Courseiva

SAA-C03 Design Resilient Architectures Practice Question

A logistics company runs an order-tracking API on a fleet of EC2 instances in a single Availability Zone behind a Network Load Balancer. The architecture team must make the API resilient to the loss of that Availability Zone without changing the API endpoint that clients already use. The instances are stateless and store session data in a shared Amazon ElastiCache cluster. Which change should the solutions architect make to meet these requirements?

⚠ Common exam trap

The trap here is assuming the load balancer itself needs replacing or duplicating, when the real single point of failure is the compute capacity confined to one Availability Zone.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Auto Scaling group that spans at least two Availability Zones, register the instances with a target group attached to the existing Network Load Balancer, and enable cross-zone load balancing.

The resilient pattern is to spread stateless compute across multiple Availability Zones and let the existing Regional Network Load Balancer route to whichever targets are healthy. Because the load balancer already has nodes in every enabled zone, adding an Auto Scaling group that spans zones gives the surviving zone capacity to absorb traffic, and cross-zone load balancing keeps distribution even. Session state already lives in ElastiCache, so no failover logic is needed in the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable termination protection on the EC2 instances and configure an Elastic IP address per instance so that clients can reconnect to the same address after a zone failure.

    Why it's wrong here

    Termination protection only blocks accidental instance termination; it does nothing when an Availability Zone itself is impaired. Elastic IP addresses are Regional and can be remapped, but clients are connecting to the load balancer endpoint, not to instance addresses, so this design neither preserves the endpoint nor provides running capacity in a second zone.

  • ✗

    Replace the Network Load Balancer with an Application Load Balancer deployed in one Availability Zone and attach an Auto Scaling group with a desired capacity of two instances.

    Why it's wrong here

    An Application Load Balancer is also a Regional resource, but keeping the Auto Scaling group in a single Availability Zone means the workload still has no capacity in a second zone, so a zone failure still takes down every instance. This option changes the load balancer type and its DNS name, which also violates the requirement that clients keep using the existing API endpoint.

  • ✗

    Create a second Network Load Balancer in a different Availability Zone and use Amazon Route 53 weighted routing to send half the client traffic to each load balancer.

    Why it's wrong here

    A second Network Load Balancer in another zone does not protect the instances, which remain in one zone, and weighted routing does not automatically withdraw a failed endpoint from DNS. Weighted records keep resolving to the failed load balancer until health checks and TTL expire, and clients would also need to tolerate two different endpoint names, which the scenario forbids.

  • ✓

    Create an Auto Scaling group that spans at least two Availability Zones, register the instances with a target group attached to the existing Network Load Balancer, and enable cross-zone load balancing.

    Why this is correct

    A Network Load Balancer is a Regional resource with nodes in each enabled Availability Zone, so extending the Auto Scaling group across multiple Availability Zones lets healthy instances in a surviving zone serve traffic without any DNS or endpoint change. Cross-zone load balancing distributes traffic evenly so the remaining zone absorbs the full load, and because sessions live in ElastiCache, no instance holds state that would be lost.

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.