CompTIA Study Materials
AWS Study Materials
AWS Certified Developer Associate AWS Certified Developer Associate
AWS Certified Developer Associate DVA-C02
AWS Certified Solutions Architect Associate AWS Certified Solutions Architect Associate
AWS Certified Solutions Architect Associate SAA-C03
AWS Cloud Practitioner AWS Cloud Practitioner
AWS Cloud Practitioner CLF-C02
Microsoft Study Materials
Microsoft Azure Fundamentals Microsoft Azure Fundamentals
Microsoft Azure Fundamentals AZ-900

Free AWS Certified Solutions Architect Associate SAA-C03 Practice Question

A company has a web application architecture which consists of a load balancer accessible by internet users and web servers that are not publicly exposed. The architecture also includes a database server that contains sensitive information and needs to communicate with the web servers. Which approach should be taken to ensure that data is securely transferred from users to the web application and that the web application has a secure connection to the database server?

  • Activate a common managed DDoS protection service on the load balancer for encryption, and use directory services to manage database server access.

  • Place the database server in a public subnet to enable public internet users to directly access the application database without requiring web server intervention.

  • Set up secured connection protocol listeners for the load balancer and use instance-level security mechanisms to permit data flow only from the web servers to the database server.

  • Use internet gateway and static IP addresses to ensure connection between internet users and the application is consistent and secure.

This question's topic:
AWS Certified Solutions Architect Associate SAA-C03 / 
Design Secure Architectures
Your Score:
Design Secure Architectures
Design Resilient Architectures
Design High-Performing Architectures
Design Cost-Optimized Architectures