SAA-C03 Design Secure Architectures Practice Question
A company runs a two-tier web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The EC2 instances must access an Amazon Aurora MySQL DB cluster. A security engineer must ensure that only these EC2 instances can connect to the database, and that no credentials are stored on the instances. What should the security engineer do?
⚠ Common exam trap
The trap here is assuming that moving credentials into Secrets Manager also restricts which hosts can connect, when network access control and credential management are separate concerns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the DB cluster security group to allow inbound MySQL traffic from the EC2 instances' security group, and enable IAM database authentication on the cluster.
Restricting the Aurora security group to the EC2 instances' security group enforces network-level isolation so only those instances can open a MySQL session. Enabling IAM database authentication lets the application use its IAM role to obtain a temporary token, so no long-lived database password is stored on the instances, satisfying both the access and credential requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a VPC endpoint for Aurora and attach an IAM policy that allows only the EC2 instance role to use the endpoint.
Why it's wrong here
AWS PrivateLink endpoints are not used to reach an Aurora cluster endpoint inside the same VPC; the cluster is reached directly through its DNS name. IAM policies on a VPC endpoint would not authenticate MySQL sessions or replace database credentials, so the no-credentials-on-instances requirement fails.
- ✓
Configure the DB cluster security group to allow inbound MySQL traffic from the EC2 instances' security group, and enable IAM database authentication on the cluster.
Why this is correct
Referencing the EC2 instances' security group as the source in the DB cluster security group allows only those instances to reach port 3306, and IAM database authentication lets the application generate a short-lived authentication token from its IAM role instead of storing a database password on the instance.
- ✗
Store the Aurora master credentials in AWS Secrets Manager and grant the EC2 instance role permission to retrieve the secret at boot.
Why it's wrong here
Secrets Manager removes hard-coded credentials from the AMI, but the EC2 instances still connect as the master user, so any instance can perform administrative actions on the cluster. It also does not restrict which network sources can reach the database, so the requirement that only these EC2 instances connect is not met.
- ✗
Place the DB cluster in a private subnet and attach an AWS WAF web ACL to the cluster endpoint to filter incoming connections.
Why it's wrong here
AWS WAF protects HTTP and HTTPS endpoints such as CloudFront distributions and Application Load Balancers; it cannot inspect or filter native MySQL traffic on port 3306. A private subnet alone still permits any resource in the VPC that knows the endpoint and credentials to connect to the cluster.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.