Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A financial services company runs a three-tier web application on AWS. The application tier consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. A security audit reveals that the application instances are receiving large volumes of unwanted traffic directly from the internet on port 443, bypassing the load balancer. The company wants to ensure that only traffic from the ALB can reach the application instances, while allowing the instances to download software updates from the internet. What should a solutions architect recommend?

⚠ Common exam trap

The trap here is assuming that an AWS WAF rule or a network ACL can restrict traffic that reaches instances directly, when only security group referencing combined with private subnets removes the direct path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the application instances' security group to allow inbound traffic only from the ALB's security group, and place the instances in private subnets with a NAT gateway for outbound internet access.

The most secure and operationally sound approach is to use security group referencing so that the instances accept traffic only from the load balancer, and to remove direct internet exposure by placing instances in private subnets. A NAT gateway then allows outbound updates. This combination enforces the traffic path through the ALB while preserving necessary outbound connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the network ACL on the application subnets to deny inbound traffic on port 443 from all sources except the ALB's private IP addresses.

    Why it's wrong here

    Network ACLs are stateless and operate at the subnet level. Allowing only the ALB's private IPs would block the return traffic for outbound connections initiated by the instances, breaking software updates. Also, the ALB's IPs can change, making static allow lists unreliable and operationally fragile.

  • ✗

    Attach an AWS WAF web ACL to the ALB and create a rule to block all IP addresses except those in the ALB's subnet CIDR range.

    Why it's wrong here

    AWS WAF inspects requests at the ALB, but it cannot stop clients from connecting directly to the EC2 instances' public IP addresses, because those connections never traverse the ALB. Additionally, the ALB's subnet CIDR range does not represent legitimate client IPs, so the rule would not achieve the intended restriction.

  • ✗

    Move the application instances to a placement group and enable enhanced networking to prevent direct internet access.

    Why it's wrong here

    Placement groups and enhanced networking affect instance placement and network performance, not security or internet reachability. They do not filter inbound traffic or remove public IP addresses, so unwanted direct traffic would continue to reach the instances on port 443.

  • ✓

    Configure the application instances' security group to allow inbound traffic only from the ALB's security group, and place the instances in private subnets with a NAT gateway for outbound internet access.

    Why this is correct

    Referencing the ALB's security group as the source in the instances' inbound rule ensures only traffic that passed through the load balancer is accepted. Placing instances in private subnets removes direct internet routing, and a NAT gateway provides outbound-only internet access for updates, satisfying both requirements without exposing the instances.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.