Courseiva

DOP-C02 Resilient Cloud Solutions Practice Question

A company is using Amazon RDS for MySQL with Multi-AZ deployment. During a recent failover, the application experienced a brief downtime because the DNS cache on the application servers still pointed to the old primary. How can a DevOps engineer minimize this downtime?

⚠ Common exam trap

Test-takers frequently think increasing TTL or using a different endpoint will help, but the real issue is DNS cache staleness, which RDS Proxy bypasses entirely by managing connections at the proxy layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an RDS Proxy to manage connections and reduce DNS dependency.

RDS Proxy acts as a connection broker that maintains persistent connections to the database and abstracts the underlying DNS changes during failover. When a failover occurs, RDS Proxy automatically reconnects to the new primary without requiring the application to resolve a new DNS record, thereby eliminating the downtime caused by stale DNS caches. This reduces the application's dependency on DNS resolution and provides faster failover recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use an RDS Proxy to manage connections and reduce DNS dependency.

    Why this is correct

    RDS Proxy sits between your application and the database, exposing a fixed writer endpoint that masks the underlying instance DNS changes. When a Multi-AZ failover occurs, RDS Proxy automatically redirects existing connections to the new primary, which eliminates the delay caused by clients waiting for DNS TTL to expire. It also pools and reuses database connections, reducing connection-related errors during failover and lowering CPU/memory pressure on the database. This is exactly why it reduces DNS dependency and delivers failover times typically under one second.

  • ✗

    Configure the application to use the Multi-AZ endpoint instead of the primary endpoint.

    Why it's wrong here

    Multi-AZ deployment does not create a separate 'Multi-AZ endpoint' that your application can target; you still connect to the same RDS DNS CNAME (e.g., mydb.xxxx.rds.amazonaws.com). On failover, Amazon RDS updates that CNAME to point to the new primary instance, so your application never needs to switch to a different hostname. There is no such thing as a distinct Multi-AZ address in the RDS API or console, so configuring the app to use one is impossible and would provide no benefit.

  • ✗

    Configure application servers to use a hardcoded IP address instead of the RDS endpoint.

    Why it's wrong here

    Hardcoding an IP address defeats the purpose of a managed database, because RDS instance IP addresses are not static and can change during failover, patch/maintenance windows, or after a restore. The DNS endpoint is a CNAME that gets updated during Multi-AZ failover; a hardcoded IP would keep pointing to the old, now-unavailable instance. This approach would cause total loss of connectivity until a manual configuration change is made, making it strictly worse than using the standard RDS endpoint.

  • ✗

    Increase the TTL on the RDS DNS record.

    Why it's wrong here

    Increasing the TTL on the RDS DNS record is not a supported or effective fix, because Amazon RDS manages the DNS record's TTL and the CNAME is automatically refreshed with a new IP on failover. If a client cached the old A record, a higher TTL would keep it sending traffic to the failed primary for an even longer period, extending downtime. Lower TTL values help clients discover the new primary faster, but even this is inferior to RDS Proxy, which avoids client-side DNS resolution during failover entirely.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.