SAA-C03 Design High-Performing Architectures Practice Question
A company runs a microservices application on Amazon ECS with AWS Fargate. The services communicate over HTTP/2 and gRPC. The architect needs to implement service-to-service communication that provides high throughput, low latency, and mutual TLS encryption. The solution must also support traffic splitting for canary deployments. Which approach should the architect take?
⚠ Common exam trap
The trap here is thinking that an Application Load Balancer or API Gateway can provide mutual TLS for service-to-service communication, when they are primarily for north-south traffic and do not offer the same mesh capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy an AWS App Mesh virtual service with Envoy proxies sidecar containers, and configure routes with weights for canary deployments.
AWS App Mesh is a service mesh that uses Envoy proxies to manage service-to-service communication. It supports HTTP/2 and gRPC, provides mutual TLS for encryption, and allows weighted routing for canary deployments. This makes it the best fit for the requirements of high throughput, low latency, mTLS, and traffic splitting in an ECS on Fargate environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an Application Load Balancer with gRPC support and configure multiple target groups with weighted routing.
Why it's wrong here
An Application Load Balancer can route gRPC traffic and supports weighted target groups for canary deployments, but it does not provide mutual TLS between services. The ALB terminates TLS at the load balancer, and traffic between the ALB and targets may not be encrypted with mTLS. Additionally, an ALB introduces an extra network hop, which may increase latency. For service-to-service mTLS, a service mesh is more appropriate.
- ✗
Use Amazon API Gateway with private integration to the ECS services, and enable mutual TLS on the API Gateway.
Why it's wrong here
Amazon API Gateway can provide mutual TLS for client-to-API authentication, but it is designed for north-south traffic (external to internal), not service-to-service communication. Using API Gateway for internal microservices adds latency and complexity, and it may not support HTTP/2 end-to-end for gRPC. API Gateway also does not provide the fine-grained traffic splitting for canary deployments as seamlessly as a service mesh.
- ✓
Deploy an AWS App Mesh virtual service with Envoy proxies sidecar containers, and configure routes with weights for canary deployments.
Why this is correct
AWS App Mesh is a service mesh that provides consistent networking for microservices. It uses Envoy proxies to handle service-to-service communication, supporting HTTP/2 and gRPC. It can enforce mutual TLS for encryption and provides traffic routing capabilities, including weighted targets for canary deployments. This meets all requirements: high throughput, low latency, mTLS, and traffic splitting.
- ✗
Configure AWS Cloud Map for service discovery and use security groups to enforce encryption between tasks.
Why it's wrong here
AWS Cloud Map provides service discovery, but it does not handle traffic routing, load balancing, or encryption. Security groups control network access but do not provide encryption. Mutual TLS requires certificate management and encryption at the application layer, which Cloud Map and security groups do not offer. This approach lacks the necessary features for mTLS and canary traffic splitting, making it insufficient for the requirements.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.