Courseiva

SAA-C03 Design Secure Architectures Practice Question

A stateless web application runs on Amazon EC2 instances across two Availability Zones. The team wants unhealthy instances to be removed automatically and replaced without manual action. What is the best solution?

⚠ Common exam trap

It's easy for candidates to confuse network ACLs (stateless packet filters) with health check mechanisms, or assume that persistent storage (EBS) alone provides high availability without an orchestration layer like Auto Scaling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an Application Load Balancer with an Auto Scaling group and configure health checks.

An Application Load Balancer (ALB) with an Auto Scaling group provides automated health checks and instance replacement. The ALB performs HTTP/HTTPS health checks against the instances, and when an instance fails the health check, the Auto Scaling group automatically terminates the unhealthy instance and launches a new one to maintain the desired capacity. This ensures the stateless web application remains available across both Availability Zones without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the instances in a single subnet and increase the instance size.

    Why it's wrong here

    Collapsing all instances into a single subnet means they reside in one Availability Zone, so an AZ outage takes the entire web tier down; increasing the instance size only adds vertical capacity within that same failure domain. A larger instance is still a single fail point and can be terminated or become unhealthy, and without an Auto Scaling group or load balancer, there is no mechanism to replace it or distribute traffic. This approach sacrifices the horizontal elasticity and fault isolation that a multi-AZ Application Load Balancer plus Auto Scaling group design provides.

    When this WOULD be correct

    This option would be correct if the question asked for a solution to handle increased load for a single-instance application that does not require high availability, and the goal was to vertically scale the instance to improve performance.

  • ✓

    Use an Application Load Balancer with an Auto Scaling group and configure health checks.

    Why this is correct

    An Application Load Balancer distributes traffic across healthy targets, and an Auto Scaling group can replace instances that fail health checks. Together, they provide automatic recovery from instance failure and keep the application available across multiple Availability Zones. This is the standard resilient design for stateless EC2 web tiers.

  • ✗

    Use a network ACL to detect failed instances and restart them.

    Why it's wrong here

    A network ACL is a stateless VPC-level firewall that filters traffic entering or leaving a subnet; it has no visibility into instance health, no ability to communicate with EC2 or the orchestration layer, and cannot initiate a restart of a failed instance. It simply allows or denies packets based on rules, so it never detects process failures or triggers recovery for the web tier. This is a network security control, not a resilience mechanism.

    When this WOULD be correct

    A question asks for a security layer to block specific IP ranges from accessing a subnet, or to allow/deny traffic at the subnet boundary based on source/destination IP and port. In that context, a network ACL is the correct answer.

  • ✗

    Store the web servers on EBS volumes so the data survives failures.

    Why it's wrong here

    EBS volumes provide durable block storage, but attaching them to EC2 instances does nothing to detect an unhealthy instance, replace it, or reroute traffic; a web server process crash or instance failure leaves the application down even if its disk data is intact. In fact, a stateless web tier should treat compute as disposable and offload session state to external stores such as ElastiCache or S3—relying on EBS to survive failures does not restore service. Additionally, an EBS volume is confined to one Availability Zone, so it cannot provide cross-zone failover when the instance fails.

    When this WOULD be correct

    If the question required ensuring data persistence for stateful applications after instance failure, such as a database server where data must survive termination, then using EBS volumes with termination protection would be correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Use an Application Load Balancer with an Auto Scaling group and configure health checks.Correct answer▾

Why this is correct

An Application Load Balancer distributes traffic across healthy targets, and an Auto Scaling group can replace instances that fail health checks. Together, they provide automatic recovery from instance failure and keep the application available across multiple Availability Zones. This is the standard resilient design for stateless EC2 web tiers.

✗Place the instances in a single subnet and increase the instance size.Wrong answer — click to see why▾

Why this is wrong here

Placing instances in a single subnet and increasing instance size does not provide automatic unhealthy instance replacement; it only increases capacity within one Availability Zone, offering no fault tolerance or self-healing.

★ When this WOULD be the correct answer

This option would be correct if the question asked for a solution to handle increased load for a single-instance application that does not require high availability, and the goal was to vertically scale the instance to improve performance.

Why candidates choose this

Candidates may think that a larger instance can handle failures better, or they confuse vertical scaling with the automatic recovery provided by Auto Scaling groups.

✗Use a network ACL to detect failed instances and restart them.Wrong answer — click to see why▾

Why this is wrong here

Network ACLs are stateless packet filters at the subnet level; they cannot detect failed instances or trigger instance replacement. They do not perform health checks or automate recovery.

★ When this WOULD be the correct answer

A question asks for a security layer to block specific IP ranges from accessing a subnet, or to allow/deny traffic at the subnet boundary based on source/destination IP and port. In that context, a network ACL is the correct answer.

Why candidates choose this

Candidates may confuse network ACLs (which filter traffic) with health check mechanisms, or mistakenly think ACLs can monitor instance health and trigger actions.

✗Store the web servers on EBS volumes so the data survives failures.Wrong answer — click to see why▾

Why this is wrong here

Storing web servers on EBS volumes does not automate instance replacement or health checks; it only preserves data across failures, but manual action is still required to replace failed instances.

★ When this WOULD be the correct answer

If the question required ensuring data persistence for stateful applications after instance failure, such as a database server where data must survive termination, then using EBS volumes with termination protection would be correct.

Why candidates choose this

Candidates may think that preserving data on EBS volumes automatically handles failures, confusing data durability with instance recovery automation.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.