Courseiva

SAA-C03 Design Resilient Architectures Practice Question

A patient portal receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers?

⚠ Common exam trap

Many exam-takers confuse a load-balancing or caching service (like CloudFront or Route 53) with a message queue, failing to recognize that only a queue provides durable, asynchronous decoupling and retry capability for request processing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon SQS queue

Amazon SQS is the correct choice because it acts as a durable, highly available message buffer between the web tier and the fulfilment workers. It decouples the components, allowing the web tier to enqueue requests immediately without waiting for the downstream service, and the workers can poll and process messages at their own pace. SQS automatically retains messages for up to 14 days and supports retries via a dead-letter queue, ensuring no requests are lost even during spikes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF is a web application firewall that inspects and filters HTTP(S) requests at Layer 7 based on rules like IP reputation, SQL injection, or cross-site scripting. It can block or rate-limit malicious traffic, but it has no storage or buffering mechanism to hold legitimate order requests during traffic bursts. Any allowed request is forwarded directly to the origin, so the backend would still be overwhelmed by the same spike; WAF does not decouple producers from consumers. Its purpose is security, not asynchronous work management.

  • ✗

    Amazon CloudFront

    Why it's wrong here

    Amazon CloudFront is a content delivery network that caches static and dynamic content at edge locations to reduce latency and offload repeated requests from the origin. It can handle high read throughput and absorbs some origin load by serving cached responses, but it cannot queue or buffer new order submissions for later processing. Since each order creates a unique request that must eventually reach the application backend, CloudFront simply forwards the traffic without providing durability or retry mechanics. The burst still hits your backend synchronously, so it does not solve the buffering problem.

  • ✓

    Amazon SQS queue

    Why this is correct

    Amazon SQS is a distributed message queue that decouples the patient portal from the order-processing backend: the portal sends each order as a message, and SQS durably stores it across multiple Availability Zones until a consumer polls and processes it. During a burst, SQS absorbs the unprocessed messages, allowing the backend to scale out or catch up at its own pace rather than being overwhelmed. The visibility timeout prevents the same message from being processed by multiple workers, while a dead-letter queue captures any messages that fail repeatedly after a configured number of attempts. This buffering plus retry capability directly addresses the bursting workload described in the scenario.

  • ✗

    Amazon Route 53 weighted routing

    Why it's wrong here

    Amazon Route 53's weighted routing policy is a DNS feature that distributes requests among multiple healthy endpoints (e.g., two load balancers) by assigning relative weights to records. It only controls which IP address clients resolve and does not know about the volume or state of pending work at each target; a request is simply redirected to a single endpoint. If that endpoint is busy, the request is still sent directly to it, so Route 53 cannot smooth out a sudden burst of orders or hold them for processing. There is no buffer, store, or visibility timeout—routing decisions are made at DNS resolution time only.

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.