Skip to content
BytePatterns

SAA-C03 · Domain 1: Design Secure Architectures · 30% of the exam

Task 1.2: Design secure workloads and applications.

Keeping an application safe on the network and at its front door: public and private subnets, security groups and network ACLs, VPC endpoints, secrets kept out of code, and the services that stop DDoS, SQL injection and unwanted sign-ins.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

Application servers run in private subnets in two Availability Zones of a VPC that has an internet gateway attached. They must download operating system updates from the internet over IPv4, must not be reachable from the internet, and must keep outbound access if one Availability Zone fails. The security team does not allow any public subnet in this VPC. Which design meets these requirements?

  1. AA zonal NAT gateway in a public subnet of each zone, with each private subnet routing 0.0.0.0/0 to the gateway in its own zone
  2. BAn egress-only internet gateway, with both private subnets' route tables sending outbound traffic to it
  3. CA route from both private subnets to the internet gateway, with security groups that allow no inbound traffic
  4. DA regional NAT gateway for the VPC, with both private subnets' route tables sending 0.0.0.0/0 to it
Show the answer and why
  • AA zonal NAT gateway in a public subnet of each zone, with each private subnet routing 0.0.0.0/0 to the gateway in its own zone

    Incorrect

    One zonal NAT gateway per zone survives a zone failure, but each zonal public NAT gateway is hosted in a public subnet with a route to the internet gateway, and the security team allows no public subnet.

  • BAn egress-only internet gateway, with both private subnets' route tables sending outbound traffic to it

    Incorrect

    An egress-only internet gateway carries IPv6 traffic only. It cannot give instances outbound access over IPv4.

  • CA route from both private subnets to the internet gateway, with security groups that allow no inbound traffic

    Incorrect

    A route to an internet gateway turns the subnets into public subnets, and the servers would need public IP addresses to use it. The design breaks the no-public-subnet rule and leaves the servers addressable from the internet, guarded only by security groups.

  • DA regional NAT gateway for the VPC, with both private subnets' route tables sending 0.0.0.0/0 to it

    Correct

    A regional NAT gateway needs no public subnet, has its own route table with a route to the internet gateway, and expands across the Availability Zones where the workloads run, which gives high availability by default. Both subnets can route to its single ID.

Outbound-only IPv4 access calls for a NAT gateway. Zonal NAT gateways operate in one Availability Zone and sit in public subnets, so the resilient zonal design needs a public subnet per zone. A regional NAT gateway spans the zones of the workload and needs no public subnet, which meets every requirement here.

Question 2 · choose 1

A web application runs behind an Application Load Balancer. Logs show SQL injection attempts and bursts of thousands of requests per minute from a small set of IP addresses. The company wants a managed way to block both at the load balancer. What should a solutions architect do?

  1. ASubscribe to AWS Shield Advanced and add the load balancer to its list of protected resources
  2. BTurn on Amazon GuardDuty and have a Lambda function add deny rules to the security groups
  3. CAssociate an AWS WAF web ACL with the SQL database managed rule group and a rate-based rule
  4. DAdd network ACL rules to the load balancer's subnets that deny the offending IP addresses
Show the answer and why
  • ASubscribe to AWS Shield Advanced and add the load balancer to its list of protected resources

    Incorrect

    Shield Advanced protects against DDoS attacks. Blocking SQL injection still needs AWS WAF rules that inspect the requests.

  • BTurn on Amazon GuardDuty and have a Lambda function add deny rules to the security groups

    Incorrect

    GuardDuty is a threat detection service that produces findings. Security groups also cannot hold deny rules; they only allow traffic.

  • CAssociate an AWS WAF web ACL with the SQL database managed rule group and a rate-based rule

    Correct

    AWS WAF inspects web requests to the load balancer. The SQL database managed rule group blocks SQL injection patterns, and a rate-based rule limits requests per source IP.

  • DAdd network ACL rules to the load balancer's subnets that deny the offending IP addresses

    Incorrect

    Network ACLs filter by address and port and cannot see SQL injection inside a request. A fixed IP list also needs manual upkeep as sources change.

Request content (SQL injection) and request rate per IP are both layer 7 concerns, which is AWS WAF's job. Shield Advanced focuses on DDoS, and network ACLs cannot read requests.

Question 3 · choose 1

A Lambda function connects to an Amazon RDS for PostgreSQL database with a user name and password that are stored in an environment variable today. A new policy requires the password to rotate automatically every 30 days without redeploying the function. Which solution meets the requirement with the LEAST operational effort?

