
AWSCertified Solutions Architect - Associate
Domain 1Objective 2
Task 1.2: Design Secure Workloads and Applications SAA-C03 Practice Questions (Page 3)
Part of the Design Secure Architectures domain, which makes up ~18% of our current practice bank. AWS does not publish an official question count, but from its 130-minute exam (~50–85 total, ~9–15 in this domain), expect 3–5 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
10concepts
Questions 11–15
- 11
A database instance should not be directly accessible from the internet. In which type of subnet should it be placed?
Select an answer first - 12
A web application is vulnerable to an attack where malicious SQL statements are inserted into an input field. Which AWS service can help mitigate this type of attack?
Select an answer first - 13
A company has instances in a private subnet that need to download software updates from the internet. Which VPC component enables this without allowing inbound connections from the internet?
Select an answer first - 14
A company has a web application behind an Application Load Balancer (ALB). The security team has identified that the application is vulnerable to cross-site scripting (XSS) attacks. The company wants to block these attacks without modifying the application code. Which solution should the solutions architect implement?
Select an answer first - 15
An organization needs to discover and protect sensitive data such as personally identifiable information (PII) stored in Amazon S3. Which AWS service is designed for this use case?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SAA-C03” is a trademark of its owner, used for identification only.