DOP-C02 Resilient Cloud Solutions Practice Question
A company is designing a highly available architecture for a web application that uses Amazon EC2 instances. The application must be resilient to the failure of a single instance and a single Availability Zone. Which TWO actions should the company take? (Choose TWO.)
⚠ Common exam trap
It's easy for candidates to think a load balancer alone provides high availability, but they overlook that the load balancer itself must be deployed across multiple AZs (or be a Regional service like ALB with cross-zone load balancing enabled) and that instances must be in at least two AZs to survive an AZ failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an Auto Scaling group with a minimum of two instances spread across two Availability Zones.
An Auto Scaling group with a minimum of two instances spread across two Availability Zones ensures that if one instance or one entire AZ fails, the remaining instance(s) in the other AZ can continue serving traffic, and Auto Scaling will automatically launch a replacement instance in the healthy AZ to restore the desired count. Option B is correct because distributing EC2 instances across at least two Availability Zones is the fundamental requirement for AZ-level resilience, as it eliminates a single point of failure at the AZ boundary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use an Auto Scaling group with a minimum of two instances spread across two Availability Zones.
Why this is correct
An Auto Scaling group with a minimum of two instances across two Availability Zones is the most complete solution because it combines horizontal scaling with automated self-healing. The ASG continuously monitors instance health and automatically replaces failed instances, while distributing the workload across two AZs ensures that a single Availability Zone outage does not eliminate all capacity. This is the gold standard for highly available EC2 architectures.
- ✓
Distribute EC2 instances across at least two Availability Zones.
Why this is correct
Distributing EC2 instances across at least two Availability Zones is a valid high-availability pattern, as it eliminates the single point of failure caused by an AZ outage. However, without a managing service like Auto Scaling, you must manually replace any failed instances, making this approach less operationally resilient from a recovery-time perspective. It is still a sufficient design when combined with a load balancer to route traffic to healthy AZs.
- ✗
Place all EC2 instances in a single Availability Zone and use a Network Load Balancer.
Why it's wrong here
Placing all EC2 instances in a single Availability Zone and using a Network Load Balancer is problematic because the NLB is regional but its targets are all in one AZ, meaning the whole application goes down when that AZ fails. The NLB itself can operate across multiple AZs, but it does not provide any automatic instance replacement or health-based recovery on its own. This configuration leaves the workload vulnerable to a single failure domain.
- ✗
Use a single Application Load Balancer in one Availability Zone.
Why it's wrong here
Using a single Application Load Balancer in one Availability Zone is a critical misconfiguration because you are not only placing all targets in one AZ, but the ALB is also only enabled in one subnet, making the load balancer itself a single point of failure. ALBs are regional services, but they must be enabled across multiple AZs to be highly available—specifying just one subnet removes that resilience. Even if the instances were multi-AZ, the ALB's own single-AZ presence would negate the architecture's fault tolerance.
- ✗
Use a single large EC2 instance in one Availability Zone.
Why it's wrong here
A single large EC2 instance in one Availability Zone offers no resilience at all: any AZ outage, hardware failure, or maintenance event takes the entire workload offline. While an m5.24xlarge may provide ample compute resources, scale-up does not equate to high availability, and there is no automated recovery or load-balanced redundancy. This design ignores the fundamental requirement of distributing workloads across independent failure domains.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is designing a highly available architecture for a stateless web application using AWS services. Which TWO steps should they take to achieve high availability?
medium- A.Store session state in an EBS volume attached to each instance
- ✓ B.Deploy EC2 instances in multiple Availability Zones
- C.Use a single NAT instance in a public subnet
- D.Use only M5 instance types for better performance
- ✓ E.Use an Application Load Balancer to distribute traffic
Why B: Option B is correct because deploying EC2 instances across multiple Availability Zones ensures the application survives an AZ-level failure, which is a fundamental requirement for high availability in AWS. Option E is correct because an Application Load Balancer distributes incoming traffic across healthy targets in multiple AZs, performs health checks, and automatically routes around failed instances, directly supporting high availability for a stateless web tier. Option A is incorrect because storing session state on an EBS volume tied to a single instance creates a single point of failure and is unnecessary for a stateless application. Option C is incorrect because a single NAT instance is itself a single point of failure and cannot provide high availability. Option D is incorrect because choosing a specific instance type like M5 improves performance but does nothing to increase availability.
Variation 2. A company wants to design a resilient architecture for a web application using AWS services. Which of the following is a best practice for improving resilience?
easy- ✓ A.Deploy EC2 instances in multiple Availability Zones.
- B.Use an Auto Scaling group in a single AZ.
- C.Use a single AZ with RDS Multi-AZ.
- D.Use one large EC2 instance to handle all traffic.
Why A: Deploying EC2 instances across multiple Availability Zones (AZs) is a fundamental best practice for resilience because it eliminates a single point of failure at the data center level. If one AZ experiences an outage, traffic can be automatically routed to healthy instances in other AZs via an Elastic Load Balancer (ELB), ensuring application availability. This approach aligns with the AWS Well-Architected Framework's Reliability Pillar, which mandates distributing workloads across multiple AZs to achieve high availability.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.