Courseiva

SAA-C03 · topic practice

Design Resilient Architectures practice questions

This domain covers designing systems that stay available through failures and recover quickly, using Multi-AZ RDS, Route 53 failover routing, S3 cross-region replication, and DR strategies like pilot light and warm standby. Questions test matching RTO/RPO requirements and latency goals to the right AWS services and redundancy patterns.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design Resilient Architectures

What the exam tests

What to know about Design Resilient Architectures

Be able to map availability, latency, and DR requirements to specific AWS services: Multi-AZ for failover, read replicas for read scaling, Global Accelerator for UDP/static IP, and the correct DR strategy for given RTO/RPO and cost constraints.

Configuring RDS Multi-AZ for automatic failover and read replicas for low-latency reads

Using Route 53 health checks and failover routing to redirect traffic during outages

Selecting Global Accelerator for static anycast IPs and UDP-based global latency reduction

Choosing DR strategies (backup/restore, pilot light, warm standby, multi-site) by RTO/RPO

Watch out for

Common Design Resilient Architectures exam traps

  • ▸Assuming Multi-AZ RDS read replicas serve read traffic; Multi-AZ standby does not serve reads, while read replicas do but are not automatic failover targets.
  • ▸Confusing CloudFront with Global Accelerator for UDP or static IP needs; CloudFront is HTTP/HTTPS only and uses dynamic edge IPs.
  • ▸Picking a DR strategy that meets RTO/RPO but ignores cost; warm standby is cheaper than multi-site but pilot light may miss tight RTOs.

Practice set

Design Resilient Architectures questions

20 questions · select your answer, then reveal the explanation

An enterprise application runs on Amazon EC2 instances managed by an Auto Scaling group behind an Application Load Balancer. The application experiences unpredictable traffic spikes, and instances occasionally fail health checks due to heavy load during startup. How should the Solutions Architect configure the Auto Scaling group to ensure high availability and prevent premature termination of booting instances?

Refer to the exhibit. A Solutions Architect applied an Amazon S3 bucket policy to restrict data access exclusively to a specific VPC endpoint. However, after applying the policy, legitimate applications running inside the authorized VPC endpoint are completely blocked from accessing the bucket. What is the cause of this failure?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowReadFromSpecificVPC",
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": [
        "arn:aws:s3:::my-secure-bucket",
        "arn:aws:s3:::my-secure-bucket/*"
      ],
      "Condition": {
        "StringNotEquals": {
          "aws:SourceVpce": "vpce-1a2b3c4d"
        }
      }
    }
  ]
}

A developer is building a serverless application with unpredictable, intermittent traffic patterns. The database must scale capacity automatically to handle bursts and shut down during periods of inactivity to save costs. Which database service is most appropriate?

A solutions architect is designing a VPC for a highly resilient application across three Availability Zones. The application needs outbound internet access for updates but must not be reachable from the internet. Which TWO components are required?

Refer to the exhibit. A solutions architect is reviewing the bucket policy for a sensitive data repository. What is the effect of this policy?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowSSLRequestsOnly",
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": [
        "arn:aws:s3:::my-secure-bucket",
        "arn:aws:s3:::my-secure-bucket/*"
      ],
      "Condition": {
        "Bool": {
          "aws:SecureTransport": "false"
        }
      }
    }
  ]
}

Refer to the exhibit. The Auto Scaling group is configured with the 'OldestInstance' termination policy. If a scale-in event occurs, which instance will the ASG terminate first?

Exhibit

{
  "AutoScalingGroups": [
    {
      "AutoScalingGroupName": "production-asg",
      "TerminationPolicies": [
        "OldestInstance",
        "Default"
      ],
      "AvailabilityZones": ["us-east-1a", "us-east-1b"],
      "Instances": [
        {"InstanceId": "i-111", "AvailabilityZone": "us-east-1a", "LaunchTime": "2023-01-01T10:00:00Z"},
        {"InstanceId": "i-222", "AvailabilityZone": "us-east-1a", "LaunchTime": "2023-01-01T12:00:00Z"},
        {"InstanceId": "i-333", "AvailabilityZone": "us-east-1b", "LaunchTime": "2023-01-01T08:00:00Z"}
      ]
    }
  ]
}

An application uses an Auto Scaling group with instances across three Availability Zones. The architect wants to ensure the application remains available even if one AZ experiences a total network isolation. What is the most effective way to ensure this?

