Multi-AZ Deployment for AZ Failure Resilience
A company has a stateless web application on EC2 instances behind an ALB. They want to ensure that if an entire Availability Zone fails, the application remains available with minimal impact. Which architecture best meets this requirement?
Quick Answer
The correct architecture is to deploy the application in two Availability Zones with an Auto Scaling group and an Application Load Balancer that is enabled for multiple AZs. This design ensures that if an entire Availability Zone fails, the ALB automatically reroutes traffic to healthy instances in the remaining AZ, while the Auto Scaling group replaces lost capacity in the surviving zones, providing true Multi-AZ deployment for Availability Zone failure resilience. On the AWS Certified DevOps Engineer Professional DOP-C02 exam, this question tests your understanding of high-availability patterns versus disaster recovery—a common trap is assuming a single-AZ ALB is sufficient, but the ALB itself becomes a single point of failure if not multi-AZ enabled. Remember the memory tip: “Two AZs for the app, multi-AZ for the ALB—both must span zones to survive a zone outage.”
⚠ Common exam trap
DOP-C02 often tests the misconception that a single-AZ ALB can provide high availability if EC2 instances are in multiple AZs, but the ALB itself is a single point of failure; candidates must remember that the ALB must also be enabled for multiple AZs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the application in two AZs with an Auto Scaling group and an ALB that is enabled for multiple AZs
The correct architecture deploys the stateless application across two Availability Zones using an Auto Scaling group that spans both AZs, and an Application Load Balancer (ALB) configured with subnets in both AZs. If one AZ fails, the ALB automatically routes traffic to healthy instances in the surviving AZ, and the Auto Scaling group maintains capacity. This provides high availability with minimal impact, as required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a global secondary index in DynamoDB to replicate data across regions
Why it's wrong here
A global secondary index (GSI) in DynamoDB is used to improve query performance, not to provide high availability for compute resources. The application is stateless on EC2, so the focus should be on multi-AZ deployment for the compute layer.
- ✗
Deploy EC2 instances in two AZs but use a single-AZ ALB
Why it's wrong here
A single-AZ ALB has its load balancer nodes in one AZ, so that AZ's failure removes the entry point even though instances remain in two AZs. Single-AZ load balancers suit cost-sensitive or non-production workloads where cross-AZ resilience is not required.
- ✓
Deploy the application in two AZs with an Auto Scaling group and an ALB that is enabled for multiple AZs
Why this is correct
Spreading instances across two Availability Zones with an Auto Scaling group lets it replace capacity in the surviving AZ, while the multi-AZ ALB routes only to healthy targets. This satisfies the AZ-failure constraint by removing the single-AZ dependency and enabling automatic recovery.
- ✗
Deploy the application in a single AZ with an Auto Scaling group that launches instances in the same AZ
Why it's wrong here
A single-AZ deployment places both the Auto Scaling group and its instances in one AZ, so that AZ's failure takes down every instance with no capacity elsewhere. Single-AZ Auto Scaling suits dev, test, or stateless workloads where AZ-failure tolerance is explicitly not required.
Visual reference
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's application runs on EC2 instances in a single Availability Zone. The operations team wants to improve resilience without redesigning the application. Which action is the MOST effective?
easy- A.Use a larger instance type to handle more traffic.
- B.Enable EC2 Auto Recovery to automatically restart the instance if it fails.
- ✓ C.Deploy EC2 instances across multiple Availability Zones using an Auto Scaling group.
- D.Place the instance in a placement group to ensure low latency.
Why C: Deploying EC2 instances across multiple Availability Zones (AZs) using an Auto Scaling group is the most effective action because it eliminates the single point of failure at the AZ level. If one AZ experiences an outage, the Auto Scaling group automatically launches replacement instances in the remaining healthy AZs, ensuring application availability without requiring any application-level changes. This directly addresses the goal of improving resilience by leveraging AWS's fault-isolated infrastructure.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.