SAA-C03 Design Resilient Architectures Practice Question
A ticket booking system runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include?
⚠ Common exam trap
Many exam-takers think a single larger subnet or a different load balancer type provides resilience, but only distributing subnets across multiple Availability Zones with health checks ensures the system can survive an AZ failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Subnets in at least two Availability Zones with health checks enabled
An Auto Scaling group configured with subnets in at least two Availability Zones and health checks enabled ensures that if one AZ fails, EC2 instances in the remaining AZs continue to serve traffic. The Application Load Balancer distributes requests across healthy instances in multiple AZs, and the Auto Scaling group replaces failed instances in the affected AZ, maintaining capacity. This design meets the requirement to tolerate the failure of one Availability Zone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Subnets in at least two Availability Zones with health checks enabled
Why this is correct
Deploying an Auto Scaling group across subnets in at least two Availability Zones (AZs) is the core of high availability. Each AZ is an isolated failure domain, so if one AZ fails, the ASG continues to run instances in the other AZ(es). Coupled with ELB or ASG health checks, the group automatically detects unhealthy instances—whether due to EC2 failure or AZ impairment—and replaces them, maintaining desired capacity and absorbing request traffic. This design avoids any single point of failure at both the compute and network layers.
- ✗
All instances in one larger subnet
Why it's wrong here
A subnet is scoped to a single Availability Zone; placing all instances in one larger subnet does not make them resilient to an AZ failure. A larger subnet simply provides a bigger IP address range, but all of those instances share the same physical infrastructure and failure domain. If that AZ goes down, every instance in that subnet becomes unreachable, and there is no capacity elsewhere to fail over to. Thus, traffic is continuously lost with no automatic recovery mechanism.
- ✗
A Network Load Balancer in one subnet
Why it's wrong here
An Application Load Balancer or Network Load Balancer is a regional service, but its nodes run in specific subnets. Placing the load balancer in only one subnet confines its entry points to a single AZ; if that AZ fails, the load balancer nodes become unavailable, and traffic cannot be distributed to backend instances even if those instances are healthy in other AZs. For true resilience, the load balancer must be enabled in subnets across at least two AZs so that DNS and routing can continue to direct traffic to surviving nodes.
- ✗
A single EC2 instance with detailed monitoring
Why it's wrong here
Detailed monitoring (1-minute CloudWatch metrics) gives you more granular visibility into an instance's CPU, network, and disk usage, but it does absolutely nothing to provide redundancy or automatic failover. A single EC2 instance remains a single point of failure: if the instance crashes, reboots, or becomes unavailable, there is no second instance to serve requests. Monitoring may alert you to the outage, but it cannot replace the failed instance or reroute traffic, so the application is still down until manual intervention occurs.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.