SAA-C03 Design Secure Architectures Practice Question
A web application for a order processing API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?
⚠ Common exam trap
Watch out — candidates often confuse network-layer controls (security groups and network ACLs) with application-layer protection, assuming they can filter HTTP-level attacks, when in fact only AWS WAF can inspect and block SQL injection and XSS at the application layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF associated with the Application Load Balancer
AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS) attacks. By associating an AWS WAF web ACL with the Application Load Balancer, you can filter and monitor HTTP/HTTPS requests based on customizable rules, providing application-layer protection with minimal operational overhead since AWS manages the underlying infrastructure and rule updates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security groups on the application instances
Why it's wrong here
Security groups act as a stateful, instance-level firewall that only evaluates source/destination IP, port, and protocol. They cannot parse HTTP request bodies, headers, or URIs, so an SQL injection payload in a POST body or a malicious query string would pass straight through. To block application-layer attacks, you need a web application firewall component such as AWS WAF.
- ✗
Network ACLs on the public subnets
Why it's wrong here
Network ACLs are stateless subnet-level filters that apply to all traffic entering or leaving the subnets, but they only enforce rules based on IP addresses, ports, and protocols. They do not decode HTTP traffic and cannot distinguish a normal request from a crafted XSS or SQL injection attempt. Additionally, because NACLs have no awareness of session state, they must have both inbound and outbound rules configured separately, but that still provides no payload inspection.
- ✓
AWS WAF associated with the Application Load Balancer
Why this is correct
AWS WAF is a managed web application firewall that inspects HTTP and HTTPS requests at layer 7 and can be associated with an Application Load Balancer to filter traffic before it reaches backend instances. It supports AWS-managed rule groups, including the SQL database and cross-site scripting rule sets, that examine request components such as headers, query strings, and body payloads. When deployed on an ALB, WAF can block or allow requests in real time based on those rules, directly mitigating the specific attacks described.
- ✗
AWS Shield Advanced only
Why it's wrong here
AWS Shield Advanced is a DDoS mitigation service that protects against network and transport-layer attacks such as UDP floods or SYN floods, and it also provides cost protection and DDoS response support. It does not inspect the content of individual HTTP requests, so a SQL injection or XSS payload embedded in a legitimate-looking request would not be detected or blocked. Shield Advanced complements, but does not replace, a layer-7 web application firewall like AWS WAF.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.