Objective 1.2

SAA-C03

Design secure workloads and applications.

Objective 1.2 sits in Design Secure Architectures, which carries 30% of the Solutions Architect Associate exam. The questions below are original, written from the official objective title above, and each explanation cites the Amazon Web Services (AWS) page it rests on.

Objective title verbatim from the official objectives. Amazon Web Services (AWS) exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

1-2Design Secure Architectures

A team allows 443 inbound on the security group and on a custom network ACL for the subnet. Clients still time out. What is missing?

An outbound NACL rule for ephemeral portsCorrect · your answerCorrect. Responses exit the subnet from ports 1024 to 65535, and the inbound entry for 443 says nothing about them.
An inbound NACL rule for ephemeral portsTraffic on the way in is already permitted on 443. Widening the client range inward would matter on a subnet that holds the calling side.
An outbound security group rule for port 443Security groups track the request and let its reply back on their own, which is why no second entry is needed there.
A second NACL associated with that subnetA subnet holds one association at a time. Attaching another simply replaces the first and evaluates nothing extra.

Correct.

Checked against docs.aws.amazon.com, August 2026

Concept

A filter that keeps no state has to be told about both halves of a conversation. The reply to a permitted request is another packet arriving at the boundary, matched against its own entries.

Why A

Replies leave the subnet from a high numbered client port picked by the requester, so the subnet boundary needs an entry permitting that range in the leaving direction.

Source

NACLs are stateless, which means that information about previously sent or received traffic is not saved. If, for example, you create a NACL rule to allow specific inbound traffic to a subnet, responses to that traffic are not automatically allowed…

AWS docs: Network ACLs, checked August 2026
#vpc#network-acl#stateless#ephemeral-ports

Now you: objective 1.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

1-2Design Secure Architectures

A team must stop one abusive source address from reaching any instance in a subnet, without listing every other client. Which control does that?

Sample question 2 of 3

1-2Design Secure Architectures

A web app carries database credentials in its source code. Your security team wants them rotated on a schedule without a redeploy. What do you use?

Sample question 3 of 3

1-2Design Secure Architectures

A mobile app signs users in through a Cognito user pool. The app must now upload objects to S3 as those users. What supplies the AWS credentials?

Full Solutions Architect Associate question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Design Secure Architectures