Courseiva

SAA-C03 Design Secure Architectures Practice Question

A financial services company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be accessible only from a specific corporate IP range (203.0.113.0/24). The security team wants to restrict access at the load balancer level and also ensure that the instances themselves only accept traffic from the ALB. Which combination of security group configurations should a solutions architect implement?

⚠ Common exam trap

The trap here is using IP addresses instead of security group references for the instances, which can break when ALB IPs change.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the ALB security group to allow inbound HTTP/HTTPS from 203.0.113.0/24. Configure the EC2 instances' security group to allow inbound traffic only from the ALB security group.

The most secure and maintainable configuration is to restrict the ALB to the corporate IP range and allow the instances to accept traffic only from the ALB security group. This ensures that all external traffic goes through the ALB and that instances are not directly accessible, while using security group references simplifies management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the ALB security group to allow inbound HTTP/HTTPS from 203.0.113.0/24. Configure the EC2 instances' security group to allow inbound traffic from the ALB's IP addresses.

    Why it's wrong here

    Using the ALB's IP addresses as the source in the instances' security group is not recommended because ALB IP addresses can change. It is better to reference the ALB security group, which dynamically allows traffic from any IP the ALB uses, ensuring consistent and secure access control.

  • ✓

    Configure the ALB security group to allow inbound HTTP/HTTPS from 203.0.113.0/24. Configure the EC2 instances' security group to allow inbound traffic only from the ALB security group.

    Why this is correct

    This approach restricts access to the ALB from the corporate IP range and ensures that EC2 instances only accept traffic from the ALB. Referencing the ALB security group as the source in the instances' security group is a best practice because it automatically adapts to ALB IP changes and prevents direct access to instances.

  • ✗

    Configure the ALB security group to allow inbound HTTP/HTTPS from 0.0.0.0/0. Configure the EC2 instances' security group to allow inbound traffic from 203.0.113.0/24.

    Why it's wrong here

    Allowing the ALB to accept traffic from anywhere exposes the application to the internet, violating the requirement to restrict access to the corporate IP range. Additionally, allowing the instances to accept traffic directly from the corporate range bypasses the ALB and weakens security.

  • ✗

    Configure the ALB security group to allow inbound HTTP/HTTPS from 203.0.113.0/24. Configure the EC2 instances' security group to allow inbound traffic from 0.0.0.0/0.

    Why it's wrong here

    While the ALB is properly restricted, allowing the instances to accept traffic from anywhere means they are directly accessible from the internet, which is a security risk. The instances should only accept traffic from the ALB to ensure all traffic goes through the load balancer and its security controls.

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.