SAA-C03 Design Secure Architectures Practice Question
A web application for a mobile banking backend is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?
⚠ Common exam trap
Candidates often confuse network-level controls (security groups, NACLs) with application-layer protection, assuming that blocking ports or IP ranges is sufficient to stop web application attacks like SQL injection and XSS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF associated with the Application Load Balancer
AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). By associating an AWS WAF web ACL with the Application Load Balancer, you can filter and monitor HTTP(S) requests based on rules that block these attack patterns, all without managing any infrastructure. This provides the required protection with minimal operational overhead because AWS WAF is a fully managed service that integrates directly with ALB.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security groups on the application instances
Why it's wrong here
Security groups are stateful, instance-level firewall rules that filter traffic based on source/destination IP addresses, protocol, and port numbers at the network interface layer. They operate only on packet metadata at Layers 3 and 4, not on the contents of HTTP requests, such as URL parameters, headers, or body payloads. As a result, a security group cannot identify or block SQL injection or XSS attempts that are embedded in otherwise valid HTTPS traffic to port 443.
- ✓
AWS WAF associated with the Application Load Balancer
Why this is correct
AWS WAF is a Layer 7 (application-layer) firewall that you can associate with an Application Load Balancer to inspect every HTTP/HTTPS request before it is forwarded to backend instances. It can examine the entire request—including URI, query strings, headers, body, and cookies—and enforce custom rules or AWS managed rule groups specifically designed to block SQL injection and cross-site scripting. This makes it the correct service to protect the mobile banking backend from the described web attacks.
- ✗
Network ACLs on the public subnets
Why it's wrong here
Network ACLs act as a stateless firewall at the subnet boundary, using numbered allow/deny rules based on IP CIDR ranges, protocol, and port. Because they are not aware of the state of a connection and do not perform deep packet inspection, they cannot examine application-layer data inside an HTTP request. Malicious SQLi or XSS payloads will pass through an NACL as long as the traffic matches the permitted port and protocol rules, so NACLs provide no defense against these threats.
- ✗
AWS Shield Advanced only
Why it's wrong here
AWS Shield Advanced is a managed protection service designed specifically to mitigate distributed denial of service (DDoS) attacks, such as large volumetric, stateful-exhaustion, or reflection-based attacks at Layers 3 and 4, and sometimes Layer 7 (for example, HTTP floods). It does not include an application-layer inspection engine that can parse HTTP payloads to detect SQL injection or XSS; those attacks require content-aware analysis. While Shield Advanced can be paired with WAF for a layered defense, relying on it alone leaves the mobile banking application vulnerable to web application exploits.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.