  1. AEncrypt the environment variable with a customer managed KMS key and turn on automatic rotation of that key
  2. BStore the password as a SecureString parameter in Parameter Store and read the parameter at runtime
  3. CStore the credentials in AWS Secrets Manager with automatic rotation on, and read the secret at runtime
  4. DWrite a scheduled script that changes the password and then updates the function's environment variable
Show the answer and why
  • AEncrypt the environment variable with a customer managed KMS key and turn on automatic rotation of that key

    Incorrect

    KMS key rotation replaces the key material used for encryption. The database password itself stays the same.

  • BStore the password as a SecureString parameter in Parameter Store and read the parameter at runtime

    Incorrect

    Parameter Store encrypts values but does not rotate them on its own. AWS recommends Secrets Manager for credentials that need automatic rotation.

  • CStore the credentials in AWS Secrets Manager with automatic rotation on, and read the secret at runtime

    Correct

    Secrets Manager rotates the secret on a schedule and updates the database. The function reads the current value each time, so nothing is redeployed.

  • DWrite a scheduled script that changes the password and then updates the function's environment variable

    Incorrect

    It can work, but it is custom code to build, secure and maintain, and each run changes the function's configuration.

Automatic rotation of database credentials without code changes is what Secrets Manager is for. Rotating a KMS key does not change a password.

Question 4 · choose 1

EC2 instances in private subnets with no NAT device must retrieve secrets from AWS Secrets Manager. Company policy forbids any route to the internet from these subnets. Which solution meets these requirements?

  1. ACreate a gateway VPC endpoint for Secrets Manager and add it to the private subnets' route tables
  2. BPeer the VPC with a shared-services VPC that has a NAT gateway, and route through the peering
  3. CAssign Elastic IP addresses to the instances and allow only Secrets Manager in the security groups
  4. DCreate an interface VPC endpoint for Secrets Manager in the private subnets with private DNS on
Show the answer and why
  • ACreate a gateway VPC endpoint for Secrets Manager and add it to the private subnets' route tables

    Incorrect

    Gateway endpoints exist only for Amazon S3 and DynamoDB. Other services are reached privately through interface endpoints.

  • BPeer the VPC with a shared-services VPC that has a NAT gateway, and route through the peering

    Incorrect

    VPC peering does not support edge-to-edge routing: a VPC cannot use a NAT device or internet gateway in the peered VPC.

  • CAssign Elastic IP addresses to the instances and allow only Secrets Manager in the security groups

    Incorrect

    Public addresses only work with a route to an internet gateway, which the policy forbids, and they make the instances reachable from the internet.

  • DCreate an interface VPC endpoint for Secrets Manager in the private subnets with private DNS on

    Correct

    An interface endpoint uses AWS PrivateLink to reach the service through private IP addresses in the VPC, with no internet gateway or NAT device.

Private access to an AWS service other than S3 or DynamoDB means an interface endpoint. Peering cannot lend another VPC's NAT gateway.

Question 5 · choose 2

A three-tier application runs in a VPC. The application tier is an Auto Scaling group, so its IP addresses change often. The database must accept connections on port 3306 only from the application tier and must never be reachable from the internet. Which steps should a solutions architect take? (Choose TWO.)

  1. AAllow port 3306 in the database security group from the current private IPs of the app instances
  2. BPlace the database in subnets whose route table has no route to an internet gateway
  3. CAdd a database security group rule that denies inbound traffic from 0.0.0.0/0 on all other ports
  4. DAllow port 3306 in the database security group with the app tier's security group as the source
  5. EGive the database a public IP address and use a network ACL that allows only port 3306 inbound
Show the answer and why
  • AAllow port 3306 in the database security group from the current private IPs of the app instances

    Incorrect

    The addresses change as the group scales, so the rules would go stale and block new instances or admit old addresses.

  • BPlace the database in subnets whose route table has no route to an internet gateway

    Correct

    A subnet without a route to an internet gateway is private, so the database has no path to or from the internet.

  • CAdd a database security group rule that denies inbound traffic from 0.0.0.0/0 on all other ports

    Incorrect

    Security groups accept allow rules only; there is no deny rule to add. Anything not allowed is already refused.

  • DAllow port 3306 in the database security group with the app tier's security group as the source

    Correct

    Referencing a security group as the source admits every instance that has that group, whatever its current IP address.

  • EGive the database a public IP address and use a network ACL that allows only port 3306 inbound

    Incorrect

    A public address with port 3306 open in the ACL exposes the database to the internet, which the requirement forbids.

Keep the database in a private subnet, and let the security group trust the application tier's group instead of its changing addresses.

Question 6 · choose 1

A company is building a mobile app backed by a REST API in Amazon API Gateway. Customers must be able to sign up with an email address or sign in with a social identity provider, and only signed-in customers may call the API. Which solution requires the LEAST custom code?

