SAA-C03 Design Secure Architectures Practice Question
A web application behind an Application Load Balancer (ALB) currently allows client connections over HTTP (port 80). The security policy requires all client traffic to use HTTPS. What is the best ALB change to enforce this requirement?
⚠ Common exam trap
Test-takers frequently think removing the HTTP listener or enabling TLS on the target group is sufficient, but the correct approach is to use a redirect action on the HTTP listener to enforce HTTPS without breaking client connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add an HTTP listener on port 80 with a redirect action to HTTPS on port 443, and configure an HTTPS listener using an ACM certificate
It uses an ALB HTTP-to-HTTPS redirect action, which is the most efficient and AWS-native way to enforce HTTPS-only traffic. The HTTP listener on port 80 automatically redirects all client requests to the HTTPS listener on port 443, which terminates TLS using an ACM certificate. This approach requires no changes to client applications and ensures compliance with the security policy at the load balancer level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add an HTTP listener on port 80 with a redirect action to HTTPS on port 443, and configure an HTTPS listener using an ACM certificate
Why this is correct
Redirecting all HTTP requests to HTTPS forces clients to use TLS when they access the application. Configuring an HTTPS listener with an ACM certificate ensures the ALB terminates TLS on port 443 using a valid certificate, directly enforcing encryption in transit for client-to-ALB traffic.
- ✗
Enable TLS only on the target group so that traffic between the ALB and targets is encrypted, even if clients connect via HTTP
Why it's wrong here
Encrypting traffic between the ALB and the targets does not satisfy the requirement, which is about client traffic. If clients still connect to the ALB using HTTP, their traffic is not encrypted in transit from the client to the ALB.
When this WOULD be correct
In a scenario where the requirement is to encrypt traffic between the ALB and backend targets (e.g., to meet compliance for internal traffic), and client-to-ALB encryption is handled separately or not required.
- ✗
Turn on S3 server-side encryption to ensure data is encrypted in transit from clients to the ALB
Why it's wrong here
Enabling S3 server-side encryption (SSE-S3 or SSE-KMS) encrypts objects at rest in Amazon S3; it has no effect on data in motion. The client-to-ALB connection is governed solely by the ALB's listener protocol — an HTTP listener on port 80 sends plaintext traffic regardless of S3 configuration. Since the ALB is not an S3 endpoint, S3 encryption cannot protect the network path between the client and the load balancer, so this action does not satisfy the requirement for encrypting traffic in transit.
When this WOULD be correct
This option would be correct in a scenario where the question asks for encrypting data stored in an S3 bucket, such as 'How to ensure objects in an S3 bucket are encrypted at rest?'
- ✗
Remove port 80 access by removing the port 80 listener and leave only a default target group
Why it's wrong here
Removing the HTTP listener on port 80 would cause any client that attempts to reach the application over HTTP to fail with a connection error instead of being redirected to HTTPS. This action does not enforce encryption; HTTPS on port 443 would still work, but there is no graceful migration path to guide users from the insecure URL to the secure one, which can break existing links or bookmarks. The default target group is unrelated to listener-level configuration, so this change neither redirects clients to TLS nor provides the required secure access path. A redirect action on the HTTP listener is the correct way to enforce HTTPS while preserving compatibility.
When this WOULD be correct
If the security policy required that all client traffic must be HTTPS and that any HTTP requests should be rejected (not redirected), then removing the HTTP listener would be correct. For example, a strict policy that no HTTP traffic is allowed at all.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Add an HTTP listener on port 80 with a redirect action to HTTPS on port 443, and configure an HTTPS listener using an ACM certificateCorrect answer▾
Why this is correct
Redirecting all HTTP requests to HTTPS forces clients to use TLS when they access the application. Configuring an HTTPS listener with an ACM certificate ensures the ALB terminates TLS on port 443 using a valid certificate, directly enforcing encryption in transit for client-to-ALB traffic.
✗Enable TLS only on the target group so that traffic between the ALB and targets is encrypted, even if clients connect via HTTPWrong answer — click to see why▾
Why this is wrong here
Enabling TLS on the target group only encrypts traffic between the ALB and targets, but does not enforce HTTPS between clients and the ALB, leaving client traffic unencrypted over HTTP.
★ When this WOULD be the correct answer
In a scenario where the requirement is to encrypt traffic between the ALB and backend targets (e.g., to meet compliance for internal traffic), and client-to-ALB encryption is handled separately or not required.
Why candidates choose this
Candidates may confuse the need for end-to-end encryption with the requirement to encrypt client traffic, mistakenly thinking that securing the target group alone satisfies the HTTPS requirement.
✗Turn on S3 server-side encryption to ensure data is encrypted in transit from clients to the ALBWrong answer — click to see why▾
Why this is wrong here
S3 server-side encryption encrypts data at rest in Amazon S3, not data in transit. It does not affect traffic between clients and the ALB, so it cannot enforce HTTPS for client connections.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the question asks for encrypting data stored in an S3 bucket, such as 'How to ensure objects in an S3 bucket are encrypted at rest?'
Why candidates choose this
Candidates may confuse encryption at rest with encryption in transit, or mistakenly think S3 can be used to secure ALB traffic due to its encryption capabilities.
✗Remove port 80 access by removing the port 80 listener and leave only a default target groupWrong answer — click to see why▾
Why this is wrong here
Removing the port 80 listener would drop HTTP requests entirely, but the requirement is to redirect HTTP to HTTPS, not to block HTTP. This would break clients that still attempt HTTP connections.
★ When this WOULD be the correct answer
If the security policy required that all client traffic must be HTTPS and that any HTTP requests should be rejected (not redirected), then removing the HTTP listener would be correct. For example, a strict policy that no HTTP traffic is allowed at all.
Why candidates choose this
Candidates may think that simply removing HTTP access enforces HTTPS, but they overlook the need to redirect existing HTTP clients to HTTPS to maintain accessibility and user experience.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.