS) attack. The application is hosted on EC2 instances behind an Application Load Balancer (ALB). Which TWO AWS services or features can be used to mitigate this attack and protect the application?

A security team needs to identify and protect sensitive data, such as credit card numbers and passport IDs, that may be stored across hundreds of S3 buckets in multiple AWS accounts. Which service should they use to automate this discovery process?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design Secure Architectures sessions

Start a Design Secure Architectures only practice session

Every question in these sessions is drawn from the Design Secure Architectures domain — nothing else.

Related practice questions

Related SAA-C03 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SAA-C03 exam test about Design Secure Architectures?
Be able to select the right AWS control for a stated security goal: VPC endpoints for private service access, ACM plus ALB listeners for TLS, security group references for database isolation, and IAM and KMS for least privilege and encryption. Get the source of trust right.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design Secure Architectures questions in a focused session?
Yes — the session launcher on this page draws every question from the Design Secure Architectures domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SAA-C03 topics?
Use the topic links above to move to related areas, or go back to the SAA-C03 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SAA-C03 exam covers. They are not copied from any real exam or dump site.