Courseiva

SAA-C03 Design Secure Architectures Practice Question

A startup runs a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from specific IP addresses. Which AWS service should be used to meet these requirements?

⚠ Common exam trap

Many candidates confuse DDoS protection with application-layer exploit protection, when AWS Shield Advanced addresses volumetric attacks while AWS WAF handles HTTP-level filtering and rate limiting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF

AWS WAF is the service designed to filter and monitor HTTP requests at the application layer. It provides managed rule groups that block SQL injection and cross-site scripting, and rate-based rules that limit requests from specific IP addresses. Associating a web ACL with the Application Load Balancer enforces these protections directly on incoming traffic, meeting both requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes logs such as VPC Flow Logs, DNS logs, and CloudTrail events to identify malicious activity. It does not sit in the request path and cannot block or rate-limit web traffic. It would alert on suspicious behavior but would not prevent SQL injection or cross-site scripting attacks against the application.

  • ✗

    AWS Shield Advanced

    Why it's wrong here

    AWS Shield Advanced provides enhanced protection against distributed denial-of-service attacks, including volumetric and state-exhaustion attacks. It does not inspect HTTP request payloads for SQL injection or cross-site scripting, and it does not offer application-layer rate limiting based on request patterns. While it is valuable for DDoS mitigation, it does not address the web exploit and rate-limiting requirements described.

  • ✓

    AWS WAF

    Why this is correct

    AWS WAF inspects HTTP and HTTPS requests and can block common exploits such as SQL injection and cross-site scripting using managed rule groups. It also supports rate-based rules that count requests from a source IP over a time window, which meets the rate-limiting requirement. Associating a web ACL with the Application Load Balancer provides the needed protection.

  • ✗

    AWS Network Firewall

    Why it's wrong here

    AWS Network Firewall provides stateful inspection at the VPC level, filtering traffic by IP, port, and protocol, and can perform some deep packet inspection. However, it is not designed for HTTP application-layer exploit protection such as SQL injection or cross-site scripting, and it does not offer the same web ACL rule model as AWS WAF. Using it here would not meet the application-layer requirements efficiently.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.