Courseiva

SAA-C03 Design High-Performing Architectures Practice Question

A game streaming service must use UDP for real-time gameplay traffic. For external firewall allowlisting, the service requires stable, static IP addresses. The TLS handshake must be handled end-to-end by the application servers (the load balancer must not terminate TLS). Which AWS load balancing option best fits these requirements?

⚠ Common exam trap

Many exam-takers assume an ALB can handle UDP traffic because it supports WebSocket or HTTP/2, but ALB is strictly Layer 7 and only supports TCP-based protocols, while NLB is the correct choice for UDP and TLS passthrough with static IPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a Network Load Balancer (NLB) with a UDP listener, configure the NLB to use Elastic IP addresses for static IPs, and use TCP listeners for TLS passthrough to the application servers.

A Network Load Balancer (NLB) supports UDP listeners, which are required for real-time gameplay traffic, and can be assigned Elastic IP addresses to provide stable, static IPs for firewall allowlisting. Additionally, NLB supports TCP listeners with TLS passthrough, meaning it forwards the encrypted traffic without terminating the TLS handshake, allowing the application servers to handle end-to-end encryption as required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a Network Load Balancer (NLB) with a UDP listener, configure the NLB to use Elastic IP addresses for static IPs, and use TCP listeners for TLS passthrough to the application servers.

    Why this is correct

    NLB supports UDP listeners and is designed for low-latency, high-performance networking. Associating Elastic IP addresses with the NLB provides stable public IP addresses for firewall allowlisting. For TLS passthrough, using a TCP listener keeps the TLS handshake and encryption between the client and the targets (no load balancer TLS termination).

  • ✗

    Use an Application Load Balancer (ALB) with UDP listeners and configure TLS passthrough.

    Why it's wrong here

    ALB is intended for HTTP/HTTPS Layer 7 traffic and does not provide UDP load balancing suitable for low-latency game traffic. Even with TLS passthrough concepts, the missing UDP support makes ALB incompatible with the requirement.

    When this WOULD be correct

    When the requirement is for HTTP/HTTPS traffic with path-based routing, host-based routing, or WebSocket support, and TLS termination at the load balancer is acceptable. For example, a web application needing advanced routing and SSL offloading.

  • ✗

    Use Amazon API Gateway with a WebSocket API and keepalive pings to provide UDP-like low-latency delivery.

    Why it's wrong here

    Amazon API Gateway WebSocket APIs use a persistent TCP-based WebSocket connection, which does not provide the connectionless datagram behavior of UDP. Keepalive pings simply maintain the TCP connection; they do not emulate UDP's low-overhead, best-effort delivery or reduce the overhead of TCP's reliability and flow control. As a fully managed API service, API Gateway is designed for HTTP/WebSocket application messaging, not for raw UDP game traffic load balancing and packet forwarding.

    When this WOULD be correct

    This option would be correct for a real-time chat or notification service that requires persistent bidirectional communication with low latency, where clients connect via WebSocket and the service does not need static IPs or UDP transport.

  • ✗

    Use a Classic Load Balancer and multiplex UDP over TCP to meet the UDP and low-latency requirements.

    Why it's wrong here

    The Classic Load Balancer operates at Layer 4, but its listeners are limited to TCP and SSL/TLS; it has no UDP listener capability. Multiplexing UDP datagrams over a TCP byte stream fundamentally changes transport semantics—TCP's reliable delivery, in-order guarantees, and retransmission logic introduce head-of-line blocking and added latency, which is counterproductive for real-time gameplay. Furthermore, CLB is a legacy load balancer without the low-latency, connection-oriented UDP forwarding that game streaming requires.

    When this WOULD be correct

    If the question required load balancing legacy HTTP/HTTPS traffic with basic round-robin routing and no need for UDP or static IPs, a Classic Load Balancer would be a valid, cost-effective option.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Use a Network Load Balancer (NLB) with a UDP listener, configure the NLB to use Elastic IP addresses for static IPs, and use TCP listeners for TLS passthrough to the application servers.Correct answer▾

Why this is correct

NLB supports UDP listeners and is designed for low-latency, high-performance networking. Associating Elastic IP addresses with the NLB provides stable public IP addresses for firewall allowlisting. For TLS passthrough, using a TCP listener keeps the TLS handshake and encryption between the client and the targets (no load balancer TLS termination).

✗Use an Application Load Balancer (ALB) with UDP listeners and configure TLS passthrough.Wrong answer — click to see why▾

Why this is wrong here

ALB does not support UDP listeners; it only supports HTTP, HTTPS, and WebSocket protocols. Additionally, ALB cannot provide static IP addresses or perform TLS passthrough without terminating TLS.

★ When this WOULD be the correct answer

When the requirement is for HTTP/HTTPS traffic with path-based routing, host-based routing, or WebSocket support, and TLS termination at the load balancer is acceptable. For example, a web application needing advanced routing and SSL offloading.

Why candidates choose this

Candidates may mistakenly think ALB supports UDP because it handles WebSocket traffic, or they confuse ALB's TLS termination with the ability to pass through TLS without decryption.

✗Use Amazon API Gateway with a WebSocket API and keepalive pings to provide UDP-like low-latency delivery.Wrong answer — click to see why▾

Why this is wrong here

Amazon API Gateway WebSocket API does not support UDP traffic; it uses WebSocket protocol over TCP, and it cannot provide static IP addresses for firewall allowlisting. The requirement for UDP and static IPs makes this option invalid.

★ When this WOULD be the correct answer

This option would be correct for a real-time chat or notification service that requires persistent bidirectional communication with low latency, where clients connect via WebSocket and the service does not need static IPs or UDP transport.

Why candidates choose this

Candidates may confuse WebSocket's low-latency, full-duplex communication with UDP's real-time capabilities, and overlook that WebSocket runs over TCP and lacks static IP support.

✗Use a Classic Load Balancer and multiplex UDP over TCP to meet the UDP and low-latency requirements.Wrong answer — click to see why▾

Why this is wrong here

Classic Load Balancers do not support UDP listeners; they only handle TCP/SSL traffic. Multiplexing UDP over TCP would break real-time gameplay requirements by introducing TCP overhead and latency.

★ When this WOULD be the correct answer

If the question required load balancing legacy HTTP/HTTPS traffic with basic round-robin routing and no need for UDP or static IPs, a Classic Load Balancer would be a valid, cost-effective option.

Why candidates choose this

Candidates may think Classic Load Balancers can be adapted to support UDP via workarounds, or they confuse Classic Load Balancers with Network Load Balancers, assuming both support UDP.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.