Courseiva
Design for New Solutions →easyMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A company is designing a new internal web application for its employees. The application must be accessible only from the corporate network, which connects to AWS via an AWS Site-to-Site VPN. The company wants to use an Application Load Balancer (ALB) to distribute traffic to EC2 instances. The solution must ensure that the ALB is not accessible from the internet. Which configuration should be used?

⚠ Common exam trap

The trap here is assuming that security groups alone can make an internet-facing ALB private, when the ALB's scheme itself determines internet reachability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an internal ALB in a private subnet and attach a security group that allows traffic from the corporate network CIDR.

The requirement is for an ALB that is not accessible from the internet but is reachable from the corporate network over VPN. An internal ALB provides a private DNS name and private IP addresses, ensuring no internet exposure. Placing it in a private subnet and using a security group to allow only the corporate CIDR restricts access to the intended source. This combination satisfies the security and accessibility requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an internet-facing ALB in a private subnet and attach a network ACL that denies all traffic except the corporate CIDR.

    Why it's wrong here

    An internet-facing ALB cannot be placed in a private subnet; it requires public subnets to have public IP addresses. Even if it could, the scheme would still have a public DNS name and be reachable from the internet. Network ACLs are stateless and less precise than security groups, and this configuration is not supported by AWS.

  • ✓

    Create an internal ALB in a private subnet and attach a security group that allows traffic from the corporate network CIDR.

    Why this is correct

    An internal ALB has only private IP addresses and its DNS name resolves to private IPs, so it is not reachable from the internet. Placing it in a private subnet and allowing the corporate CIDR via security group ensures that only traffic from the VPN can reach the load balancer, meeting the requirement for internal-only access.

  • ✗

    Create an internet-facing ALB in a public subnet and attach a security group that allows only the corporate network CIDR.

    Why it's wrong here

    An internet-facing ALB has a publicly resolvable DNS name and public IP addresses, making it reachable from the internet even if security groups restrict access. Security groups are stateful and can limit sources, but the ALB itself is still exposed to the internet, violating the requirement for non-internet accessibility. A private ALB is required.

  • ✗

    Create an internal ALB in a public subnet and attach a security group that allows only the corporate network CIDR.

    Why it's wrong here

    An internal ALB has private IP addresses and is not internet-reachable, but placing it in a public subnet is unnecessary and can expose it to unintended routing. While security groups can restrict access, the public subnet may have an internet gateway route, and the ALB's nodes could potentially be reached from within the VPC. Best practice is to place internal load balancers in private subnets.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.