Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A web application for a claims portal is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

⚠ Common exam trap

It's easy for candidates to confuse network-layer controls (like security groups or NACLs) with application-layer protection, assuming they can block SQL injection or XSS, but these operate at Layer 3/4 and cannot inspect HTTP request bodies or headers for malicious content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF associated with the Application Load Balancer

AWS WAF is a web application firewall that integrates directly with an Application Load Balancer to filter and monitor HTTP/HTTPS requests. It provides managed rules specifically designed to block common attack patterns like SQL injection and cross-site scripting (XSS) with minimal operational overhead, as the rules are pre-configured and automatically updated by AWS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS WAF associated with the Application Load Balancer

    Why this is correct

    AWS WAF associated with the Application Load Balancer is the correct answer because it operates at Layer 7, inspecting HTTP/HTTPS requests, headers, body, and query strings for signatures of SQL injection and cross-site scripting (XSS). Managed rule groups such as the Core Rule Set (CRS) and OWASP Top 10 rules specifically detect and block these application-layer exploits. Attaching AWS WAF to an ALB enables centralized, content-aware filtering of all traffic destined to your application, which is exactly the capability required to protect a claims portal against these attack types.

  • ✗

    AWS Shield Advanced only

    Why it's wrong here

    AWS Shield Advanced alone is insufficient because it provides distributed denial-of-service (DDoS) mitigation at Layers 3 and 4, such as volumetric traffic absorption and stateful packet inspection, but it does not perform application-layer content inspection. Shield Advanced does not parse HTTP request bodies or headers to identify SQL injection or XSS patterns. While it helps protect against large-scale DDoS attacks that could make the portal unavailable, it cannot address the specific web application vulnerabilities described in the question, making it an incomplete security solution on its own.

  • ✗

    Network ACLs on the public subnets

    Why it's wrong here

    Network ACLs on the public subnets are stateless, rule-based filters that evaluate traffic based on source/destination IP addresses, ports, and protocols at Layers 3 and 4 of the OSI model. They have no visibility into application-layer payloads, so they cannot distinguish a legitimate GET request from a malicious SQLi payload or an XSS script embedded in a parameter. Additionally, NACLs cannot inspect HTTP bodies or methods, and their stateless nature requires explicit inbound and outbound rules, but even with perfect rules they remain blind to application-layer attacks.

  • ✗

    Security groups on the application instances

    Why it's wrong here

    Security groups on the application instances act as stateful state-level firewalls that allow or deny traffic based on IP addresses, port ranges, and protocols, but they do not inspect the contents of HTTP packets. They can restrict which clients (e.g., only the ALB) can reach the instances, yet they cannot evaluate whether a request contains a SQL injection payload or a malicious script in a form field. Since security groups operate at the network and transport layer, they are powerless to block application-layer threats such as SQLi and XSS, which is why they are not the correct solution for this scenario.

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.