SAA-C03 Design Secure Architectures Practice Question
A company has a VPC with a CIDR block of 10.0.0.0/16. They need to deploy a web application that must be accessible from the internet. The application will run on Amazon EC2 instances in an Auto Scaling group. The security team requires that the instances be in private subnets and that inbound traffic from the internet be allowed only on ports 80 and 443. They also want to use an Application Load Balancer (ALB) for load balancing and SSL termination. Which architecture meets these requirements?
⚠ Common exam trap
The trap here is placing the ALB in private subnets or the instances in public subnets, which breaks the security requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the ALB in public subnets, the EC2 instances in private subnets, and configure the ALB security group to allow inbound 80/443 from 0.0.0.0/0. Configure the EC2 security group to allow inbound traffic only from the ALB security group.
The correct architecture uses public subnets for the ALB and private subnets for the EC2 instances. The ALB security group allows inbound internet traffic on 80/443, while the EC2 security group allows inbound only from the ALB. This design ensures the instances are not directly accessible from the internet and meets the load balancing and SSL termination requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the ALB in public subnets, the EC2 instances in private subnets, and configure the ALB security group to allow inbound 80/443 from the VPC CIDR. Configure the EC2 security group to allow inbound traffic from the ALB security group.
Why it's wrong here
The ALB security group must allow inbound traffic from the internet (0.0.0.0/0) on ports 80 and 443 to be publicly accessible. Restricting to the VPC CIDR would prevent external users from accessing the application. The EC2 security group rule is correct, but the ALB rule is insufficient, so the application would not be reachable from the internet.
- ✗
Deploy the ALB in public subnets, the EC2 instances in public subnets, and configure both security groups to allow inbound 80/443 from 0.0.0.0/0. Configure the EC2 instances to use an Elastic IP address.
Why it's wrong here
This architecture places the EC2 instances in public subnets and allows direct inbound traffic from the internet, which violates the requirement that instances be in private subnets. It also exposes the instances to potential attacks. Using an Elastic IP further increases the attack surface. This does not meet the security requirements.
- ✗
Deploy the ALB in private subnets, the EC2 instances in public subnets, and configure the ALB security group to allow inbound 80/443 from 0.0.0.0/0. Configure the EC2 security group to allow inbound traffic only from the ALB security group.
Why it's wrong here
Placing the ALB in private subnets makes it inaccessible from the internet, so it cannot serve as the public entry point. Placing EC2 instances in public subnets exposes them to the internet, violating the requirement that they be in private subnets. This architecture does not meet the security requirements and is not recommended.
- ✓
Deploy the ALB in public subnets, the EC2 instances in private subnets, and configure the ALB security group to allow inbound 80/443 from 0.0.0.0/0. Configure the EC2 security group to allow inbound traffic only from the ALB security group.
Why this is correct
This architecture places the ALB in public subnets to receive internet traffic, while the EC2 instances remain in private subnets without public IPs. The ALB security group allows inbound 80/443 from the internet, and the EC2 security group allows inbound only from the ALB, ensuring that instances are not directly accessible. This meets all requirements and follows AWS best practices.
Visual reference
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.