A company runs a global gaming application on Amazon EC2 instances behind an Application Load Balancer in the us-east-1 Region. Players in Europe and Asia report high latency and intermittent connection drops. The company wants to improve the application's performance for global users by routing traffic over the AWS global network. The company also needs two static IP addresses that users can whitelist in their firewalls for consistent access, and the solution must provide health checks to automatically route traffic away from unhealthy endpoints. Which AWS service should the company use?
AWS Global Accelerator uses the AWS global network to route traffic from users to the closest healthy endpoint. It provides two static anycast IP addresses that serve as fixed entry points, which can be whitelisted in firewalls. It also performs health checks and automatically reroutes traffic away from unhealthy endpoints, making it ideal for global performance improvement and reliable access.
Why this answer
AWS Global Accelerator is correct because it uses the AWS global network to route traffic from users to the application, reducing latency and jitter by avoiding the public internet. It provides two static anycast IP addresses that remain consistent for firewall whitelisting, and it integrates with health checks to automatically reroute traffic away from unhealthy EC2 endpoints behind the Application Load Balancer.
Exam trap
The trap here is that candidates often confuse Amazon CloudFront's edge caching with Global Accelerator's network path optimization, assuming CloudFront can provide static IPs and accelerate any TCP/UDP traffic, but CloudFront only accelerates HTTP/HTTPS and does not offer static IP addresses for whitelisting.
Why the other options are wrong
Amazon CloudFront is a CDN that caches content at edge locations, but the question requires two static IP addresses for whitelisting and health checks to route traffic away from unhealthy endpoints. CloudFront does not provide static IP addresses for whitelisting and its health check capabilities are limited to origin failover, not per-endpoint routing.
AWS WAF is a web application firewall that protects against common web exploits, but it does not provide global traffic acceleration, static IP addresses, or health checks for routing traffic away from unhealthy endpoints.
Amazon Route 53 provides DNS resolution and routing policies (e.g., latency-based, geolocation) but does not offer static IP addresses or health checks that automatically route traffic away from unhealthy endpoints at the application layer; it only directs traffic based on DNS, which can be cached and slow to update.
When would these options actually be correct?
A company wants to deliver static or dynamic web content with low latency and high transfer speeds to global users, and needs to offload traffic from origin servers. The question would specify caching requirements, such as reducing load on EC2 instances or serving cached content for repeated requests.
A company wants to protect a web application running behind an Application Load Balancer from SQL injection and cross-site scripting attacks, and needs to block specific IP addresses. AWS WAF would be the correct service to attach to the ALB or CloudFront for these security requirements.
A company wants to route users to the nearest healthy endpoint based on latency or geography using DNS, and does not require static IP addresses or fast failover at the network layer. For example, a web application with multiple regional deployments where DNS caching is acceptable.
Why candidates pick the wrong answer
Candidates may think CloudFront improves latency for global users because it uses edge locations, and they might overlook the specific requirements for static IP addresses and health checks for traffic routing.
Candidates may confuse AWS WAF's ability to filter traffic with the need for global performance improvement, or think that a firewall can also handle traffic routing and acceleration.