Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A company runs a two-tier web application on Amazon EC2 instances in a public subnet. The EC2 instances must access an Amazon Aurora MySQL DB cluster in private subnets. A security engineer must ensure that only the web tier can reach the database on port 3306, and that no other resources in the VPC can connect. Which combination of security group configuration and subnet placement should the engineer implement?

⚠ Common exam trap

The trap here is assuming that specifying the public subnet CIDR block in the database security group is equivalent to allowing only the web tier, when in fact a CIDR rule permits every resource in that subnet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a security group to the Aurora cluster that allows inbound TCP 3306 from the security group attached to the EC2 instances, and place the Aurora cluster in private subnets.

The secure pattern is to keep the database in private subnets and use a security group inbound rule that references the web tier's security group as the source. Security group references are evaluated dynamically, so only instances carrying that group can open a connection on the database port, and private subnet placement prevents any inbound path from the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach a security group to the Aurora cluster that allows inbound TCP 3306 from the CIDR block of the public subnet, and place the Aurora cluster in private subnets.

    Why it's wrong here

    Allowing the entire public subnet CIDR block on 3306 grants database access to every resource in that subnet, including any future instance or ENI that is not part of the web tier. Security group rules that reference CIDR ranges cannot distinguish between the trusted web instances and other workloads, so this violates the requirement that only the web tier can connect.

  • ✗

    Attach a security group to the Aurora cluster that allows inbound TCP 3306 from the security group attached to the EC2 instances, and place the Aurora cluster in the same public subnet as the EC2 instances.

    Why it's wrong here

    Although the security group reference correctly restricts access to the web tier, placing the Aurora cluster in a public subnet exposes the database endpoints to the internet if the subnet route table has an internet gateway route. The scenario requires the database to remain unreachable from outside the VPC, so the subnet placement makes this design unsuitable.

  • ✗

    Attach a network ACL to the private subnets that allows inbound TCP 3306 from the public subnet CIDR block, and rely on the default security group for the Aurora cluster.

    Why it's wrong here

    Network ACLs are stateless and apply at the subnet boundary, so they cannot identify which instances are part of the web tier. Using the default security group, which typically allows all traffic from other members of the same group, does not restrict access to the EC2 web instances and may permit unrelated resources to reach the database.

  • ✓

    Attach a security group to the Aurora cluster that allows inbound TCP 3306 from the security group attached to the EC2 instances, and place the Aurora cluster in private subnets.

    Why this is correct

    Referencing the web tier's security group as the source in the database security group's inbound rule allows any instance that carries that security group to connect on 3306, regardless of its private IP address. Placing Aurora in private subnets removes any route to the internet, so only resources inside the VPC can attempt a connection, satisfying the least-privilege requirement.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.