Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer is designing an AWS CloudFormation template to deploy a three-tier web application. The application must be highly available across multiple Availability Zones. The engineer needs to ensure that the database layer uses a Multi-AZ deployment. Which TWO options should the engineer implement to meet these requirements? (Choose TWO.)

⚠ Common exam trap

Watch out — candidates often assume any database engine can be made Multi-AZ by simply setting the flag, but the exam tests the knowledge that engines like Aurora have a different architecture and require a cluster-based approach, not the standard MultiAZ property.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Select a database engine that supports Multi-AZ deployments.

Not all AWS RDS database engines support Multi-AZ deployments; for example, Amazon Aurora uses a different high-availability mechanism (cluster volume) and does not use the standard Multi-AZ feature. The engineer must verify that the chosen engine (e.g., MySQL, PostgreSQL, Oracle, SQL Server) explicitly supports Multi-AZ to enable synchronous standby replication across Availability Zones. Option E is correct because setting the 'MultiAZ' property to 'true' on the 'AWS::RDS::DBInstance' resource directly instructs CloudFormation to provision a primary DB instance in one AZ and a standby in another AZ, with automatic failover.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Define a separate 'AWS::RDS::DBSubnetGroup' resource with subnets from at least two Availability Zones.

    Why it's wrong here

    While a DB subnet group spanning at least two AZs is a prerequisite for RDS Multi-AZ, simply creating the subnet group does not make the DB instance highly available. The instance will remain single-AZ unless the DBInstance's MultiAZ property is set to true (or the engine defaults to Multi-AZ). This option confuses a networking prerequisite with the actual failover configuration.

  • ✗

    Deploy the database with multiple read replicas in different Availability Zones.

    Why it's wrong here

    Read replicas are asynchronous copies used to offload read traffic; they do not provide automatic failover for the primary DB instance. If the primary fails, a read replica must be manually promoted, which incurs downtime and data loss risk. Multi-AZ uses synchronous physical replication to a standby in another AZ, enabling automatic failover without application changes. Thus replicas alone do not satisfy the Multi-AZ requirement.

  • ✓

    Select a database engine that supports Multi-AZ deployments.

    Why this is correct

    Multi-AZ availability is not universally available across all RDS database engines; for example, Microsoft SQL Server supports Multi-AZ only on Enterprise or Standard editions (and not on Express/Web), while Oracle requires Enterprise Edition. If an engine/edition lacks Multi-AZ support, setting MultiAZ=true in CloudFormation will fail validation or be ignored. Therefore, confirming engine support is a necessary prerequisite before enabling Multi-AZ in the template.

  • ✗

    Configure the database to use a DB subnet group with subnets in a single Availability Zone.

    Why it's wrong here

    A subnet group confined to a single Availability Zone cannot host a standby in a different AZ, so RDS Multi-AZ cannot be enabled. The DBInstance would be single-AZ and vulnerable to AZ-level failures. Multi-AZ requires a subnet group with subnets in at least two AZs; a single-AZ subnet group is fundamentally incompatible with the failover architecture.

  • ✓

    Set the 'MultiAZ' property of the 'AWS::RDS::DBInstance' resource to 'true'.

    Why this is correct

    In CloudFormation, the MultiAZ property on AWS::RDS::DBInstance is the direct switch that provisions a synchronously replicated standby in another AZ. When set to true, RDS automatically handles failover, and the CNAME/endpoint is updated to point to the standby if the primary fails. This is a correct way to design a Multi-AZ deployment, provided the chosen engine and subnet group support it.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.