Courseiva

SAA-C03 Design Secure Architectures Practice Question

A database administrator wants a regular backup of an Amazon RDS database so the team can restore to a recent point in time if needed. Which AWS feature should they use?

⚠ Common exam trap

Many exam-takers confuse security groups or WAF rules with backup mechanisms because they are common security services, but they have no role in data persistence or recovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

RDS automated backups and snapshots

Amazon RDS automated backups and snapshots provide the ability to restore a database to any point within the backup retention period (up to 35 days). Automated backups include transaction logs for point-in-time recovery, while manual snapshots are user-initiated backups stored until explicitly deleted. This directly meets the requirement for regular backups and point-in-time restore capability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    RDS automated backups and snapshots

    Why this is correct

    RDS automated backups are enabled by default and provide a daily snapshot of the database plus transaction logs captured every five minutes. This combination enables point-in-time recovery to any second within the configured retention window, which can be set from 1 to 35 days. Manual snapshots, on the other hand, are user-initiated, persist indefinitely, and provide a baseline that can be used to restore a database after the automated retention period has lapsed. Together, these backup mechanisms are purpose-built for database recovery and are the correct way to ensure backup and restore capability for Amazon RDS.

  • ✗

    Amazon Route 53 alias records

    Why it's wrong here

    Amazon Route 53 alias records are DNS records that map a custom domain name to an AWS resource, such as an RDS database endpoint, by resolving the alias to the resource's current IP address. They influence how clients connect to the database but contain no database content, schema, or transaction data. Alias records are purely routing constructs and have no mechanism to capture, store, or restore any database state, making them entirely unable to serve as a backup solution.

    When this WOULD be correct

    A question asks: 'Which AWS service can be used to route traffic to an RDS database with a custom domain name?' In that context, Route 53 alias records would be correct.

  • ✗

    Security groups

    Why it's wrong here

    Security groups function as a stateful virtual firewall at the network interface level, allowing you to control inbound and outbound traffic using allow rules based on IP addresses, ports, and protocols. They protect an RDS instance from unauthorized network access but do not interact with the database engine or its underlying storage. Because they only filter network packets, they cannot capture data, generate snapshots, or provide point-in-time recovery, so they are irrelevant to the backup requirement.

    When this WOULD be correct

    A question asks: 'Which AWS feature should be used to restrict network access to an RDS database to only allow traffic from a specific application server?' In that scenario, security groups would be the correct answer.

  • ✗

    AWS WAF rules

    Why it's wrong here

    AWS WAF is a web application firewall that inspects HTTP/S requests and mitigates common exploits, such as SQL injection and cross-site scripting, typically deployed in front of a load balancer or content delivery network. It operates at the application layer on traffic destined to web resources and has no visibility into an RDS database's data files, log streams, or storage volumes. Consequently, WAF rules can defend the web-facing front end but cannot create recoverable database backups or support point-in-time restoration.

    When this WOULD be correct

    A question asking how to block SQL injection or cross-site scripting attacks against an Application Load Balancer or CloudFront distribution would make AWS WAF rules the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓RDS automated backups and snapshotsCorrect answer▾

Why this is correct

RDS automated backups are enabled by default and provide a daily snapshot of the database plus transaction logs captured every five minutes. This combination enables point-in-time recovery to any second within the configured retention window, which can be set from 1 to 35 days. Manual snapshots, on the other hand, are user-initiated, persist indefinitely, and provide a baseline that can be used to restore a database after the automated retention period has lapsed. Together, these backup mechanisms are purpose-built for database recovery and are the correct way to ensure backup and restore capability for Amazon RDS.

✗Amazon Route 53 alias recordsWrong answer — click to see why▾

Why this is wrong here

Amazon Route 53 alias records are used for DNS routing, not for database backup or point-in-time recovery of RDS instances.

★ When this WOULD be the correct answer

A question asks: 'Which AWS service can be used to route traffic to an RDS database with a custom domain name?' In that context, Route 53 alias records would be correct.

Why candidates choose this

Candidates may confuse 'alias records' with 'backup records' or think Route 53 manages database snapshots due to its broad management capabilities.

✗Security groupsWrong answer — click to see why▾

Why this is wrong here

Security groups act as a virtual firewall for controlling inbound and outbound traffic to RDS instances, but they do not provide backup or point-in-time recovery capabilities.

★ When this WOULD be the correct answer

A question asks: 'Which AWS feature should be used to restrict network access to an RDS database to only allow traffic from a specific application server?' In that scenario, security groups would be the correct answer.

Why candidates choose this

Candidates may confuse security groups with database backup features because both are common RDS configuration tasks, leading them to select a familiar option without reading the question carefully.

✗AWS WAF rulesWrong answer — click to see why▾

Why this is wrong here

AWS WAF rules are used to filter and monitor HTTP/HTTPS traffic to protect web applications from common web exploits, not for database backup or point-in-time recovery.

★ When this WOULD be the correct answer

A question asking how to block SQL injection or cross-site scripting attacks against an Application Load Balancer or CloudFront distribution would make AWS WAF rules the correct answer.

Why candidates choose this

Candidates might confuse 'rules' for backup policies or think WAF provides some form of data protection, but WAF is a web application firewall, not a backup service.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.