Courseiva

SAA-C03 Design Resilient Architectures Practice Question

A company hosts an internal API behind an Application Load Balancer (ALB) in two AWS Regions. They want Amazon Route 53 to automatically fail over to the secondary Region when the primary Region’s ALB is unhealthy. Health checks for the primary ALB are already configured, but the DNS record currently uses a latency-based routing policy. Which Route 53 configuration most directly provides automatic failover based on health status?

⚠ Common exam trap

Candidates often confuse latency-based routing with failover routing, assuming latency-based routing inherently provides health-based failover, but it only optimizes for latency and does not automatically reroute based on health status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a Route 53 failover routing policy: configure two alias records for the ALBs where the primary record is marked PRIMARY, the secondary is marked SECONDARY, and each record has an associated health check.

Route 53 failover routing policy is specifically designed to automatically route traffic away from an unhealthy resource to a healthy one. By creating two alias records (one PRIMARY with an associated health check for the primary ALB, and one SECONDARY for the secondary ALB), Route 53 will automatically fail over to the secondary record when the primary health check fails. This directly meets the requirement for automatic failover based on health status, unlike latency-based routing which only optimizes for response time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Keep latency-based routing, and set the weights so the secondary Region rarely receives traffic unless manual changes are made.

    Why it's wrong here

    Latency-based routing selects the Region with the lowest network latency for each user, while weighted routing merely distributes traffic according to fixed percentages. Neither policy reacts to health checks or automatically shifts traffic when the primary Region fails; the weights would remain unchanged, so the secondary Region would only receive its small configured share until someone manually adjusts the weights or the primary record is removed. This approach requires operational intervention and does not provide the deterministic, health-check-driven failover the company needs.

  • ✓

    Use a Route 53 failover routing policy: configure two alias records for the ALBs where the primary record is marked PRIMARY, the secondary is marked SECONDARY, and each record has an associated health check.

    Why this is correct

    Route 53 failover routing is designed specifically for active-passive failover: you create two alias records pointing to the two ALBs, one marked PRIMARY and the other SECONDARY, each with an associated health check. Under normal conditions, Route 53 returns the PRIMARY record, but if that record's health check fails, Route 53 automatically stops returning it and returns the SECONDARY record instead. This gives the company an automated, DNS-level failover that does not depend on client latency, manual weight changes, or client-side load balancing.

  • ✗

    Use an alias A record that returns both ALBs simultaneously so clients automatically load balance across Regions during outages.

    Why it's wrong here

    An alias A record in Route 53 can point to a single ALB, so returning both ALBs simultaneously would require multiple A records under the same name. Even if both are returned, DNS does not force clients to load balance; each client randomly picks one of the returned IPs, and a client may continue using the unhealthy primary Region. Health checks without a failover routing policy do not remove the unhealthy ALB from the response set, so this approach cannot guarantee that traffic shifts to the secondary only after primary failure.

  • ✗

    Use geolocation routing to route users to the primary Region and rely on ALB health checks to shift requests between Regions.

    Why it's wrong here

    Geolocation routing directs users to the Region you map based on their geographic location, not on the health or availability of the ALBs. The ALB's own health checks only control whether individual targets behind that ALB are considered healthy; they have no effect on Route 53's geolocation mapping. Thus, users in the primary Region would still be routed to the primary ALB even if it is completely unhealthy, and there is no mechanism to shift requests to the secondary Region automatically.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.