Question 643 of 1,040
Design Secure ArchitectureshardMultiple SelectObjective-mapped

Quick Answer

The answer is to restrict the ALB security group inbound rules to the AWS-managed CloudFront origin-facing prefix list. This is correct because the prefix list contains the IP ranges of all CloudFront edge locations, so only traffic routed through CloudFront can reach the ALB, effectively blocking any direct internet access. AWS WAF should be associated with the CloudFront distribution, not the ALB, to inspect traffic at the edge before it reaches the origin, which reduces the attack surface and offloads processing. On the SAA-C03 exam, this scenario tests your understanding of layered security with CloudFront and WAF, and a common trap is to mistakenly apply WAF to the ALB or use a generic IP whitelist instead of the managed prefix list. Remember the memory tip: “Prefix the prefix list” — always use the managed CloudFront prefix list for ALB security group rules to enforce origin access control.

SAA-C03 Design Secure Architectures Practice Question

This SAA-C03 practice question tests your understanding of design secure architectures. Match the stated requirement to the specific cloud service, access model, or configuration option — many options are valid in isolation but not for this scenario. After answering, compare your reasoning against the explanation and wrong-answer breakdown below. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.

A public web application sits behind Amazon CloudFront with an Application Load Balancer as the origin. The security team wants all edge traffic inspected by AWS WAF and also wants to prevent anyone on the internet from reaching the ALB directly. Which two changes should be made? Select two.

Question 1hardmulti select
Full question →

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Associate an AWS WAF web ACL with the CloudFront distribution.

Option A is correct because AWS WAF can be associated directly with a CloudFront distribution to inspect all edge traffic before it reaches the origin. This allows the security team to filter malicious requests at the AWS edge locations, reducing the attack surface and offloading processing from the Application Load Balancer.

Key principle: Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Associate an AWS WAF web ACL with the CloudFront distribution.

    Why this is correct

    CloudFront supports AWS WAF at the edge, so requests can be inspected and filtered before they reach the origin. This placement stops malicious traffic early and applies the protection globally at the distribution layer.

    Related concept

    Read the scenario before looking for a memorised answer.

  • Restrict the ALB security group inbound rules to the AWS-managed CloudFront origin-facing prefix list.

    Why this is correct

    Limiting the ALB security group to the CloudFront origin-facing prefix list ensures the load balancer only accepts traffic from CloudFront edge-to-origin connections. That blocks direct client access from the internet while still allowing CloudFront to forward legitimate requests to the application.

    Related concept

    Read the scenario before looking for a memorised answer.

  • Place the ALB in private subnets and keep the CloudFront distribution unchanged.

    Why it's wrong here

    A standard internet-facing CloudFront distribution needs a reachable origin. Simply moving the ALB to private subnets does not provide a valid direct origin path for CloudFront and does not satisfy the requirement by itself.

  • Use an S3 Origin Access Control instead of a security group change.

    Why it's wrong here

    Origin Access Control is an S3-origin feature and does not apply to an ALB. It cannot restrict traffic to a load balancer origin or replace security group controls.

  • Open the ALB to 0.0.0.0/0 and rely on WAF alone for protection.

    Why it's wrong here

    WAF can filter requests, but leaving the ALB open to the internet violates the requirement to prevent direct access to the origin. The origin must be restricted at the network layer so only CloudFront can reach it.

Common exam traps

Common exam trap: answer the scenario, not the keyword

The trap here is that candidates often think placing the ALB in private subnets is sufficient, but they forget that CloudFront cannot route traffic to private subnets without a public endpoint or a VPC origin configuration, making option C invalid.

Detailed technical explanation

How to think about this question

AWS WAF integrates with CloudFront at the edge, inspecting HTTP(S) requests before they traverse the AWS backbone to the origin. The ALB security group should reference the AWS-managed prefix list for CloudFront (com.amazonaws.global.cloudfront.origin-facing) to allow only traffic from CloudFront’s IP ranges, which are dynamically updated by AWS. This ensures that even if someone discovers the ALB’s DNS name, they cannot bypass CloudFront and WAF protections.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.

TExam Day Tips

  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Key takeaway

Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.

Real-world example

How this comes up in practice

A media company stores terabytes of video archives that are accessed once a year for audit purposes. Moving these objects to a cold storage tier (Azure Archive, S3 Glacier, or Google Nearline) costs a fraction of hot storage. Questions like this test whether you understand storage tiers, access frequency tradeoffs, and retrieval latency requirements.

What to study next

Got this wrong? Here's your next step.

Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.

Related practice questions

Related SAA-C03 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

Practice this exam

Start a free SAA-C03 practice session

Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.

FAQ

Questions learners often ask

What does this SAA-C03 question test?

Design Secure Architectures — This question tests Design Secure Architectures — Read the scenario before looking for a memorised answer..

What is the correct answer to this question?

The correct answer is: Associate an AWS WAF web ACL with the CloudFront distribution. — Option A is correct because AWS WAF can be associated directly with a CloudFront distribution to inspect all edge traffic before it reaches the origin. This allows the security team to filter malicious requests at the AWS edge locations, reducing the attack surface and offloading processing from the Application Load Balancer.

What should I do if I get this SAA-C03 question wrong?

Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.

What is the key concept behind this question?

Read the scenario before looking for a memorised answer.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Keep practising

More SAA-C03 practice questions

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.