  1. AUse an Amazon Cognito user pool with social providers and a Cognito authorizer on the API
  2. BUse IAM Identity Center for customer sign-in and protect the API methods with IAM authorization
  3. CCreate an IAM user for each customer and have the app sign its API requests with that user's keys
  4. DWrite a Lambda authorizer that checks passwords against a DynamoDB table of customer accounts
Show the answer and why
  • AUse an Amazon Cognito user pool with social providers and a Cognito authorizer on the API

    Correct

    A user pool provides sign-up and sign-in, including social providers, and API Gateway can check its tokens with a Cognito user pool authorizer.

  • BUse IAM Identity Center for customer sign-in and protect the API methods with IAM authorization

    Incorrect

    IAM Identity Center connects workforce users to AWS accounts and applications. It is not a sign-up service for an app's customers.

  • CCreate an IAM user for each customer and have the app sign its API requests with that user's keys

    Incorrect

    IAM users have long-term credentials, which would sit inside every copy of the app. AWS recommends against long-term credentials where temporary ones can be used.

  • DWrite a Lambda authorizer that checks passwords against a DynamoDB table of customer accounts

    Incorrect

    It can work, but you would build and secure sign-up, password storage and social sign-in yourself, which Cognito already provides.

Customer identity for an app is Amazon Cognito; workforce identity is IAM Identity Center. API Gateway accepts Cognito user pool tokens directly.

Question 7 · choose 1

A company must connect its data center to a VPC within a few days. Traffic must be encrypted, the link must use the company's existing internet connection, and it must stay up when one AWS endpoint of the link is down for maintenance. Which solution meets these requirements?

  1. AOrder an AWS Direct Connect dedicated connection and attach a private virtual interface to the VPC
  2. BCreate an AWS Site-to-Site VPN connection and configure both tunnels on the customer gateway
  3. CSet up AWS Client VPN and install the VPN client software on each server in the data center
  4. DCreate a VPC peering connection between the VPC and the CIDR range of the data center network
Show the answer and why
  • AOrder an AWS Direct Connect dedicated connection and attach a private virtual interface to the VPC

    Incorrect

    Direct Connect is a private link through a Direct Connect location, not the existing internet connection, and it is not IPsec-encrypted unless combined with a VPN.

  • BCreate an AWS Site-to-Site VPN connection and configure both tunnels on the customer gateway

    Correct

    Site-to-Site VPN runs IPsec over the internet. Each connection has two tunnels in different Availability Zones, so traffic moves to the other tunnel during maintenance.

  • CSet up AWS Client VPN and install the VPN client software on each server in the data center

    Incorrect

    Client VPN is a managed remote access service for individual users' devices, not a link between two networks.

  • DCreate a VPC peering connection between the VPC and the CIDR range of the data center network

    Incorrect

    VPC peering connects two VPCs. It cannot connect an on-premises network.

Encrypted, over the internet and quick to set up describes Site-to-Site VPN; configure both tunnels for redundancy. Direct Connect is a dedicated private connection.

Question 8 · choose 1

Workloads in several VPCs may reach only an approved list of internet domain names, such as a package repository and a payment provider. All other outbound traffic must be blocked and inspected statefully. Which AWS service should a solutions architect use?

  1. AAWS Network Firewall with a stateful domain list rule group
  2. BSecurity groups with outbound rules for the approved services
  3. CNetwork ACLs that deny all outbound ports except port 443
  4. DAWS WAF with a rate-based rule on the egress NAT gateway
Show the answer and why
  • AAWS Network Firewall with a stateful domain list rule group

    Correct

    Network Firewall is a stateful network firewall for VPCs, and its domain list rule groups allow or deny traffic by domain name.

  • BSecurity groups with outbound rules for the approved services

    Incorrect

    Security group rules match IP addresses, prefix lists and ports, not domain names.

  • CNetwork ACLs that deny all outbound ports except port 443

    Incorrect

    Network ACLs filter by address and port; allowing 443 lets traffic reach any HTTPS site.

  • DAWS WAF with a rate-based rule on the egress NAT gateway

    Incorrect

    AWS WAF protects web applications behind resources such as load balancers; it does not filter a VPC's outbound traffic.

Outbound filtering by domain name with stateful inspection is a Network Firewall job; security groups and ACLs only see addresses and ports.

Question 9 · choose 1

A company serves images worldwide from an S3 bucket through Amazon CloudFront. The bucket must not be readable directly from the internet, only through the distribution. What should a solutions architect configure?

