Courseiva

SAA-C03 Design Secure Architectures Practice Question

An internal web application must require encrypted client connections. The company currently has an ALB listener on port 80 (HTTP), and users can access the application over plain HTTP. What is the best change to ensure all client traffic uses HTTPS?

⚠ Common exam trap

It's easy for candidates to confuse encryption at rest (S3 default encryption) with encryption in transit, or assume that WAF or post-receipt encryption can secure the initial client connection, when only a properly configured HTTPS listener with a redirect from HTTP can enforce encrypted client connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an HTTPS (port 443) listener using an ACM certificate and update the port 80 listener to redirect to HTTPS (or to block plain HTTP requests).

It uses an HTTPS listener on port 443 with an ACM certificate to enforce encrypted client connections, and redirecting HTTP (port 80) traffic to HTTPS ensures all traffic is encrypted in transit. This is the standard AWS best practice for enforcing HTTPS on an ALB, as it directly controls the listener behavior at the load balancer level without requiring application changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure an HTTPS (port 443) listener using an ACM certificate and update the port 80 listener to redirect to HTTPS (or to block plain HTTP requests).

    Why this is correct

    Client-to-ALB encryption is enforced by terminating TLS on an ALB HTTPS listener. Redirecting or blocking HTTP on port 80 ensures clients cannot successfully establish plaintext HTTP sessions, so all viable paths use HTTPS end-to-end between the client and the load balancer.

  • ✗

    Enable S3 default encryption so HTTP requests are automatically encrypted in transit.

    Why it's wrong here

    S3 default encryption (SSE-S3 or SSE-KMS) applies exclusively to objects at rest inside an S3 bucket; it does nothing to alter the HTTP/TCP traffic traveling between a client and an Application Load Balancer. Even if the backing storage for the web application were S3, the encryption would not extend to the network path, and clients would still be transmitting plaintext if they connect over the ALB's HTTP listener. TLS/HTTPS must terminate at the ALB itself to encrypt the client-to-load-balancer hop.

  • ✗

    Set the application to encrypt data only after it is received by the ALB.

    Why it's wrong here

    Encrypting only after the request arrives at the ALB does not protect the hop between the client and the ALB. Plain HTTP would still be used on that leg, violating the requirement for encrypted client connections.

  • ✗

    Rely on WAF alone to encrypt HTTP traffic.

    Why it's wrong here

    AWS WAF is a web application firewall that inspects and filters HTTP requests. It does not provide TLS termination or encryption for client connections; TLS must be configured via HTTPS listeners (for example, on the ALB).

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.