SAA-C03 Design Resilient Architectures Practice Question
A retail API runs on Amazon EC2 instances behind an Application Load Balancer and stores orders in an Amazon RDS for PostgreSQL database. A test that stopped one Availability Zone caused the API to return errors because all application servers were in the same AZ and the database was single-AZ. Which two changes should the architect make to continue serving traffic during a single-AZ failure? Select two.
⚠ Common exam trap
Many candidates think a read replica can serve as a high-availability solution for writes, but read replicas are asynchronous and do not support automatic failover for the primary database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Auto Scaling group to launch instances across private subnets in at least two Availability Zones.
Option B is correct because an Auto Scaling group that spans private subnets in at least two Availability Zones ensures application instances remain available if one AZ fails, and the ALB can route to healthy targets in the surviving AZ. Option D is correct because converting RDS for PostgreSQL to a Multi-AZ deployment creates a synchronous standby in a different AZ and automatically fails over the database endpoint, eliminating the single-AZ database as a point of failure. Option A is wrong because increasing instance size does not address the single-AZ placement of the application servers. Option C is wrong because a single-AZ Network Load Balancer still fails when that AZ fails and does not improve database resilience. Option E is wrong because a read replica is asynchronous, is not an automatic failover target for writes, and pointing the application at the replica endpoint does not provide a highly available primary database.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the EC2 instance size and keep all application servers in the same subnet.
Why it's wrong here
Resizing instances and retaining a single subnet leaves every application server in one Availability Zone, so an AZ outage still removes all capacity. It is tempting because vertical scaling raises throughput, and would be correct for handling load growth, but it addresses neither the AZ placement nor the single-AZ database failure described.
When this WOULD be correct
If the question described a performance bottleneck (e.g., CPU or memory saturation) and the goal was to improve throughput for a single-AZ workload, increasing instance size would be correct.
- ✓
Configure the Auto Scaling group to launch instances across private subnets in at least two Availability Zones.
Why this is correct
Spreading instances across private subnets in at least two Availability Zones lets the Auto Scaling group replace capacity in a surviving AZ, satisfying the requirement to keep serving traffic when one AZ fails. The load balancer then routes only to healthy targets.
- ✗
Replace the Application Load Balancer with a Network Load Balancer in a single Availability Zone.
Why it's wrong here
A Network Load Balancer confined to one Availability Zone still loses all traffic routing when that zone fails, and it does not address the single-AZ database. It is tempting because NLB handles high-throughput TCP workloads, and would be correct for extreme performance or static IP needs, but cross-AZ resilience is the actual requirement.
When this WOULD be correct
When the requirement is to handle extremely high throughput with low latency for TCP/UDP traffic, and the application is already deployed across multiple AZs with its own failover logic. An NLB in a single AZ could be correct if the question explicitly states that only one AZ is used and the goal is to maximize performance within that AZ.
- ✓
Convert the RDS for PostgreSQL database to a Multi-AZ deployment.
Why this is correct
Multi-AZ RDS maintains a synchronous standby in a different Availability Zone and automatically fails over the database endpoint, removing the single-AZ database as the outage's point of failure. This satisfies the requirement to survive a single-AZ failure without manual intervention.
- ✗
Add an Amazon RDS read replica and point the application to the replica endpoint.
Why it's wrong here
A read replica is asynchronous and read-only, so it cannot accept order writes or provide automatic failover when the primary AZ fails. It is tempting because replicas offload read traffic and can be promoted manually, and would be correct for scaling read-heavy workloads, but the stem requires write availability during an AZ outage.
When this WOULD be correct
A read replica would be correct if the question asked for offloading read traffic from the primary database to improve read performance, or if the requirement was to have a standby for disaster recovery in a different region (cross-region read replica) without automatic failover.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Configure the Auto Scaling group to launch instances across private subnets in at least two Availability Zones.Correct answer▾
Why this is correct
Spreading instances across private subnets in at least two Availability Zones lets the Auto Scaling group replace capacity in a surviving AZ, satisfying the requirement to keep serving traffic when one AZ fails. The load balancer then routes only to healthy targets.
✗Increase the EC2 instance size and keep all application servers in the same subnet.Wrong answer — click to see why▾
Why this is wrong here
Increasing EC2 instance size and keeping all servers in one subnet does not provide fault tolerance across Availability Zones; a single AZ failure would still take down all application servers.
★ When this WOULD be the correct answer
If the question described a performance bottleneck (e.g., CPU or memory saturation) and the goal was to improve throughput for a single-AZ workload, increasing instance size would be correct.
Why candidates choose this
Candidates may think bigger instances alone can handle failures, confusing vertical scaling with high availability.
✗Replace the Application Load Balancer with a Network Load Balancer in a single Availability Zone.Wrong answer — click to see why▾
Why this is wrong here
A Network Load Balancer (NLB) in a single AZ cannot provide cross-AZ failover; the question requires serving traffic during a single-AZ failure, which demands multi-AZ architecture. An NLB alone does not address the lack of application server redundancy.
★ When this WOULD be the correct answer
When the requirement is to handle extremely high throughput with low latency for TCP/UDP traffic, and the application is already deployed across multiple AZs with its own failover logic. An NLB in a single AZ could be correct if the question explicitly states that only one AZ is used and the goal is to maximize performance within that AZ.
Why candidates choose this
Candidates may confuse load balancer types, thinking an NLB provides better availability than an ALB, or they may overlook that the NLB is still confined to a single AZ, which does not solve the multi-AZ failure requirement.
✗Add an Amazon RDS read replica and point the application to the replica endpoint.Wrong answer — click to see why▾
Why this is wrong here
A read replica does not provide automatic failover; the application would need to manually switch to the replica endpoint, which does not address the single-AZ failure of the primary database. The question requires continued serving traffic during a single-AZ failure, which Multi-AZ provides by automatic failover.
★ When this WOULD be the correct answer
A read replica would be correct if the question asked for offloading read traffic from the primary database to improve read performance, or if the requirement was to have a standby for disaster recovery in a different region (cross-region read replica) without automatic failover.
Why candidates choose this
Candidates may confuse read replicas with Multi-AZ deployments, thinking that a read replica provides high availability, but it does not offer automatic failover and is primarily for read scaling.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.