Courseiva

SAA-C03 Design Secure Architectures Practice Question

You want to protect an Application Load Balancer (ALB) from common web exploits using AWS WAF. The application is not using CloudFront. Which AWS WAF deployment scope should you choose so the WAF rules apply to the ALB?

⚠ Common exam trap

Watch out — candidates often assume AWS WAF always requires CloudFront or that Shield Advanced provides application-layer inspection, but the exam tests the specific requirement that regional WAF is the only option for ALB without CloudFront.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS WAF regional scope (associate the web ACL with the ALB resource)

AWS WAF offers two deployment scopes: regional and CloudFront (global). Since the application is using an Application Load Balancer (ALB) without CloudFront, you must choose the regional scope. This allows you to associate the web ACL directly with the ALB resource, enabling AWS WAF to inspect HTTP/HTTPS requests for common web exploits like SQL injection and cross-site scripting (XSS) at the regional endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS WAF regional scope (associate the web ACL with the ALB resource)

    Why this is correct

    ALBs are regional resources. When you protect an ALB without CloudFront, you should use the regional WAF scope and associate the web ACL directly with the ALB, so WAF can inspect incoming requests destined for that ALB.

  • ✗

    Use AWS WAF CloudFront (global) scope and associate the web ACL with the ALB

    Why it's wrong here

    AWS WAF web ACLs are available in two scopes: CloudFront (global) and Regional. A CloudFront-scoped web ACL can only be associated with a CloudFront distribution, not with a regional endpoint such as an ALB. Attempting to attach a global web ACL to an ALB is unsupported and will not apply WAF protection to the load balancer. To protect an ALB, you must create a Regional web ACL in the same Region and associate it directly with the ALB resource.

    When this WOULD be correct

    If the application used CloudFront as a content delivery network in front of the ALB, then using AWS WAF with CloudFront (global) scope would be correct. The web ACL would be associated with the CloudFront distribution to protect against web exploits.

  • ✗

    Use AWS Shield Advanced and rely on it to inspect payloads for SQL injection and XSS

    Why it's wrong here

    AWS Shield Advanced is a managed distributed denial-of-service (DDoS) protection service that provides always-on network and transport-layer mitigation and access to the DDoS Response Team. It does not parse HTTP headers, query strings, or request bodies, so it cannot identify SQL injection or XSS signatures. Those application-layer threats require rule-based inspection in AWS WAF, which evaluates HTTP content; Shield Advanced alone is not a substitute.

    When this WOULD be correct

    A question asking for the best service to protect against DDoS attacks targeting an ALB, where the application is not using CloudFront, would make Shield Advanced the correct answer.

  • ✗

    Use security groups only, because they can detect SQL injection patterns in HTTP requests

    Why it's wrong here

    Security groups act as a virtual firewall that filters traffic based on IP addresses, ports, and protocols at the network and transport layers. They have no visibility into HTTP application-layer data, such as URI paths, query string contents, or request bodies, which are the only places SQL injection and XSS payloads appear. As a result, security groups cannot detect or block those attacks; this requires a WAF rule that inspects the actual HTTP request content.

    When this WOULD be correct

    If the question asked for a network-layer defense to block specific IP addresses or ports for an ALB, security groups would be the correct answer. For example: 'Which AWS service can be used to restrict inbound traffic to an ALB based on source IP address?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Use AWS WAF regional scope (associate the web ACL with the ALB resource)Correct answer▾

Why this is correct

ALBs are regional resources. When you protect an ALB without CloudFront, you should use the regional WAF scope and associate the web ACL directly with the ALB, so WAF can inspect incoming requests destined for that ALB.

✗Use AWS WAF CloudFront (global) scope and associate the web ACL with the ALBWrong answer — click to see why▾

Why this is wrong here

AWS WAF with CloudFront (global) scope can only be associated with CloudFront distributions, not with Application Load Balancers. Since the application is not using CloudFront, this scope cannot protect the ALB.

★ When this WOULD be the correct answer

If the application used CloudFront as a content delivery network in front of the ALB, then using AWS WAF with CloudFront (global) scope would be correct. The web ACL would be associated with the CloudFront distribution to protect against web exploits.

Why candidates choose this

Candidates may mistakenly think that AWS WAF's global scope can be applied to any AWS resource, or they may confuse the regional and global scopes, assuming the global scope is more powerful and can protect ALBs directly.

✗Use AWS Shield Advanced and rely on it to inspect payloads for SQL injection and XSSWrong answer — click to see why▾

Why this is wrong here

AWS Shield Advanced provides DDoS protection, not application-layer web exploit detection like SQL injection or XSS. It does not inspect payloads for these threats; that is the role of AWS WAF.

★ When this WOULD be the correct answer

A question asking for the best service to protect against DDoS attacks targeting an ALB, where the application is not using CloudFront, would make Shield Advanced the correct answer.

Why candidates choose this

Candidates may confuse Shield Advanced with WAF, assuming it includes web exploit detection, or overestimate its capabilities due to its 'Advanced' naming.

✗Use security groups only, because they can detect SQL injection patterns in HTTP requestsWrong answer — click to see why▾

Why this is wrong here

Security groups operate at the network layer (Layer 3/4) and cannot inspect application-layer payloads for SQL injection or XSS patterns; they only filter based on IP addresses, ports, and protocols.

★ When this WOULD be the correct answer

If the question asked for a network-layer defense to block specific IP addresses or ports for an ALB, security groups would be the correct answer. For example: 'Which AWS service can be used to restrict inbound traffic to an ALB based on source IP address?'

Why candidates choose this

Candidates may mistakenly believe security groups provide application-layer inspection because they are familiar with them as a primary security mechanism, overlooking that WAF is required for Layer 7 threats.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.