Courseiva

SAA-C03 Design Resilient Architectures Practice Question

A company runs an internet-facing API in two AWS Regions. Route 53 currently uses simple routing to a primary Application Load Balancer (ALB) DNS name. When the primary Region experiences an outage, customers wait a long time because the DNS entry is not changed automatically.

The team wants automatic failover: if the primary Region ALB health check fails for a sustained period, Route 53 should route users to the secondary Region ALB.

Which Route 53 approach best meets this requirement?

⚠ Common exam trap

Many exam-takers confuse failover routing with latency-based or weighted routing, assuming that latency-based routing inherently provides failover, but it does not—it only optimizes for performance, not availability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Route 53 failover routing with a PRIMARY and SECONDARY record set for the same name, and attach health checks to the ALBs.

Route 53 failover routing is designed specifically for active-passive failover scenarios. By creating PRIMARY and SECONDARY record sets with the same DNS name and attaching health checks to the ALBs, Route 53 will automatically route traffic to the secondary ALB when the primary ALB health check fails for a sustained period. This meets the requirement for automatic failover without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Route 53 failover routing with a PRIMARY and SECONDARY record set for the same name, and attach health checks to the ALBs.

    Why this is correct

    Route 53 failover routing is specifically designed for active-passive DNS failover. You create two records with the same name, designate one as PRIMARY and one as SECONDARY, and attach a Route 53 health check to each ALB endpoint. Route 53 continuously evaluates the PRIMARY health check; when it fails for the configured evaluation period, Route 53 responds with the SECONDARY record's IP or alias. This gives a deterministic, health-driven failover where the healthy secondary ALB starts receiving traffic once the primary is marked unhealthy, respecting the record TTL for propagation.

  • ✗

    Use latency-based routing so Route 53 automatically spreads traffic to both Regions based on measured latency.

    Why it's wrong here

    Latency-based routing selects the Region with the lowest network latency for each user, so it can spread traffic across both Regions simultaneously based on geography. It does not provide deterministic active-passive failover: even if the primary ALB is wholly unhealthy, latency measurements may still point users there if that Region is closest or if no health check is associated with the latency records. Attaching health checks would exclude unhealthy endpoints, but the decision remains latency-driven and does not honor a preferred secondary in a specified failover order.

    When this WOULD be correct

    A company wants to route users to the region with the lowest latency for better performance, and both regions are healthy and active. They do not require failover; they simply want to optimize response times.

  • ✗

    Use weighted routing and configure the secondary ALB to receive 100% traffic when the primary returns HTTP 5xx responses.

    Why it's wrong here

    Weighted routing distributes traffic according to static weights you assign to each record, and it does not monitor ALB application response codes like HTTP 5xx. Although you can attach health checks to weighted records so unhealthy records are excluded from responses, simply 'configuring the secondary to receive 100%' on a 5xx condition is not a native weighted-routing feature. There is no built-in action that alters weights based on ALB status, so you'd still need an external automation or a health-check-driven failover policy such as failover routing.

    When this WOULD be correct

    When you need to gradually shift traffic from one endpoint to another (e.g., blue/green deployment) or split traffic across multiple endpoints for A/B testing, and you manually adjust weights. Health checks are not required for this scenario.

  • ✗

    Use geolocation routing and restrict the primary Region record to specific countries only.

    Why it's wrong here

    Geolocation routing directs users to the record that corresponds to their physical (IP-based) location, such as country or continent. It has no built-in health-check failover logic, so if you restrict the primary Region's record to specific countries, those users would continue receiving the primary's DNS response even when the primary ALB is down. You would have to manually change records or rely on a separate failover mechanism, making this unsuitable for automatic cross-Region disaster recovery.

    When this WOULD be correct

    A company needs to restrict access to its API based on the user's country due to licensing or regulatory requirements. For example, users from the EU must be routed to a specific ALB in Frankfurt, while users from the US go to an ALB in Virginia.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Use Route 53 failover routing with a PRIMARY and SECONDARY record set for the same name, and attach health checks to the ALBs.Correct answer▾

Why this is correct

Route 53 failover routing is specifically designed for active-passive DNS failover. You create two records with the same name, designate one as PRIMARY and one as SECONDARY, and attach a Route 53 health check to each ALB endpoint. Route 53 continuously evaluates the PRIMARY health check; when it fails for the configured evaluation period, Route 53 responds with the SECONDARY record's IP or alias. This gives a deterministic, health-driven failover where the healthy secondary ALB starts receiving traffic once the primary is marked unhealthy, respecting the record TTL for propagation.

✗Use latency-based routing so Route 53 automatically spreads traffic to both Regions based on measured latency.Wrong answer — click to see why▾

Why this is wrong here

Latency-based routing distributes traffic based on lowest latency, not health. It does not provide automatic failover when a region is completely down; users may still be routed to the unhealthy primary if it has lower latency.

★ When this WOULD be the correct answer

A company wants to route users to the region with the lowest latency for better performance, and both regions are healthy and active. They do not require failover; they simply want to optimize response times.

Why candidates choose this

Candidates may think latency routing inherently handles failover because it 'automatically' routes to the best region, but it lacks health check awareness and can still direct traffic to an unhealthy endpoint.

✗Use weighted routing and configure the secondary ALB to receive 100% traffic when the primary returns HTTP 5xx responses.Wrong answer — click to see why▾

Why this is wrong here

Weighted routing distributes traffic based on weights, not health. It cannot automatically shift 100% traffic to the secondary ALB based on HTTP 5xx responses; health checks are not integrated with weighted routing for automatic failover.

★ When this WOULD be the correct answer

When you need to gradually shift traffic from one endpoint to another (e.g., blue/green deployment) or split traffic across multiple endpoints for A/B testing, and you manually adjust weights. Health checks are not required for this scenario.

Why candidates choose this

Candidates may think weighted routing can be used for failover by setting weights to 0 and 100, but they overlook that Route 53 does not automatically adjust weights based on endpoint health.

✗Use geolocation routing and restrict the primary Region record to specific countries only.Wrong answer — click to see why▾

Why this is wrong here

Geolocation routing directs traffic based on the geographic location of the user, not on the health or availability of the endpoint. It cannot automatically failover to a secondary Region when the primary ALB becomes unhealthy.

★ When this WOULD be the correct answer

A company needs to restrict access to its API based on the user's country due to licensing or regulatory requirements. For example, users from the EU must be routed to a specific ALB in Frankfurt, while users from the US go to an ALB in Virginia.

Why candidates choose this

Candidates may confuse geolocation routing with failover routing, thinking that restricting traffic to specific countries can somehow trigger a failover, or they may overestimate Route 53's ability to automatically detect and react to regional outages with geolocation policies.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.