SAA-C03 Design Secure Architectures Practice Question
A company has a primary application in us-east-1 and a standby environment in us-west-2. Users should go to the primary site while it is healthy and automatically switch to the standby site if the primary fails. Which Route 53 routing policy should they use?
⚠ Common exam trap
Candidates often confuse failover routing with latency-based routing, thinking that latency routing will automatically switch to a healthy region, but latency routing only optimizes for speed and does not consider health status unless combined with health checks, which is not its primary purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Failover routing with health checks
Failover routing with health checks is the correct choice because it allows you to configure an active-passive failover pattern where Route 53 directs traffic to the primary resource (us-east-1) as long as it passes a health check. If the health check fails, Route 53 automatically routes traffic to the secondary resource (us-west-2), ensuring high availability without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Weighted routing
Why it's wrong here
Weighted routing assigns a relative weight to each record and proportionally distributes DNS answers among all records, for example 80% primary and 20% standby, which intentionally sends traffic to both endpoints at all times. Unlike failover routing, it does not encode an explicit active-passive relationship; even with health checks, weighted routing simply removes unhealthy records from the denominator and continues splitting traffic among the remaining records based on original weights. This makes it suitable for load distribution or canary releases, but it does not model the 'primary always preferred, standby only on failure' pattern described in the question.
When this WOULD be correct
A company wants to send 10% of traffic to a new application version for testing while sending 90% to the stable version, using Route 53 to distribute traffic based on weights.
- ✓
Failover routing with health checks
Why this is correct
Route 53 failover routing is designed for active-passive resilience. You define a primary record and a secondary record, then attach health checks so DNS answers shift to the standby when the primary is unhealthy. This provides a simple disaster recovery pattern for user-facing endpoints without requiring application-level traffic management.
- ✗
Geolocation routing
Why it's wrong here
Geolocation routing evaluates the geographic origin of the client's DNS resolver and maps that location to a designated record, such as sending US users to us-east-1 and European users to eu-west-1. This policy is location-driven, not health-driven; if the primary endpoint fails, users from that region will still receive the DNS record pointing to the unhealthy endpoint until an administrator manually changes the geographically assigned record. It therefore cannot automatically redirect all traffic to the standby environment during an outage.
When this WOULD be correct
A company needs to route users to different endpoints based on their country or continent, e.g., users in Europe go to eu-west-1, users in North America go to us-east-1, and they want to serve localized content or comply with data residency requirements.
- ✗
Latency-based routing
Why it's wrong here
Latency-based routing answers DNS queries by returning the endpoint that appears to have the lowest latency from the calling resolver's network, so users are directed to whichever site is fastest rather than to a pre-defined primary site. Even if health checks eliminate unhealthy endpoints, the decision when both sites are healthy is purely performance-based, which can send traffic to the standby region during normal operation. This fails the active-passive requirement where the primary region must always be preferred unless it is actually unhealthy.
When this WOULD be correct
A company wants to route users to the AWS region that provides the lowest latency for each user, without a fixed primary/standby setup. For example, a global application serving users worldwide should use latency-based routing to minimize response times.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Failover routing with health checksCorrect answer▾
Why this is correct
Route 53 failover routing is designed for active-passive resilience. You define a primary record and a secondary record, then attach health checks so DNS answers shift to the standby when the primary is unhealthy. This provides a simple disaster recovery pattern for user-facing endpoints without requiring application-level traffic management.
✗Weighted routingWrong answer — click to see why▾
Why this is wrong here
Weighted routing distributes traffic across multiple resources based on assigned weights, but it does not automatically fail over to a standby site when the primary fails; it requires manual weight adjustment or health checks to redirect traffic.
★ When this WOULD be the correct answer
A company wants to send 10% of traffic to a new application version for testing while sending 90% to the stable version, using Route 53 to distribute traffic based on weights.
Why candidates choose this
Candidates may think weighted routing can be used to send all traffic to the primary by setting its weight to 100 and the standby to 0, but this does not provide automatic failover without health checks.
✗Geolocation routingWrong answer — click to see why▾
Why this is wrong here
Geolocation routing directs traffic based on the user's geographic location, not on the health of the primary site. It cannot automatically fail over to a standby region when the primary fails.
★ When this WOULD be the correct answer
A company needs to route users to different endpoints based on their country or continent, e.g., users in Europe go to eu-west-1, users in North America go to us-east-1, and they want to serve localized content or comply with data residency requirements.
Why candidates choose this
Candidates may confuse geolocation with geographic failover, thinking that routing based on location can also handle failover, or they may assume that 'geolocation' implies awareness of site health.
✗Latency-based routingWrong answer — click to see why▾
Why this is wrong here
Latency-based routing directs users to the region with the lowest latency, not to a primary site with automatic failover to a standby site. It does not support health checks to detect primary failure.
★ When this WOULD be the correct answer
A company wants to route users to the AWS region that provides the lowest latency for each user, without a fixed primary/standby setup. For example, a global application serving users worldwide should use latency-based routing to minimize response times.
Why candidates choose this
Candidates may think latency-based routing can automatically redirect users when the primary fails, confusing performance optimization with disaster recovery failover.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.