  1. AMake the bucket public and attach an AWS WAF web ACL to the CloudFront distribution
  2. BGive each viewer a presigned URL for every image that the bucket serves
  3. CUse origin access control and a bucket policy that allows only the distribution
  4. DAllow the CloudFront edge IP ranges in a bucket policy with an IP condition
Show the answer and why
  • AMake the bucket public and attach an AWS WAF web ACL to the CloudFront distribution

    Incorrect

    WAF filters requests to the distribution, but a public bucket can still be read directly, bypassing CloudFront.

  • BGive each viewer a presigned URL for every image that the bucket serves

    Incorrect

    Presigned URLs grant temporary access to individual objects; they do not tie access to the distribution.

  • CUse origin access control and a bucket policy that allows only the distribution

    Correct

    With OAC, CloudFront sends authenticated requests to S3, and the bucket policy can allow only that distribution.

  • DAllow the CloudFront edge IP ranges in a bucket policy with an IP condition

    Incorrect

    This is not how CloudFront authenticates to S3; the documented mechanisms are origin access control and the older origin access identity.

Keep the bucket private and let CloudFront authenticate to it with origin access control.

Question 10 · choose 1

Administrators connect to Linux EC2 instances in private subnets through a bastion host with SSH keys. The security team wants to close all inbound ports, stop managing SSH keys, control access with IAM, and log every session. What should a solutions architect recommend?

  1. AReplace the bastion host with an AWS Client VPN endpoint for the admins
  2. BMove the bastion host into a private subnet and keep port 22 restricted
  3. CGive each instance a public IP address with SSH allowed only from the office
  4. DUse AWS Systems Manager Session Manager and remove the bastion host
Show the answer and why
  • AReplace the bastion host with an AWS Client VPN endpoint for the admins

    Incorrect

    Client VPN gives users network access to the VPC, but the instances still need SSH open and keys managed.

  • BMove the bastion host into a private subnet and keep port 22 restricted

    Incorrect

    Admins could no longer reach it from outside, and SSH keys and an open port 22 remain.

  • CGive each instance a public IP address with SSH allowed only from the office

    Incorrect

    This exposes every instance to the internet and keeps SSH keys to manage.

  • DUse AWS Systems Manager Session Manager and remove the bastion host

    Correct

    Session Manager reaches managed instances without inbound ports, bastion hosts or SSH keys, with access controlled by IAM and sessions logged.

No inbound ports, no keys, IAM control and session logs: that is Session Manager.

Question 11 · choose 1

Web servers in a public subnet accept HTTPS from the internet. The team replaced the default network ACL with a custom one that allows inbound TCP 443 from 0.0.0.0/0 and has no other rules except the default deny. Security groups allow 443 inbound. Clients now time out. Which change fixes the problem?

  1. AAdd an outbound security group rule that allows the responses to the clients
  2. BAdd an outbound network ACL rule allowing responses to client ephemeral ports
  3. CAdd an inbound network ACL rule that allows the clients' ephemeral port range
  4. DAdd a route to the internet gateway in the route table of the public subnet
Show the answer and why
  • AAdd an outbound security group rule that allows the responses to the clients

    Incorrect

    Security groups are stateful, so responses to allowed inbound traffic leave regardless of outbound rules.

  • BAdd an outbound network ACL rule allowing responses to client ephemeral ports

    Correct

    Network ACLs are stateless, so responses to inbound traffic need their own outbound rule to the clients' ephemeral port range.

  • CAdd an inbound network ACL rule that allows the clients' ephemeral port range

    Incorrect

    The requests already arrive on 443. What is missing is the return path out of the subnet.

  • DAdd a route to the internet gateway in the route table of the public subnet

    Incorrect

    The subnet is already public and traffic reaches the servers; the problem is the stateless filter on the way out.

Stateless network ACLs need rules for both directions. Security groups track connections; network ACLs do not.

Question 12 · choose 1

A company wants to be alerted when any of its EC2 instances communicates with a known command-and-control server or cryptocurrency-mining host, using a managed service that needs no agents to start detecting. Which service should it turn on?

  1. AAmazon Inspector
  2. BAmazon Macie
  3. CAmazon GuardDuty
  4. DAWS Config
Show the answer and why
  • AAmazon Inspector

    Incorrect

    Inspector scans workloads for software vulnerabilities and unintended network exposure, not for live malicious traffic.

  • BAmazon Macie

    Incorrect

    Macie discovers sensitive data in S3; it does not watch EC2 network activity.

  • CAmazon GuardDuty

    Correct

    GuardDuty analyzes data sources such as VPC flow logs and DNS logs and reports findings like instances querying command-and-control servers or running bitcoin tools.

  • DAWS Config

    Incorrect

    Config records and evaluates resource configurations, not the traffic an instance sends.

Detecting compromised behavior from logs is GuardDuty; finding vulnerable software is Inspector.

Practise domain 1 →Practise all domains →