Courseiva
Resilient Cloud Solutions →mediumMultiple Choice

DOP-C02 Resilient Cloud Solutions Practice Question

A company hosts a static website on Amazon S3 with a CloudFront distribution. The website is critical for business operations and must be available even if the primary AWS Region fails. Currently, the S3 bucket is in us-east-1, and CloudFront uses that bucket as the origin. The company has a secondary bucket in us-west-2 with a replica of the data. The company wants to use CloudFront to automatically fail over to the secondary bucket if the primary becomes unavailable. The DevOps engineer needs to implement a solution that requires minimal operational overhead. What should the engineer do?

⚠ Common exam trap

The trap here is that candidates often reach for Route 53 failover or Lambda@Edge because they are familiar multi-region patterns, missing that CloudFront Origin Failover is a built-in, zero-overhead feature designed exactly for this scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure CloudFront Origin Failover by adding both buckets as origins, with the primary in us-east-1 and secondary in us-west-2.

CloudFront Origin Failover is a native feature that allows you to designate a primary and secondary origin within a single distribution; CloudFront automatically routes requests to the secondary origin when the primary returns specific error codes (e.g., 500, 502, 503, 504) or fails health checks. This requires no additional infrastructure, no DNS changes, and no custom code, making it the lowest-operational-overhead solution. It directly meets the requirement of automatic failover to the us-west-2 bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use an Application Load Balancer in front of both S3 buckets and point CloudFront to the ALB.

    Why it's wrong here

    An Application Load Balancer cannot use S3 buckets as targets; ALB target groups support only EC2 instances, IP addresses, or Lambda functions, so this architecture would require an additional proxy or custom origin service to bridge to S3. Even if you placed a reverse proxy behind the ALB, the design adds a stateful compute layer, extra network hop, and ongoing operational overhead, which contradicts the requirement for minimal management of a static-site failover. CloudFront already provides native S3 integration and origin failover, making the ALB both technically invalid and unnecessarily complex.

  • ✗

    Create a second CloudFront distribution pointing to the secondary bucket and use Route 53 failover routing between the two distributions.

    Why it's wrong here

    Deploying a second CloudFront distribution and using Route 53 failover routing introduces a DNS-level decision point that can take several minutes to propagate due to TTL settings, causing a visible outage during failover. Each distribution is a separate cache tier, so you would need to manage two origins, two cache policies, and two certificates, increasing cost and operational burden. CloudFront origin failover, by contrast, happens at the edge node instantaneously based on HTTP response codes, with no dependency on DNS caches or additional distribution configuration. Route 53 health checks also cannot directly health-check a CloudFront distribution's origin; they would require an external endpoint, adding yet more moving parts.

  • ✗

    Modify the application to switch the CloudFront origin URL using Lambda@Edge when health checks fail.

    Why it's wrong here

    Modifying the application to switch the CloudFront origin URL via Lambda@Edge on health-check failure introduces custom code that must be maintained, tested, and deployed, contradicting the requirement for minimal operational overhead. This approach is tempting because Lambda@Edge can indeed inspect responses and redirect requests at the edge, making it a valid solution for custom origin failover logic when CloudFront’s native origin group feature—which automatically handles failover between primary and secondary S3 origins without any application code—is not used.

  • ✓

    Configure CloudFront Origin Failover by adding both buckets as origins, with the primary in us-east-1 and secondary in us-west-2.

    Why this is correct

    CloudFront Origin Failover is the native, minimal-configuration solution: you create an origin group containing two S3 buckets as the primary and secondary origins, and attach that group to your cache behavior. When the primary origin returns a configurable HTTP error code (commonly 5xx) or a connection timeout, CloudFront automatically retries the request against the secondary bucket in us-west-2, all within the same edge location and without involving DNS or custom code. This requires no additional compute, no Route 53 policies, and no application modifications—only enabling Cross-Region Replication between the two buckets so content stays consistent. It is the only option that leverages a built-in CloudFront feature designed specifically for this use case, meeting both the fault-tolerance and low-operational-overhead requirements.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.