A company wants to ensure high availability for their application. Which THREE of these services are inherently regional in their high-availability configuration?

An enterprise financial application runs on a fleet of Amazon EC2 instances behind an Application Load Balancer. The database layer utilizes Amazon RDS for PostgreSQL with Multi-AZ enabled. During routine maintenance or unexpected hardware degradation, connections to the database drop, causing user transactions to fail intermittently. How should the architect redesign the data tier for better fault tolerance?

A company hosts a web application on EC2 instances behind an Application Load Balancer (ALB). The application requires high availability across two Availability Zones. Which configuration ensures the most resilient traffic distribution?

Refer to the exhibit. An application running on EC2 needs to store backups in an S3 bucket. The administrator applied the policy in the exhibit, but the EC2 instance cannot upload objects. What is the most likely cause?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:PutObject"],
      "Resource": ["arn:aws:s3:::my-resilient-bucket/*"]
    }
  ]
}

A company wants to ensure that its Amazon EBS volumes are protected against data loss due to an Availability Zone failure. What is the most effective solution?

An application relies on a message queue to decouple services. The architect wants to ensure that messages are not lost if the queue service is temporarily unavailable. What should be done?

An architect is designing a web application and wants to ensure that static assets are delivered with low latency and high availability. Which THREE actions are recommended? (Select THREE.)

Refer to the exhibit. An application uses an Amazon S3 bucket to store critical backup files. The architect needs to ensure that these backups are protected from accidental deletion and that the bucket itself is highly available. Which configuration should the architect implement?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-resilient-bucket/*"
    }
  ]
}

A financial services company is hosting a critical web application on Amazon EC2 instances behind an Application Load Balancer. The application must remain available even if an entire AWS Region experiences a major outage. The database tier uses Amazon Aurora Global Databases. Which solution provides the most resilient multi-Region architecture with automated failover?

A media streaming company stores high-value video assets in an Amazon S3 bucket. The company requires a resilient storage architecture that protects against accidental deletion, malicious overwrites, and zonal or regional outages. Which combinations of features should a Solutions Architect implement to achieve these requirements? (Choose TWO.)

Question 18mediummultiple choice
Review the full routing breakdown →

A company hosts a web application on EC2 instances behind an Application Load Balancer. The application stores session state in local memory, causing users to be logged out whenever the load balancer routes requests to different instances. Which solution provides the most resilient, scalable architecture to resolve this?

A company's web application requires a highly available database layer to survive an Availability Zone failure without manual intervention. The database must remain accessible during maintenance windows and ensure zero data loss. Which solution meets these requirements with the least operational overhead?

Question 20mediummultiple choice
Review the full routing breakdown →

An application is deployed across two AWS Regions to ensure resilience. The architect needs to direct users to the healthy region with the lowest latency. If the primary region fails, traffic should fail over automatically. Which Route 53 routing policy should be implemented?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design Resilient Architectures sessions

Start a Design Resilient Architectures only practice session

Every question in these sessions is drawn from the Design Resilient Architectures domain — nothing else.

Related practice questions

Related SAA-C03 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SAA-C03 exam test about Design Resilient Architectures?
Be able to map availability, latency, and DR requirements to specific AWS services: Multi-AZ for failover, read replicas for read scaling, Global Accelerator for UDP/static IP, and the correct DR strategy for given RTO/RPO and cost constraints.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design Resilient Architectures questions in a focused session?
Yes — the session launcher on this page draws every question from the Design Resilient Architectures domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SAA-C03 topics?
Use the topic links above to move to related areas, or go back to the SAA-C03 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SAA-C03 exam covers. They are not copied from any real exam or dump site.