Courseiva

Connection Draining for Zero-Downtime Deployments

A company runs a stateless web application on AWS Lambda behind an Application Load Balancer (ALB). During a deployment, the team updates the Lambda function to a new version. Some users report seeing the old version of the application for several minutes after the deployment. What is the MOST likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ALB target group is still pointing to the old Lambda function version due to connection draining.

When an ALB is used with Lambda, the ALB invokes a specific Lambda function version or alias. If the deployment updates the Lambda function but the ALB target group alias is not updated atomically, or if connection draining keeps old connections active, some requests may still be routed to the old version. This can cause users to see the old application for several minutes. Option A is wrong because Lambda versions are immutable, so gradual rollout is not related. Option B is wrong because Lambda@Edge is not used in this setup (the application runs behind an ALB, not CloudFront). Option C is wrong because CloudFront is not mentioned in the architecture—the traffic goes directly from ALB to Lambda.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Lambda function versions are not immutable, causing a gradual rollout.

    Why it's wrong here

    Lambda published versions are immutable by design; once published, they cannot be modified. A gradual rollout is typically achieved through alias-based traffic shifting, not because versions are mutable. The observed behavior in this scenario is explained by ALB connection draining, which allows in-flight requests to complete on the old version before the target group fully switches to the new version.

  • ✗

    Lambda@Edge is overriding the function version at the edge locations.

    Why it's wrong here

    Lambda@Edge is exclusively used with Amazon CloudFront distributions to run functions at edge locations. This architecture uses an Application Load Balancer as the entry point, so Lambda@Edge is not involved. Even if it were present, Lambda@Edge does not override function versions; it explicitly routes to a specified version or alias, and no edge-level override mechanism exists here.

  • ✗

    Amazon CloudFront is caching the old response and has not been invalidated.

    Why it's wrong here

    The architecture's entry point is an Application Load Balancer, not Amazon CloudFront, and ALBs do not cache HTTP responses. CloudFront caching would only be relevant if the distribution sat in front of the application, and you would need to invalidate the cache to purge stale responses. Since no CloudFront distribution is present, stale cache responses cannot be the cause of the issue.

  • ✓

    The ALB target group is still pointing to the old Lambda function version due to connection draining.

    Why this is correct

    ALB invokes Lambda functions via a target group that references a specific function version or alias. When you publish a new version and update the target group, ALB's connection draining process allows existing in-flight connections to complete on the old version before deregistering it. As a result, the old Lambda version can continue serving requests for a short period, causing a temporary gradual rollout until draining finishes.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.