Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A public web application is fronted by Amazon CloudFront and an ALB. The team is seeing SQL injection attempts and bursts of malicious HTTP requests that increase origin load. They want to block common web attacks before they reach the ALB. What should they do?

⚠ Common exam trap

Many candidates confuse network-layer controls (security groups, NACLs) with application-layer protection, mistakenly thinking they can block SQL injection at the network level, when only a WAF can inspect HTTP request bodies for such attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Associate an AWS WAF web ACL with the CloudFront distribution.

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting. By associating an AWS WAF web ACL with the CloudFront distribution, you can inspect and filter HTTP(S) requests at the edge before they reach the ALB, reducing origin load and blocking malicious traffic early. This is the recommended approach for defending against layer 7 attacks at the CDN level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Associate an AWS WAF web ACL with the CloudFront distribution.

    Why this is correct

    AWS WAF is the correct service for filtering HTTP(S) requests based on patterns such as SQL injection, bad bots, and rate-based abuse. When associated with CloudFront, the filtering happens at the edge before traffic reaches the ALB and origin, reducing load and blocking malicious requests earlier in the path. Shield Standard is already included for basic DDoS protection, but WAF is the component that provides the application-layer controls needed here.

  • ✗

    Add an inbound security group rule to the ALB for the attacker IP ranges.

    Why it's wrong here

    Security groups act as a virtual firewall at the ENI/instance level and only evaluate packet attributes such as source IP, port, and protocol; they cannot decode HTTP requests or inspect bodies for SQL injection patterns. In a CloudFront architecture, the ALB's security group sees CloudFront edge IPs rather than the original client address, so adding rules for attacker IP ranges would not reliably filter the true source and would instead risk blocking legitimate edge traffic. This makes the approach both ineffective for content-based attacks and operationally fragile.

    When this WOULD be correct

    If the question asked to block all traffic from a specific IP range at the network level before it reaches the ALB, adding an inbound security group rule denying that IP range would be correct. For example: 'Block all requests from a known malicious IP range at the ALB.'

  • ✗

    Use a network ACL to inspect and block SQL statements in the request body.

    Why it's wrong here

    Network ACLs are stateless packet filters applied at the subnet boundary; they inspect only IP addresses, ports, and protocol flags, not the payload of TCP segments or HTTP content. Because SQL injection attacks are embedded in the HTTP request body, which may span multiple TCP segments and require stream reassembly, a NACL has no visibility into the statements and cannot block them. Additionally, as a stateless filter, it would need explicit allow rules for return traffic, further complicating any attempt to use it for application-layer defense.

    When this WOULD be correct

    A question asks to block traffic from a specific IP range at the subnet boundary for a VPC, where application-layer inspection is not required.

  • ✗

    Enable Amazon KMS encryption on the ALB listener certificates.

    Why it's wrong here

    Amazon KMS is a key management service for encrypting data at rest; it is not a feature that can be 'enabled on' TLS listener certificates, which are managed by AWS Certificate Manager. Even if you enabled HTTPS on the ALB, TLS only protects data in transit and does nothing to examine or block the decrypted HTTP request payload containing SQLi. Thus, while encryption is important for confidentiality, it neither inspects traffic nor reduces the volume of malicious requests, so it does not mitigate the attack.

    When this WOULD be correct

    A question asks how to enforce encryption for data in transit between the ALB and clients, or to meet compliance requirements for TLS termination using customer-managed keys, where the ALB must use certificates encrypted with KMS.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Associate an AWS WAF web ACL with the CloudFront distribution.Correct answer▾

Why this is correct

AWS WAF is the correct service for filtering HTTP(S) requests based on patterns such as SQL injection, bad bots, and rate-based abuse. When associated with CloudFront, the filtering happens at the edge before traffic reaches the ALB and origin, reducing load and blocking malicious requests earlier in the path. Shield Standard is already included for basic DDoS protection, but WAF is the component that provides the application-layer controls needed here.

✗Add an inbound security group rule to the ALB for the attacker IP ranges.Wrong answer — click to see why▾

Why this is wrong here

Security group rules operate at the network/transport layer and cannot inspect application-layer content like SQL injection payloads. They only filter based on IP, port, and protocol, not HTTP request bodies.

★ When this WOULD be the correct answer

If the question asked to block all traffic from a specific IP range at the network level before it reaches the ALB, adding an inbound security group rule denying that IP range would be correct. For example: 'Block all requests from a known malicious IP range at the ALB.'

Why candidates choose this

Candidates may think security groups can block attacks because they are a common security control, but they confuse network-layer filtering with application-layer inspection that WAF provides.

✗Use a network ACL to inspect and block SQL statements in the request body.Wrong answer — click to see why▾

Why this is wrong here

Network ACLs operate at the subnet level and cannot inspect application-layer content like SQL statements in request bodies; they only filter based on IP, port, and protocol.

★ When this WOULD be the correct answer

A question asks to block traffic from a specific IP range at the subnet boundary for a VPC, where application-layer inspection is not required.

Why candidates choose this

Candidates may confuse network ACLs with WAF, thinking ACLs can perform deep packet inspection, or they overestimate the capabilities of network-layer filtering.

✗Enable Amazon KMS encryption on the ALB listener certificates.Wrong answer — click to see why▾

Why this is wrong here

KMS encryption on ALB listener certificates secures data in transit but does not inspect or block SQL injection or malicious HTTP requests; it provides no web attack protection.

★ When this WOULD be the correct answer

A question asks how to enforce encryption for data in transit between the ALB and clients, or to meet compliance requirements for TLS termination using customer-managed keys, where the ALB must use certificates encrypted with KMS.

Why candidates choose this

Candidates may confuse encryption with security controls, thinking that encrypting traffic somehow prevents attacks, or they may overestimate the scope of KMS capabilities.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.