SAA-C03 Design Resilient Architectures Practice Question
A logistics company runs a stateless order-tracking API on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The architect must ensure the API survives the loss of an entire Availability Zone and that unhealthy instances are replaced automatically. (Choose two.)
⚠ Common exam trap
The trap here is assuming that enabling monitoring or termination protection contributes to resilience, when only multi-AZ capacity and ELB health checks do.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an Application Load Balancer target group health check and enable ELB health checks on the Auto Scaling group so unhealthy instances are terminated and replaced
Zone-level resilience with EC2 Auto Scaling requires the group to span multiple Availability Zones with enough desired capacity to run in each, so a single zone failure leaves serving capacity. Automatic replacement of unhealthy instances requires ELB health checks on the group, which makes the group act on the load balancer's health determination rather than only EC2 status checks. Together these two settings deliver the required survival and self-healing behaviour.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable termination protection on all EC2 instances so the Auto Scaling group cannot remove them during a zone failure
Why it's wrong here
Termination protection prevents accidental instance termination but also blocks the Auto Scaling group from replacing unhealthy instances, which breaks the automatic recovery requirement. It does not add capacity in another zone and can leave the group unable to heal. This setting is appropriate for standalone instances, not for instances managed by an Auto Scaling group that must be replaceable.
- ✗
Create a second Auto Scaling group in a different Region and use Amazon Route 53 latency-based routing to distribute traffic
Why it's wrong here
A second Region provides disaster recovery, not Availability Zone resilience, and it adds significant cost and operational complexity. Latency-based routing also does not guarantee failover on zone failure and can send traffic to an unhealthy endpoint. The requirement is zone-level tolerance within a Region, so a multi-Region design is unnecessary and misaligned.
- ✓
Attach an Application Load Balancer target group health check and enable ELB health checks on the Auto Scaling group so unhealthy instances are terminated and replaced
Why this is correct
Enabling Elastic Load Balancing health checks on the Auto Scaling group means the group uses the load balancer's health status rather than only EC2 status checks, so instances that fail application-level checks are replaced. This ensures automatic recovery from unhealthy instances, which is the second requirement. The target group health check defines what the load balancer considers healthy.
- ✗
Place the instances in a single Availability Zone and enable detailed CloudWatch monitoring with a 1-minute granularity
Why it's wrong here
Detailed monitoring improves metric resolution but does not prevent an Availability Zone outage from taking down all instances. Concentrating capacity in one zone directly contradicts the zone-resilience requirement. No amount of monitoring granularity can restore capacity in a zone that has failed, so this option does not satisfy the scenario.
- ✓
Configure the Auto Scaling group to span at least two Availability Zones and set the desired capacity to a number that keeps instances running in each zone
Why this is correct
Spreading the Auto Scaling group across multiple Availability Zones ensures that if one zone fails, instances in the surviving zone continue to serve traffic. Setting a desired capacity that places instances in each zone prevents the group from concentrating all capacity in a single zone. This is the foundational step for zone-level resilience with EC2 Auto Scaling.
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.