SAA-C03 Design Resilient Architectures Practice Question
A logistics company runs an order-tracking service on Amazon EC2 instances that write state to an Amazon DynamoDB table. A recent incident showed that a single Availability Zone failure caused the service to lose capacity, and the team also discovered that a developer accidentally deleted a production table. The architect must improve both Availability Zone resilience and protection against accidental table deletion. (Choose two.)
⚠ Common exam trap
The trap here is assuming DynamoDB needs multi-AZ configuration like a relational database, when DynamoDB already replicates data across zones and the real gaps are compute placement and deletion protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable DynamoDB point-in-time recovery on the table and attach a resource-based policy that denies the dynamodb:DeleteTable action to non-administrative principals.
Zone resilience for the compute tier comes from running instances across multiple Availability Zones behind a load balancer, so a single zone loss does not remove all capacity. Accidental table deletion is mitigated by enabling point-in-time recovery, which allows restore to a recent point in time, and by restricting who holds the delete-table permission so the mistake is far less likely to recur.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable DynamoDB point-in-time recovery on the table and attach a resource-based policy that denies the dynamodb:DeleteTable action to non-administrative principals.
Why this is correct
Point-in-time recovery allows restoration of the table to any second within the previous 35 days, which recovers data after an accidental deletion. Adding an IAM policy that denies dynamodb:DeleteTable to ordinary principals reduces the chance of the same mistake recurring, so together they address the accidental-deletion risk.
- ✗
Create a DynamoDB global secondary index on the partition key used by the tracking queries and project all attributes into the index.
Why it's wrong here
A global secondary index improves query flexibility and can serve different access patterns, but it is not a backup mechanism and provides no delete protection. Because the index depends on the base table, deleting the table also removes the index, so this does not mitigate the accidental-deletion scenario.
- ✗
Enable DynamoDB Streams on the table and write a consumer that copies every change into an Amazon S3 bucket for long-term retention.
Why it's wrong here
DynamoDB Streams captures item-level changes and can feed a replication consumer, but it does not protect against table deletion or provide point-in-time restore of the table itself. Streams records expire after 24 hours, and a table deletion stops the stream, so this is not a reliable safeguard for the stated risks.
- ✓
Deploy the EC2 instances in an Auto Scaling group that spans multiple Availability Zones and attach the instances to an Application Load Balancer.
Why this is correct
Spreading the compute fleet across multiple Availability Zones with an Auto Scaling group and fronting it with an Application Load Balancer means that if one zone fails, the load balancer routes traffic to healthy instances in the remaining zones and the group replaces lost capacity. This directly addresses the loss of service capacity during a zone event.
- ✗
Convert the DynamoDB table to use provisioned capacity mode with auto scaling so that read and write capacity automatically adjusts during traffic spikes.
Why it's wrong here
Provisioned capacity with auto scaling tunes throughput and cost, but it has no bearing on Availability Zone resilience of the compute tier or on protecting the table from deletion. The table itself is already replicated across zones by DynamoDB, so this change does not address either stated requirement.
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.