Courseiva
Design Secure Architectures →mediumMultiple Select

SAA-C03 Design Secure Architectures Practice Question

A company is designing a secure architecture for a three-tier web application on AWS. The web tier runs on Amazon EC2 instances in public subnets, the application tier runs on EC2 instances in private subnets, and the database tier runs on Amazon RDS in private subnets. The security team requires that the application tier instances can access the internet for software updates without being directly reachable from the internet, and that the database tier is not accessible from the internet. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is using Elastic IPs or public subnets to enable outbound access, which exposes instances to inbound internet traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the RDS database security group to allow inbound traffic only from the application tier security group.

A NAT gateway in a public subnet allows private application instances to initiate outbound internet traffic for updates without being reachable inbound. Referencing the application security group in the RDS security group restricts database access to only those instances. Together, these actions provide secure outbound access and database isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the RDS database in a public subnet and rely on a security group that allows only the application tier's IP range.

    Why it's wrong here

    Placing the database in a public subnet makes it potentially reachable from the internet if the security group or network ACL is misconfigured. The requirement is that the database tier is not accessible from the internet, so it must reside in private subnets. Security groups alone are not sufficient to guarantee isolation from the internet.

  • ✓

    Configure the RDS database security group to allow inbound traffic only from the application tier security group.

    Why this is correct

    Referencing the application tier security group as the source in the RDS security group rules ensures that only application instances can connect to the database. This enforces least privilege and prevents internet access. It also simplifies management because instances added to the application security group automatically gain access.

  • ✗

    Create a VPC peering connection between the application tier VPC and the database tier VPC, and route all database traffic over the peering connection.

    Why it's wrong here

    The scenario describes a single VPC with multiple tiers, so VPC peering is unnecessary and adds complexity. VPC peering is used to connect separate VPCs, not tiers within the same VPC. This option does not address the requirement for outbound internet access for the application tier and is irrelevant to database isolation.

  • ✗

    Attach an Elastic IP address to each application tier instance and configure security groups to allow only outbound traffic.

    Why it's wrong here

    Attaching Elastic IPs makes the instances publicly addressable, violating the requirement that they not be directly reachable from the internet. Security groups only allow outbound traffic do not prevent inbound traffic if the instance has a public IP and the subnet is public. This approach increases the attack surface and does not meet the security requirement.

  • ✓

    Place the application tier instances in private subnets and configure a NAT gateway in a public subnet to allow outbound internet access.

    Why this is correct

    NAT gateways allow instances in private subnets to initiate outbound traffic to the internet while preventing inbound traffic from the internet. This meets the requirement for software updates without exposing the instances. The NAT gateway must be in a public subnet with an Elastic IP and a route in the private subnet's route table pointing to it.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.