Courseiva
Design for New Solutions →hardMultiple Select

SAP-C02 Design for New Solutions Practice Question

A company is migrating a legacy application to AWS. The application requires static IP addresses for whitelisting by third-party APIs. The company plans to use an Application Load Balancer with EC2 instances. Which two steps should the company take to ensure the ALB has a consistent set of IP addresses? (Choose TWO.)

⚠ Common exam trap

A common mix-up: candidates think AWS WAF provides static IP addresses, but it does not. Additionally, they might overlook the NLB+Elastic IP approach as a valid method, or confuse NAT Gateway's outbound Elastic IPs with inbound static IPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place a Network Load Balancer with Elastic IP addresses in front of the ALB.

Option B is correct because an Application Load Balancer does not support static IP addresses, but a Network Load Balancer can be assigned Elastic IP addresses per subnet; placing the NLB in front of the ALB gives third-party APIs a fixed set of IPs to whitelist while the NLB forwards traffic to the ALB. Option D is correct because AWS Global Accelerator provides two static anycast IP addresses that front the ALB, so third parties can whitelist those fixed IPs and traffic is routed to the ALB without the ALB itself needing static addresses. Option A is not correct because a NAT Gateway with Elastic IPs only affects outbound traffic from private subnets and does not provide static inbound IPs for an ALB. Option C is not correct because a Route 53 A record resolves to the ALB's DNS name and its dynamic IP addresses, so it does not create a consistent static IP set. Option E is not correct because AWS WAF is a layer 7 filtering service and has no effect on the IP addresses used by the ALB.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a NAT Gateway with Elastic IPs for outbound traffic.

    Why it's wrong here

    A NAT Gateway with Elastic IPs governs outbound traffic from private subnets, not the ALB's inbound addresses. It is tempting because static egress IPs suit third-party whitelisting, and it would be correct when the third party whitelists the application's outbound calls rather than traffic to the load balancer.

  • ✓

    Place a Network Load Balancer with Elastic IP addresses in front of the ALB.

    Why this is correct

    A Network Load Balancer supports Elastic IP addresses, giving static public IPs for third-party whitelisting. Placing it in front of the Application Load Balancer preserves the ALB's layer 7 routing while presenting fixed addresses, satisfying the static IP constraint.

  • ✗

    Use Amazon Route 53 with an A record pointing to the ALB.

    Why it's wrong here

    Route 53 A records resolve to the ALB's DNS name, not fixed addresses; the ALB's node IPs change and cannot be whitelisted. Route 53 alias or A records suit custom domain names and DNS-based failover, not providing static egress or endpoint IPs for third-party whitelisting.

  • ✓

    Place the ALB behind an AWS Global Accelerator.

    Why this is correct

    AWS Global Accelerator provides two static anycast IPv4 addresses that front the Application Load Balancer, so third-party APIs whitelist a fixed set regardless of ALB node changes. This satisfies the stem's static-IP constraint, since ALB node addresses vary with scaling and cannot be whitelisted directly.

  • ✗

    Associate an AWS WAF web ACL with the ALB.

    Why it's wrong here

    AWS WAF filters HTTP requests against web ACL rules; it does not assign or preserve IP addresses on the ALB. It is tempting because WAF is commonly associated with ALB security, and it would be correct when the requirement is blocking malicious requests rather than providing static addresses for third-party whitelisting.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.