Courseiva

SAA-C03 Design High-Performing Architectures Practice Question

A team needs to distribute TCP traffic (not HTTP) across multiple services. The services must see the original client source IP for auditing. Which AWS load balancer is the best fit?

⚠ Common exam trap

Test-takers frequently assume an Application Load Balancer can handle any TCP traffic because of its 'listener' terminology, but ALB strictly requires HTTP/HTTPS protocols and cannot forward raw TCP streams.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network Load Balancer (NLB) using TCP listeners

A Network Load Balancer (NLB) is the best fit because it operates at Layer 4 (TCP/UDP) and preserves the original client source IP address by default, which is required for auditing. It can distribute raw TCP traffic across multiple services without inspecting application-layer headers, making it ideal for non-HTTP TCP workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application Load Balancer (ALB) using HTTP/HTTPS listeners with host-based routing

    Why it's wrong here

    Application Load Balancer (ALB) operates at Layer 7 and parses the HTTP/HTTPS request stream, which means host-based routing depends on the HTTP Host header to select a target. Arbitrary TCP traffic such as a custom binary protocol or a database replication stream does not contain HTTP headers, so ALB cannot inspect or route it meaningfully. Even though ALB supports health checks, its listeners themselves only understand HTTP/HTTPS and gRPC, so it is fundamentally incapable of load-balancing raw non-HTTP TCP streams.

    When this WOULD be correct

    When distributing HTTP/HTTPS traffic and needing advanced routing (e.g., host-based or path-based routing) with original client IP preserved via X-Forwarded-For headers.

  • ✓

    Network Load Balancer (NLB) using TCP listeners

    Why this is correct

    NLB is a Layer 4 load balancer that supports TCP and UDP. When the traffic is routed to targets (for example, instance or IP targets), the backend connection maintains the original source IP/port at the networking layer, which supports IP-based auditing without requiring HTTP headers.

  • ✗

    Classic Load Balancer (CLB) configured for TCP health checks only

    Why it's wrong here

    Classic Load Balancer (CLB) is a legacy Layer 4 load balancer that can accept TCP connections, so merely configuring TCP health checks does not fix its underlying limitations. CLB lacks modern features such as target groups that can register EC2 instances and IP addresses across VPCs, static elastic IP assignments, and the consistent source IP preservation and high-throughput connection handling that NLB provides. Because AWS no longer recommends CLB for new architectures and it is in maintenance mode, using it for high-performance TCP traffic distribution to multiple services is an outdated choice compared with NLB.

    When this WOULD be correct

    A scenario where the requirement is to distribute TCP traffic across multiple EC2 instances using basic round-robin routing, and preserving the client IP is not needed. For example, a legacy application that only needs simple load balancing without advanced features like SNI or source IP preservation.

  • ✗

    API Gateway with a VPC Link to forward raw TCP traffic

    Why it's wrong here

    API Gateway is a service designed for building HTTP, REST, and WebSocket APIs, not for transparently forwarding raw network-layer TCP segments. A VPC Link integrates API Gateway with private resources in a VPC, but that integration is still an HTTP proxy path: API Gateway forwards HTTP requests to an NLB or other HTTP-compatible endpoint and cannot maintain a raw bidirectional TCP connection for arbitrary protocols. Because API Gateway's model is request/response over HTTP, it cannot replace a Layer 4 load balancer for long-lived non-HTTP workloads like custom socket protocols or database connections.

    When this WOULD be correct

    A team needs to expose RESTful or WebSocket APIs to external clients while keeping backend services in a private VPC. API Gateway with a VPC Link would securely forward HTTP/HTTPS requests to internal ALBs or NLBs.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Network Load Balancer (NLB) using TCP listenersCorrect answer▾

Why this is correct

NLB is a Layer 4 load balancer that supports TCP and UDP. When the traffic is routed to targets (for example, instance or IP targets), the backend connection maintains the original source IP/port at the networking layer, which supports IP-based auditing without requiring HTTP headers.

✗Application Load Balancer (ALB) using HTTP/HTTPS listeners with host-based routingWrong answer — click to see why▾

Why this is wrong here

ALB only supports HTTP/HTTPS listeners, not raw TCP traffic. It cannot distribute non-HTTP TCP traffic as required.

★ When this WOULD be the correct answer

When distributing HTTP/HTTPS traffic and needing advanced routing (e.g., host-based or path-based routing) with original client IP preserved via X-Forwarded-For headers.

Why candidates choose this

Candidates may assume ALB supports all TCP traffic because it is a common load balancer, or they overlook the requirement for non-HTTP TCP traffic.

✗Classic Load Balancer (CLB) configured for TCP health checks onlyWrong answer — click to see why▾

Why this is wrong here

Classic Load Balancer (CLB) does not preserve the original client source IP for TCP traffic; it uses its own IP as the source. The question requires preserving the client IP for auditing, which CLB cannot do.

★ When this WOULD be the correct answer

A scenario where the requirement is to distribute TCP traffic across multiple EC2 instances using basic round-robin routing, and preserving the client IP is not needed. For example, a legacy application that only needs simple load balancing without advanced features like SNI or source IP preservation.

Why candidates choose this

Candidates may think CLB is sufficient for TCP traffic because it supports TCP listeners and health checks, and they might overlook the specific requirement for preserving the original client source IP.

✗API Gateway with a VPC Link to forward raw TCP trafficWrong answer — click to see why▾

Why this is wrong here

API Gateway does not support raw TCP traffic; it is designed for HTTP/HTTPS and WebSocket APIs. It cannot forward arbitrary TCP streams to backend services.

★ When this WOULD be the correct answer

A team needs to expose RESTful or WebSocket APIs to external clients while keeping backend services in a private VPC. API Gateway with a VPC Link would securely forward HTTP/HTTPS requests to internal ALBs or NLBs.

Why candidates choose this

Candidates may think API Gateway can handle any protocol via VPC Link, but VPC Link only works with HTTP/HTTPS APIs, not raw TCP.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.