AWS SAA Practice: Design Secure Architectures

SAA-C0312 questions~6 min30% of the exam

Original scenario questions covering IAM policy evaluation, KMS encryption, network isolation, and securing application access for the SAA-C03 exam.

Start quizFree · no account needed
SourceAWS Certified Solutions Architect — Associate
Blueprint
Domain 1 of 4
Weight
30% of SAA-C03
Questions
12 original
AWS pass
720 / 1,000
Written for QuizGen, never copied from the real exam.SAA-C03 exam guidePDF, opens d1.awsstatic.com in a new tab
All SAA-C03 domains4 drills, 12 questions each. Your readiness score then weights them 30/26/24/20, the way the SAA-C03 guide does.

One question, worked through

This is question 12 of the 12 below, solved in the open — deliberately, so you can judge the questions before you play. The other 11 stay hidden until you answer them, then reveal the same explanation.

Worked example

A NACL on a subnet allows all inbound HTTPS. The team adds a NACL rule to block one abusive source IP. Requests from that IP still get through. What is the most likely cause?

  • ASecurity groups override network ACL deny rules
  • BThe deny rule has a higher rule number than the allowCorrect
  • CThe IP must also be removed from the route table
  • DNACLs cannot deny traffic, only allow it

Why B

NACL rules are evaluated in ascending number order and the first match wins, so a broad allow at a lower number matches before the specific deny. Renumbering the deny below the allow makes it take effect; SGs and route tables are unrelated here.

Our blueprint tag — not a source

SAA-C03 · Domain 1 of 4 · Design Secure Architectures

We wrote this question and filed it under that domain. The domain name and its position in the outline come from the SAA-C03 exam guide (PDF, opens d1.awsstatic.com in a new tab).

Play the full quiz

All 12 questions — including the one worked through above — in about 6 minutes. Instant feedback after every answer, and your score stays on this device.

1 / 12
Practice

Question 1

A fintech app has an IAM policy granting a user s3:GetObject on a bucket, but a separate policy on the same user has an explicit Deny on that bucket. What is the effective access?

Tap an answer, or press its letter

After this drill

How ready are you for AWS SAA?

Your attempts across all 4 drills roll up into one blueprint-weighted score, built only from the questions you actually answered. Free, and it stays on this device.

Check your readiness