SAA-C03 Design Secure Architectures Practice Question
A web application for a IoT ingestion API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy? The design must avoid adding custom operational scripts.
⚠ Common exam trap
Many exam-takers confuse network-layer controls (NACLs, security groups) with application-layer protection, or assume Shield Advanced alone covers all web threats, when in fact WAF is specifically designed for Layer 7 attack mitigation like SQLi and XSS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF associated with the Application Load Balancer
AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). By associating an AWS WAF web ACL with the Application Load Balancer, you can filter and monitor HTTP(S) requests based on rules that match malicious patterns, with no custom scripts or operational overhead. This is the most efficient and managed solution for the stated requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS WAF associated with the Application Load Balancer
Why this is correct
AWS WAF integrated with an Application Load Balancer operates at Layer 7 to inspect each HTTP/HTTPS request for malicious patterns, including SQL injection and cross-site scripting (XSS). It uses managed rule groups and custom rules to filter traffic before it reaches the application instances. WAF supports real-time visibility and rate-based controls, making it the only listed option that can inspect application payloads and block these attack types.
- ✗
Network ACLs on the public subnets
Why it's wrong here
Network ACLs (NACLs) act as a stateless firewall at the subnet boundary, evaluating only source/destination IP addresses, ports, and protocols according to numbered rules. Because they do not reassemble or parse the HTTP content, they cannot detect attack signatures embedded in the request body or URI. They could block known malicious IPs, but provide no protection against application-layer attacks like SQLi/XSS.
- ✗
Security groups on the application instances
Why it's wrong here
Security groups associated with application instances provide stateful filtering based on IP addresses, ports, and protocol types at the instance or elastic network interface level. They do not perform deep packet inspection or understand HTTP semantics, so a request containing a SQL injection payload is allowed if the destination port 80/443 is open. Thus they are ineffective for detecting or mitigating application-layer attacks.
- ✗
AWS Shield Advanced only
Why it's wrong here
AWS Shield Advanced is a managed DDoS protection service that defends against volumetric and state-exhaustion attacks at Layers 3, 4, and 7, but it does not inspect individual HTTP requests for malicious patterns such as SQLi or XSS. Its Layer 7 DDoS mitigation focuses on abnormal traffic patterns or flooding, not content-based filtering. While it complements AWS WAF, it cannot replace the granular rule-based inspection needed for these web exploits.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.