DOP-C02 Resilient Cloud Solutions Practice Question
A company hosts a static website on Amazon S3 with a CloudFront distribution. The website is critical for business operations and must be available even if the primary AWS Region fails. Currently, the S3 bucket is in us-east-1, and CloudFront uses that bucket as the origin. The company has a secondary bucket in us-west-2 with a replica of the data. The company wants to use CloudFront to automatically fail over to the secondary bucket if the primary becomes unavailable. The DevOps engineer needs to implement a solution that requires minimal operational overhead. What should the engineer do?
⚠ Common exam trap
The trap here is that candidates often reach for Route 53 failover or Lambda@Edge because they are familiar multi-region patterns, missing that CloudFront Origin Failover is a built-in, zero-overhead feature designed exactly for this scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure CloudFront Origin Failover by adding both buckets as origins, with the primary in us-east-1 and secondary in us-west-2.
CloudFront Origin Failover is a native feature that allows you to designate a primary and secondary origin within a single distribution; CloudFront automatically routes requests to the secondary origin when the primary returns specific error codes (e.g., 500, 502, 503, 504) or fails health checks. This requires no additional infrastructure, no DNS changes, and no custom code, making it the lowest-operational-overhead solution. It directly meets the requirement of automatic failover to the us-west-2 bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an Application Load Balancer in front of both S3 buckets and point CloudFront to the ALB.
Why it's wrong here
An Application Load Balancer cannot use S3 buckets as targets; ALB target groups support only EC2 instances, IP addresses, or Lambda functions, so this architecture would require an additional proxy or custom origin service to bridge to S3. Even if you placed a reverse proxy behind the ALB, the design adds a stateful compute layer, extra network hop, and ongoing operational overhead, which contradicts the requirement for minimal management of a static-site failover. CloudFront already provides native S3 integration and origin failover, making the ALB both technically invalid and unnecessarily complex.
- ✗
Create a second CloudFront distribution pointing to the secondary bucket and use Route 53 failover routing between the two distributions.
Why it's wrong here
Deploying a second CloudFront distribution and using Route 53 failover routing introduces a DNS-level decision point that can take several minutes to propagate due to TTL settings, causing a visible outage during failover. Each distribution is a separate cache tier, so you would need to manage two origins, two cache policies, and two certificates, increasing cost and operational burden. CloudFront origin failover, by contrast, happens at the edge node instantaneously based on HTTP response codes, with no dependency on DNS caches or additional distribution configuration. Route 53 health checks also cannot directly health-check a CloudFront distribution's origin; they would require an external endpoint, adding yet more moving parts.
- ✗
Modify the application to switch the CloudFront origin URL using Lambda@Edge when health checks fail.
Why it's wrong here
Modifying the application to switch the CloudFront origin URL via Lambda@Edge on health-check failure introduces custom code that must be maintained, tested, and deployed, contradicting the requirement for minimal operational overhead. This approach is tempting because Lambda@Edge can indeed inspect responses and redirect requests at the edge, making it a valid solution for custom origin failover logic when CloudFront’s native origin group feature—which automatically handles failover between primary and secondary S3 origins without any application code—is not used.
- ✓
Configure CloudFront Origin Failover by adding both buckets as origins, with the primary in us-east-1 and secondary in us-west-2.
Why this is correct
CloudFront Origin Failover is the native, minimal-configuration solution: you create an origin group containing two S3 buckets as the primary and secondary origins, and attach that group to your cache behavior. When the primary origin returns a configurable HTTP error code (commonly 5xx) or a connection timeout, CloudFront automatically retries the request against the secondary bucket in us-west-2, all within the same edge location and without involving DNS or custom code. This requires no additional compute, no Route 53 policies, and no application modifications—only enabling Cross-Region Replication between the two buckets so content stays consistent. It is the only option that leverages a built-in CloudFront feature designed specifically for this use case, meeting both the fault-tolerance and low-operational-overhead requirements.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.