Connection Draining for Zero-Downtime Deployments
A company runs a stateless web application on AWS Lambda behind an Application Load Balancer (ALB). During a deployment, the team updates the Lambda function to a new version. Some users report seeing the old version of the application for several minutes after the deployment. What is the MOST likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ALB target group is still pointing to the old Lambda function version due to connection draining.
When an ALB is used with Lambda, the ALB invokes a specific Lambda function version or alias. If the deployment updates the Lambda function but the ALB target group alias is not updated atomically, or if connection draining keeps old connections active, some requests may still be routed to the old version. This can cause users to see the old application for several minutes. Option A is wrong because Lambda versions are immutable, so gradual rollout is not related. Option B is wrong because Lambda@Edge is not used in this setup (the application runs behind an ALB, not CloudFront). Option C is wrong because CloudFront is not mentioned in the architecture—the traffic goes directly from ALB to Lambda.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Lambda function versions are not immutable, causing a gradual rollout.
Why it's wrong here
Lambda published versions are immutable by design; once published, they cannot be modified. A gradual rollout is typically achieved through alias-based traffic shifting, not because versions are mutable. The observed behavior in this scenario is explained by ALB connection draining, which allows in-flight requests to complete on the old version before the target group fully switches to the new version.
- ✗
Lambda@Edge is overriding the function version at the edge locations.
Why it's wrong here
Lambda@Edge is exclusively used with Amazon CloudFront distributions to run functions at edge locations. This architecture uses an Application Load Balancer as the entry point, so Lambda@Edge is not involved. Even if it were present, Lambda@Edge does not override function versions; it explicitly routes to a specified version or alias, and no edge-level override mechanism exists here.
- ✗
Amazon CloudFront is caching the old response and has not been invalidated.
Why it's wrong here
The architecture's entry point is an Application Load Balancer, not Amazon CloudFront, and ALBs do not cache HTTP responses. CloudFront caching would only be relevant if the distribution sat in front of the application, and you would need to invalidate the cache to purge stale responses. Since no CloudFront distribution is present, stale cache responses cannot be the cause of the issue.
- ✓
The ALB target group is still pointing to the old Lambda function version due to connection draining.
Why this is correct
ALB invokes Lambda functions via a target group that references a specific function version or alias. When you publish a new version and update the target group, ALB's connection draining process allows existing in-flight connections to complete on the old version before deregistering it. As a result, the old Lambda version can continue serving requests for a short period, causing a temporary gradual rollout until draining finishes.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.