Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A healthcare company runs a three-tier web application on AWS. The application tier consists of EC2 instances in an Auto Scaling group behind an Application Load Balancer. The security team must ensure that the application instances accept traffic only from the load balancer and that no instance can be reached directly from the internet. The instances are in private subnets and have a security group attached. What should a solutions architect do to meet these requirements?

⚠ Common exam trap

The trap here is assuming that allowing the VPC CIDR range is equivalent to allowing only the load balancer, when in fact it grants access to every resource in the VPC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the instance security group to allow inbound traffic on the application port only from the load balancer's security group.

The most secure and operationally simple way to restrict instance access to the load balancer is to reference the load balancer's security group in the instance security group's inbound rule. This creates a logical relationship rather than an IP-based one, so it remains correct as the ALB scales and its node IPs change. It also prevents direct internet access because private instances have no public addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the instance security group to allow inbound traffic on the application port only from the load balancer's security group.

    Why this is correct

    Referencing the load balancer's security group as the source in the instance security group's inbound rule allows only traffic that originates from the load balancer. Because security group references are evaluated on the source's security group membership, no IP ranges need to be maintained. This satisfies the requirement that instances accept traffic only from the ALB and cannot be reached directly from the internet.

  • ✗

    Configure the instance security group to allow inbound traffic on the application port from the VPC CIDR range.

    Why it's wrong here

    Allowing the entire VPC CIDR range means any resource in the VPC, including other instances, NAT gateways, or future workloads, could connect to the application port. This is broader than the requirement, which is to permit only the load balancer. It does not prevent direct access from other compromised resources inside the VPC.

  • ✗

    Create a network ACL that denies all inbound traffic except from the load balancer's subnet CIDR range.

    Why it's wrong here

    Network ACLs are stateless and operate at the subnet level, not per instance. Allowing the load balancer's subnet CIDR would also allow any other resource in that subnet. A subnet-level allow rule does not enforce that only the load balancer can reach the instances, and managing return traffic adds complexity.

  • ✗

    Attach an Elastic IP address to each instance and allow inbound traffic only from the load balancer's public IP addresses.

    Why it's wrong here

    Attaching Elastic IP addresses to instances in private subnets would make them directly addressable and contradicts the requirement that instances cannot be reached directly. Also, ALB node IP addresses change and are not a stable source for security group rules. This approach increases exposure instead of restricting access.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.