Courseiva

DOP-C02 Resilient Cloud Solutions Practice Question

A company runs a microservices architecture on Amazon ECS. They want to ensure that if a service fails, it does not cascade to other services. Which TWO design patterns should they implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Circuit breaker pattern

The circuit breaker pattern (C) is correct because it wraps calls to a failing downstream microservice and, after a threshold of failures, trips open to fail fast instead of repeatedly invoking the unhealthy service, preventing a localized failure from cascading through the call chain. The bulkhead pattern (E) is correct because it isolates resources such as thread pools, connection pools, or ECS tasks per service or dependency, so exhaustion or failure in one component cannot consume shared capacity and take down other services. Together these patterns directly address fault isolation and cascade prevention in a microservices architecture on Amazon ECS. The cache-aside pattern (A) only improves read performance and reduces backend load by populating a cache on demand; it does not stop failure propagation. The Saga pattern (B) manages distributed transaction consistency across services via compensating actions, which is about data integrity rather than preventing cascading failures. The throttling pattern (D) limits request rates to protect a service from overload, but it is a rate-control mechanism and not the primary isolation pattern for stopping cross-service failure cascades.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cache-aside pattern

    Why it's wrong here

    Cache-aside reduces read load on a backing store by having the application populate and query a cache; it does nothing to contain failures between services, since a caller still blocks on the failing dependency. It is tempting because it is a genuine resilience-adjacent pattern, and it would be the right pick when the goal is cutting database read latency or protecting a data store from repeated identical queries.

  • ✗

    Saga pattern

    Why it's wrong here

    Saga pattern coordinates distributed transactions across multiple services by breaking them into local transactions with compensating actions, ensuring eventual consistency without a distributed transaction manager. It addresses data consistency and atomicity concerns, but it is not a resilience pattern for failure isolation; it does not stop or limit calls to a failing service, so it cannot prevent the failure from propagating to other components.

  • ✓

    Circuit breaker pattern

    Why this is correct

    Circuit breaker pattern monitors calls to a remote service and maintains three states—closed, open, and half-open—progressing to open when failure thresholds are exceeded, at which point subsequent calls fail fast without attempting the network operation. This prevents a failing service from being overwhelmed and stops the same repeated errors from saturating caller resources, thereby breaking the chain of cascading failures and giving the dependency time to recover.

  • ✗

    Throttling pattern

    Why it's wrong here

    Throttling pattern (or rate limiting) intentionally caps the number of requests or concurrent operations a service can handle, often using queues to smooth bursts and protect the service from overload. However, throttling applies limits uniformly regardless of a dependency's health; it reduces load but does not distinguish a failing upstream service or divert traffic away from it, so it doesn't prevent cascading failures in a microservices mesh.

  • ✓

    Bulkhead pattern

    Why this is correct

    Bulkhead pattern isolates each downstream dependency or service into its own thread pool, connection pool, or other resource partition, based on the ship-building design of watertight compartments. If one service exhausts or fails its pool, other pools remain unaffected, limiting the blast radius of the failure; this is a form of resource-level fault containment that complements circuit breakers.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.