SAA-C03 Design Resilient Architectures Practice Question
A content publishing system exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most? The design must avoid adding custom operational scripts.
⚠ Common exam trap
Many candidates confuse backup or access control features (like Backup Vault Lock or IAM Access Analyzer) with availability mechanisms, or think S3 Select provides caching, when the correct answer is simply leveraging CloudFront's built-in caching TTLs to serve stale content during origin outages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudFront caching with appropriate TTLs
CloudFront caches responses from the S3 origin based on configured TTLs (Cache-Control or Expires headers). If the S3 origin experiences a short outage, CloudFront can still serve cached content to users as long as the TTL has not expired, ensuring availability without custom scripts. This is the most direct and resilient feature for this use case.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IAM Access Analyzer
Why it's wrong here
IAM Access Analyzer is a permissions-analysis tool that inspects IAM policies and resource-based policies (like S3 bucket policies) to detect unintended external access, and it can generate least-privilege policies from CloudTrail logs. However, it exists entirely outside the data path for content delivery: it does not cache objects, intercept requests, or serve static content. When the S3 origin is unavailable, Access Analyzer's only function is to audit permissions, so it cannot provide any resilience or availability for the website.
- ✗
AWS Backup Vault Lock
Why it's wrong here
AWS Backup Vault Lock provides a write-once-read-many (WORM) protection on backup vaults, making backup copies immutable to prevent accidental or malicious deletion, even by root users. While this is a valuable compliance and ransomware-protection feature, it only applies to backup data managed by AWS Backup, not to the S3 bucket hosting your static website. It does not participate in content delivery, caching, or request routing, so it cannot help CloudFront serve content when the origin is temporarily unavailable.
- ✓
CloudFront caching with appropriate TTLs
Why this is correct
CloudFront caching with appropriate TTL values lets the CDN store static objects at edge locations and continue serving those cached copies even when the S3 origin is temporarily unreachable, as long as the cached object has not expired. Setting longer TTLs for immutable content (e.g., versioned images, scripts, and stylesheets) reduces the frequency of origin fetches and widens the window of resilience during an S3 outage. This is the only proposed solution that keeps content available to end users during an origin failure, directly addressing the requirement to tolerate an S3 outage.
- ✗
S3 Select
Why it's wrong here
S3 Select is a query feature that uses SQL to retrieve only a subset of rows or columns from an object in S3, reducing data transferred for analytics workloads. It requires direct, real-time access to the S3 object; it does not cache any data at the edge, nor does it maintain an independent copy of the object. Therefore, if the S3 bucket is down, S3 Select cannot retrieve anything, and it provides no benefit to a static website that normally serves full objects via CloudFront.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.