Courseiva

SAA-C03 Design Secure Architectures Practice Question

Your organization hosts an internet-facing application behind an Amazon CloudFront distribution. You want to mitigate common web exploits (for example, SQL injection and XSS) at the edge. Which action is the most appropriate way to do this using AWS services?

⚠ Common exam trap

Test-takers frequently confuse network-layer controls (security groups) or DDoS-specific services (Shield Advanced) with application-layer filtering, or mistakenly think IAM permissions can block malicious request payloads, when only a WAF can inspect and filter HTTP/HTTPS content at the edge.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an AWS WAF web ACL using managed rule sets and associate it with the CloudFront distribution.

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). By creating a web ACL with managed rule sets (e.g., the AWS Managed Rules for SQL injection and XSS) and associating it with your CloudFront distribution, you can inspect incoming HTTP/HTTPS requests at the edge and block malicious payloads before they reach your origin. This is the most appropriate and scalable way to mitigate these threats at the edge.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an AWS WAF web ACL using managed rule sets and associate it with the CloudFront distribution.

    Why this is correct

    AWS WAF examines incoming HTTP/HTTPS requests at the edge (when associated to CloudFront) and applies rule logic to detect common exploit patterns. Managed rule sets provide pre-built protections for threats like SQL injection and XSS before requests reach your origin.

  • ✗

    Add inbound rules to the security group so that only port 443 is open from the internet.

    Why it's wrong here

    A security group acts as a stateful, instance-level firewall that filters traffic by IP addresses, ports, and protocols; it has no logic to examine the payload inside allowed port 443 traffic. Opening only port 443 still permits SQL injection and XSS because those attacks are delivered through HTTPS requests that are perfectly valid at the network layer. Web application attacks occur after the TLS connection is established and the request content is parsed, so security groups are indifferent to the actual HTTP body, headers, or parameters carrying the exploit.

    When this WOULD be correct

    If the question asked for 'restricting inbound traffic to only HTTPS from the internet to an EC2 instance' without mentioning web exploits, then adding inbound rules to the security group for port 443 would be appropriate.

  • ✗

    Enable AWS Shield Advanced to block SQL injection and XSS.

    Why it's wrong here

    AWS Shield Advanced defends against Distributed Denial of Service (DDoS) attacks by absorbing volumetric, resource-exhaustion, and some Layer 7 events such as floods; it does not inspect request content for application exploit signatures like SQL injection or cross-site scripting. While Shield Advanced can be combined with AWS WAF for a layered DDoS strategy, its protection focuses on ensuring availability, not on detecting or blocking malicious payloads embedded in legitimate-looking HTTP(S) traffic. SQLi and XSS require rule-based evaluation of request fields, which is the explicit job of AWS WAF.

    When this WOULD be correct

    When the question asks for the best service to protect against large-scale DDoS attacks (e.g., volumetric or state-exhaustion attacks) targeting an application behind CloudFront, and the requirement is for enhanced DDoS mitigation with 24/7 support and cost protection.

  • ✗

    Restrict IAM permissions for the application’s EC2 instances so that SQL injection payloads cannot be executed.

    Why it's wrong here

    IAM permissions govern which AWS APIs and resources an instance can call (for example, whether it can read an S3 bucket or invoke a Lambda function); they have no visibility into the HTTP request body or query string that a web application receives. SQL injection arises when application code concatenates unvalidated user input into a SQL statement — that is entirely independent of the IAM identity used by the EC2 instance. Even a least-privilege instance profile would still allow the application to execute malicious SQL against its database, because IAM does not filter application-layer payloads.

    When this WOULD be correct

    This option would be correct in a question about limiting the blast radius of a compromised application, such as: 'How can you ensure that an EC2 instance running a web application cannot delete S3 buckets if it is compromised via SQL injection?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Create an AWS WAF web ACL using managed rule sets and associate it with the CloudFront distribution.Correct answer▾

Why this is correct

AWS WAF examines incoming HTTP/HTTPS requests at the edge (when associated to CloudFront) and applies rule logic to detect common exploit patterns. Managed rule sets provide pre-built protections for threats like SQL injection and XSS before requests reach your origin.

✗Add inbound rules to the security group so that only port 443 is open from the internet.Wrong answer — click to see why▾

Why this is wrong here

Security groups operate at the instance level, not at the edge, and cannot inspect application-layer payloads like SQL injection or XSS. They only filter traffic based on IP addresses, protocols, and ports.

★ When this WOULD be the correct answer

If the question asked for 'restricting inbound traffic to only HTTPS from the internet to an EC2 instance' without mentioning web exploits, then adding inbound rules to the security group for port 443 would be appropriate.

Why candidates choose this

Candidates may confuse network-layer security (security groups) with application-layer protection (WAF), assuming that restricting ports is sufficient to block web exploits.

✗Enable AWS Shield Advanced to block SQL injection and XSS.Wrong answer — click to see why▾

Why this is wrong here

AWS Shield Advanced provides DDoS protection, not application-layer filtering for SQL injection or XSS. It does not inspect HTTP request payloads for these exploits.

★ When this WOULD be the correct answer

When the question asks for the best service to protect against large-scale DDoS attacks (e.g., volumetric or state-exhaustion attacks) targeting an application behind CloudFront, and the requirement is for enhanced DDoS mitigation with 24/7 support and cost protection.

Why candidates choose this

Candidates may confuse AWS Shield Advanced with AWS WAF, assuming it includes web application firewall capabilities, or overestimate its scope of protection.

✗Restrict IAM permissions for the application’s EC2 instances so that SQL injection payloads cannot be executed.Wrong answer — click to see why▾

Why this is wrong here

Restricting IAM permissions for EC2 instances does not prevent SQL injection or XSS attacks at the edge; it only limits what the application can do after an attack payload reaches the instance. The question specifically asks for mitigation at the edge, which is before traffic reaches the application.

★ When this WOULD be the correct answer

This option would be correct in a question about limiting the blast radius of a compromised application, such as: 'How can you ensure that an EC2 instance running a web application cannot delete S3 buckets if it is compromised via SQL injection?'

Why candidates choose this

Candidates may think that restricting IAM permissions can block the execution of malicious payloads, but IAM controls API actions, not application-level input validation or attack patterns like SQL injection.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.