DOP-C02 Resilient Cloud Solutions Practice Question
A company runs a microservices architecture on Amazon ECS with Fargate. Services communicate via an internal Application Load Balancer. Recently, one service became unavailable due to a memory leak, causing cascading failures in downstream services. What design change would MOST effectively improve resilience and limit the blast radius?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement circuit breaker patterns in the service discovery and client libraries to stop calling unhealthy services.
Implementing a circuit breaker pattern in service discovery and client libraries stops requests to unhealthy services, preventing cascading failures and limiting blast radius. Option A is wrong because increasing memory limits only delays the inevitable failure and does not prevent downstream services from being affected. Option C (connection draining) only affects in-flight requests during deregistration, not active health issues. Option D (auto scaling) helps but does not stop requests from being sent to a failing service; scaling cannot fix a memory leak.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the memory limit for each ECS task to accommodate memory leaks.
Why it's wrong here
Raising the memory limit for each ECS task merely delays the inevitable out-of-memory kill because the root cause—the memory leak—remains unaddressed. In a shared EC2 cluster, increasing per-task limits can reduce scheduling density and enlarge the blast radius when a container ultimately crashes. This approach does not introduce any failure isolation, so dependent services will continue to call into the failing service and experience timeouts, allowing cascading failures to propagate.
- ✓
Implement circuit breaker patterns in the service discovery and client libraries to stop calling unhealthy services.
Why this is correct
Circuit breakers are a client-side resilience pattern that monitor outgoing requests to a dependency and, after exceeding a failure threshold, automatically fail fast without attempting the network call. In an ECS microservices environment with service discovery, this stops unhealthy services from being flooded with retries, preventing latency spikes and thread exhaustion in healthy services. By quarantining the failing service from call traffic, circuit breakers effectively stop cascading failures and allow the unhealthy service time to recover.
- ✗
Enable connection draining on the ALB to allow in-flight requests to complete.
Why it's wrong here
ALB connection draining is designed for graceful deregistration and instance termination, allowing in-flight requests to finish before a target is removed from rotation. It does not prevent other services from initiating new requests to an unhealthy ECS task, nor does it help once the service is already degraded and new calls are still routed to it. Because connection draining only applies to existing connections, it has no ability to stop the propagation of failures to downstream clients.
- ✗
Implement automatic scaling policies for ECS services based on memory utilization.
Why it's wrong here
ECS Service Auto Scaling based on memory utilization adjusts the desired task count only after average memory usage crosses a threshold, which lags behind a fast-spreading memory leak and cannot fix the leak itself. Adding more tasks spreads memory pressure but does not protect clients from calls to tasks that are already failing; scaling may even temporarily mask the problem until the entire cluster's capacity is exhausted. Ultimately, it fails to address the root cause or introduce failure isolation, so cascading failures remain possible.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.