SAA-C03 Design Secure Architectures Practice Question
A startup runs a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from specific IP addresses. Which AWS service should be used to meet these requirements?
⚠ Common exam trap
Many candidates confuse DDoS protection with application-layer exploit protection, when AWS Shield Advanced addresses volumetric attacks while AWS WAF handles HTTP-level filtering and rate limiting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF
AWS WAF is the service designed to filter and monitor HTTP requests at the application layer. It provides managed rule groups that block SQL injection and cross-site scripting, and rate-based rules that limit requests from specific IP addresses. Associating a web ACL with the Application Load Balancer enforces these protections directly on incoming traffic, meeting both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that analyzes logs such as VPC Flow Logs, DNS logs, and CloudTrail events to identify malicious activity. It does not sit in the request path and cannot block or rate-limit web traffic. It would alert on suspicious behavior but would not prevent SQL injection or cross-site scripting attacks against the application.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced provides enhanced protection against distributed denial-of-service attacks, including volumetric and state-exhaustion attacks. It does not inspect HTTP request payloads for SQL injection or cross-site scripting, and it does not offer application-layer rate limiting based on request patterns. While it is valuable for DDoS mitigation, it does not address the web exploit and rate-limiting requirements described.
- ✓
AWS WAF
Why this is correct
AWS WAF inspects HTTP and HTTPS requests and can block common exploits such as SQL injection and cross-site scripting using managed rule groups. It also supports rate-based rules that count requests from a source IP over a time window, which meets the rate-limiting requirement. Associating a web ACL with the Application Load Balancer provides the needed protection.
- ✗
AWS Network Firewall
Why it's wrong here
AWS Network Firewall provides stateful inspection at the VPC level, filtering traffic by IP, port, and protocol, and can perform some deep packet inspection. However, it is not designed for HTTP application-layer exploit protection such as SQL injection or cross-site scripting, and it does not offer the same web ACL rule model as AWS WAF. Using it here would not meet the application-layer requirements efficiently.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.