Courseiva

SAA-C03 Design Secure Architectures Practice Question

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application must be reachable only from a specific corporate CIDR range, and the instances must not be directly reachable from the internet. Which combination of security group configurations meets these requirements?

⚠ Common exam trap

The trap here is putting the corporate CIDR range on the instance security group, which permits clients to bypass the load balancer rather than forcing all traffic through it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow inbound HTTP and HTTPS from the corporate CIDR range on the load balancer security group, and allow inbound HTTP from the load balancer security group on the instance security group.

The load balancer security group should allow only the corporate CIDR range on the listener ports, and the instance security group should allow traffic only from the load balancer security group. Referencing a security group as a source is the cleanest way to allow traffic from the load balancer without hardcoding its IP addresses, and it prevents direct client access to the instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow inbound HTTP and HTTPS from 0.0.0.0/0 on the load balancer security group, and allow inbound HTTP from the load balancer security group on the instance security group.

    Why it's wrong here

    Allowing 0.0.0.0/0 on the load balancer exposes the application to the entire internet, which violates the requirement to restrict access to the corporate CIDR range. The instance security group reference is correct, but the load balancer rule is too permissive. This option fails the restriction requirement even though it protects the instances from direct access.

  • ✗

    Allow inbound HTTP and HTTPS from the corporate CIDR range on the instance security group, and allow outbound traffic to the load balancer security group.

    Why it's wrong here

    Security groups are stateful and filter inbound traffic at the destination. Placing the corporate CIDR rule on the instances does not control traffic that reaches the load balancer, and the load balancer would still accept traffic from anywhere. Outbound rules do not restrict who can initiate connections to the load balancer, so this design does not meet the requirement.

  • ✗

    Allow inbound HTTP and HTTPS from the corporate CIDR range on both the load balancer security group and the instance security group.

    Why it's wrong here

    Adding the corporate CIDR range directly to the instance security group allows clients in that range to bypass the load balancer and connect to the instances if routing permits. The instances should accept traffic only from the load balancer security group. This option weakens the isolation requirement even though the load balancer rule is correct.

  • ✓

    Allow inbound HTTP and HTTPS from the corporate CIDR range on the load balancer security group, and allow inbound HTTP from the load balancer security group on the instance security group.

    Why this is correct

    Restricting the load balancer security group to the corporate CIDR range limits access to the approved network. Referencing the load balancer security group as the source in the instance security group allows only traffic forwarded by the load balancer, so the instances are not directly reachable from the internet. This matches both requirements.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.