SAA-C03 Design Resilient Architectures Practice Question
A healthcare company runs a patient portal on Amazon EC2 instances behind an Application Load Balancer across two Availability Zones. A new compliance rule requires that if an entire Availability Zone fails, the portal must remain available with no manual intervention. The EC2 instances are stateless and store no session data. Which design change should the architect implement to meet this requirement?
⚠ Common exam trap
The trap here is assuming that cross-zone load balancing or a larger instance type provides AZ-level resilience, when only an Auto Scaling group spanning multiple AZs can automatically replace lost capacity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable an Auto Scaling group that spans both Availability Zones and configure the load balancer health checks to deregister unhealthy instances.
High availability across Availability Zones requires compute capacity that can be automatically replaced when an AZ fails. An Auto Scaling group spanning multiple AZs, combined with load balancer health checks, ensures that unhealthy instances are removed and new instances are launched in a surviving AZ without human action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable an Auto Scaling group that spans both Availability Zones and configure the load balancer health checks to deregister unhealthy instances.
Why this is correct
An Auto Scaling group spanning both Availability Zones automatically replaces instances in the surviving AZ when one AZ fails, and ALB health checks remove failed targets. This provides resilience without manual intervention, directly satisfying the compliance requirement for AZ failure tolerance.
- ✗
Convert the EC2 instances to a single larger instance type and enable detailed monitoring in Amazon CloudWatch.
Why it's wrong here
Scaling vertically to one large instance does not protect against an Availability Zone failure; that instance still resides in one AZ. CloudWatch detailed monitoring improves visibility but does not automatically recover or replace compute capacity, so availability after AZ loss is not achieved.
- ✗
Configure the Application Load Balancer to use cross-zone load balancing and attach an Elastic IP address to each EC2 instance.
Why it's wrong here
Cross-zone load balancing distributes traffic across healthy targets but cannot create capacity in a failed AZ. Elastic IP addresses are tied to specific instances and do not provide automatic failover or replacement when an entire Availability Zone becomes unavailable.
- ✗
Place the EC2 instances in a single Availability Zone and create an Amazon EBS snapshot schedule every hour.
Why it's wrong here
Keeping all instances in one Availability Zone means an AZ failure takes down the entire portal. EBS snapshots provide data durability for volumes, not compute availability, and restoring from snapshots requires manual intervention, so this design fails the requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.