Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be accessible only to users from a specific IP range, and the company wants to protect against common web exploits such as SQL injection and cross-site scripting. The company also wants to monitor and rate-limit requests from specific IP addresses. Which solution should a solutions architect implement?

⚠ Common exam trap

Watch out — candidates often confuse AWS Shield Advanced with AWS WAF; Shield protects against DDoS attacks, while WAF protects against application-layer exploits like SQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an AWS WAF web ACL with rules for IP matching, SQL injection, and cross-site scripting, and associate it with the ALB. Use rate-based rules to limit requests from specific IPs.

AWS WAF integrated with the ALB provides the required protections: IP matching to restrict access to a specific IP range, managed rules for SQL injection and cross-site scripting, and rate-based rules to limit requests from specific IPs. This solution directly addresses all requirements without unnecessary components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure an AWS WAF web ACL with rules for IP matching, SQL injection, and cross-site scripting, and associate it with the ALB. Use rate-based rules to limit requests from specific IPs.

    Why this is correct

    AWS WAF can be associated with an ALB to inspect incoming traffic. It provides managed rule groups for SQL injection and cross-site scripting, and you can create IP match conditions to allow only specific IP ranges. Rate-based rules automatically block IPs that exceed a request threshold, meeting the rate-limiting requirement. This is the most direct and effective solution.

  • ✗

    Deploy AWS Firewall Manager to create a security policy that includes AWS WAF rules for IP matching and rate limiting, and apply it to the ALB.

    Why it's wrong here

    AWS Firewall Manager is used to centrally manage security policies across multiple accounts and resources, but it requires AWS Organizations and is overkill for a single ALB. While it can deploy AWS WAF rules, it does not itself provide the WAF functionality; you still need to configure a web ACL. This adds unnecessary complexity and cost for a single application.

  • ✗

    Configure an Amazon CloudFront distribution in front of the ALB, use AWS WAF with the CloudFront distribution, and set up geo-restriction to allow only specific IPs.

    Why it's wrong here

    CloudFront with AWS WAF can provide protection, but geo-restriction works at the country level, not specific IP ranges. To restrict by IP range, you would still need AWS WAF IP match rules. Adding CloudFront increases complexity and cost, and the scenario does not require content delivery or global distribution. The ALB can be directly protected with AWS WAF.

  • ✗

    Use security groups on the ALB to allow traffic only from the specific IP range, and enable AWS Shield Advanced for protection against web exploits.

    Why it's wrong here

    Security groups can restrict traffic by IP range, but they cannot inspect application-layer payloads to prevent SQL injection or cross-site scripting. AWS Shield Advanced provides DDoS protection, not web application firewall capabilities. It does not offer rate limiting based on request patterns. This combination does not meet the requirement to protect against common web exploits.

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.