SAA-C03 Design Secure Architectures Practice Question
An internal web application is exposed through an Application Load Balancer (ALB). The ALB currently has only an HTTP listener on port 80. Security requires that all client traffic be encrypted in transit. What is the best next step?
⚠ Common exam trap
Watch out — candidates often confuse encryption at rest (e.g., S3 bucket encryption) with encryption in transit, or assume that enabling KMS or CloudFront settings automatically secures ALB traffic without explicit listener configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an ALB HTTPS listener on port 443 using an ACM certificate, and redirect HTTP (80) to HTTPS (443).
The requirement to encrypt all client traffic in transit is met by adding an HTTPS listener on port 443 using an ACM certificate, which enables TLS encryption. Additionally, configuring a redirect from HTTP (port 80) to HTTPS (port 443) ensures that any client attempting to connect over unencrypted HTTP is automatically upgraded to HTTPS, enforcing encryption for all traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable S3 bucket encryption for application files, since it ensures encryption in transit.
Why it's wrong here
Enabling S3 bucket encryption protects objects at rest in the S3 bucket, using server-side encryption such as SSE-S3 or SSE-KMS. It does absolutely nothing to encrypt the network path between end users and the ALB — encryption in transit requires TLS on the listener, not encryption of the underlying file storage. Since the application's web traffic is delivered through the ALB, S3 bucket encryption cannot satisfy the requirement to secure the connection between clients and the load balancer.
- ✓
Configure an ALB HTTPS listener on port 443 using an ACM certificate, and redirect HTTP (80) to HTTPS (443).
Why this is correct
Configuring an HTTPS listener on the ALB with an ACM certificate terminates TLS at the load balancer, encrypting all traffic between clients and the ALB. The ACM certificate is validated and managed by AWS, and the listener negotiates a TLS connection using an appropriate security policy. Adding an HTTP-to-HTTPS redirect rule ensures that any request sent to port 80 is automatically sent over port 443, so every client is forced to use an encrypted connection. This directly meets the requirement for encrypting traffic in transit for the internal web application.
- ✗
Turn on default encryption for CloudFront origin access, which automatically encrypts all ALB traffic.
Why it's wrong here
CloudFront's origin access control or 'default encryption' for origin communication only encrypts the connection between CloudFront and the configured origin, such as an S3 bucket or an ALB. It does not automatically encrypt or alter the direct client-to-ALB traffic path, especially when clients are connecting directly to the ALB without going through CloudFront. Additionally, the scenario describes an internal application exposed through an ALB, not necessarily through CloudFront, so this option misunderstands where TLS encryption actually needs to be applied.
- ✗
Add KMS permissions to the ALB role so TLS is enabled automatically.
Why it's wrong here
Adding KMS permissions to the ALB's IAM role does not enable TLS on the load balancer. KMS permissions govern access to customer master keys used for encryption-at-rest of AWS resources like EBS volumes, S3 objects, or RDS instances. TLS on an ALB listener is enabled by attaching an ACM certificate (or an IAM server certificate) to an HTTPS listener and specifying the desired security policy — no KMS involvement is required or sufficient. This option incorrectly conflates key management for at-rest encryption with the network-level TLS configuration.
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.