SAA-C03 Design Secure Architectures Practice Question
A startup runs a public-facing web application on Amazon EC2 instances in a VPC. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to block traffic from specific countries. Which AWS service should a solutions architect use?
⚠ Common exam trap
Test-takers frequently confuse network-layer filtering, such as network ACLs, with application-layer inspection that only AWS WAF performs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF with a web ACL attached to the Application Load Balancer, using managed rule groups and a geo match rule.
AWS WAF is the service that inspects HTTP requests for web exploits and can apply geo match conditions. Attaching a web ACL to the Application Load Balancer lets WAF evaluate each request against managed rule groups for SQL injection and cross-site scripting and against a geo match rule that blocks specified countries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS WAF with a web ACL attached to the Application Load Balancer, using managed rule groups and a geo match rule.
Why this is correct
AWS WAF inspects HTTP requests and can block SQL injection and cross-site scripting using AWS managed rule groups. It also supports a geo match condition to block requests from specified countries, directly satisfying both requirements when attached to the ALB.
- ✗
A network ACL on the public subnet that denies traffic from specific country IP ranges.
Why it's wrong here
Network ACLs operate at the subnet level on IP addresses and ports, so they cannot inspect HTTP payloads for SQL injection or cross-site scripting. Maintaining country IP ranges manually is also impractical and inaccurate compared with WAF geo match rules.
- ✗
Amazon GuardDuty with S3 protection and a threat intelligence feed.
Why it's wrong here
GuardDuty is a threat detection service that analyzes logs and findings; it does not inspect or block HTTP requests in real time. It cannot prevent SQL injection or cross-site scripting, and it has no geo-blocking capability, so it does not meet the requirements.
- ✗
AWS Shield Advanced with a web ACL attached to the Application Load Balancer.
Why it's wrong here
AWS Shield Advanced provides enhanced DDoS protection and does not include web ACLs or rule-based inspection for SQL injection and cross-site scripting. Geo-blocking is also not a Shield Advanced feature, so it does not meet the stated requirements.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.