Courseiva

SAA-C03 Design Resilient Architectures Practice Question

A ticket booking system runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include?

⚠ Common exam trap

Many exam-takers think a single larger subnet or a different load balancer type provides resilience, but only distributing subnets across multiple Availability Zones with health checks ensures the system can survive an AZ failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Subnets in at least two Availability Zones with health checks enabled

An Auto Scaling group configured with subnets in at least two Availability Zones and health checks enabled ensures that if one AZ fails, EC2 instances in the remaining AZs continue to serve traffic. The Application Load Balancer distributes requests across healthy instances in multiple AZs, and the Auto Scaling group replaces failed instances in the affected AZ, maintaining capacity. This design meets the requirement to tolerate the failure of one Availability Zone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Subnets in at least two Availability Zones with health checks enabled

    Why this is correct

    Deploying an Auto Scaling group across subnets in at least two Availability Zones (AZs) is the core of high availability. Each AZ is an isolated failure domain, so if one AZ fails, the ASG continues to run instances in the other AZ(es). Coupled with ELB or ASG health checks, the group automatically detects unhealthy instances—whether due to EC2 failure or AZ impairment—and replaces them, maintaining desired capacity and absorbing request traffic. This design avoids any single point of failure at both the compute and network layers.

  • ✗

    All instances in one larger subnet

    Why it's wrong here

    A subnet is scoped to a single Availability Zone; placing all instances in one larger subnet does not make them resilient to an AZ failure. A larger subnet simply provides a bigger IP address range, but all of those instances share the same physical infrastructure and failure domain. If that AZ goes down, every instance in that subnet becomes unreachable, and there is no capacity elsewhere to fail over to. Thus, traffic is continuously lost with no automatic recovery mechanism.

  • ✗

    A Network Load Balancer in one subnet

    Why it's wrong here

    An Application Load Balancer or Network Load Balancer is a regional service, but its nodes run in specific subnets. Placing the load balancer in only one subnet confines its entry points to a single AZ; if that AZ fails, the load balancer nodes become unavailable, and traffic cannot be distributed to backend instances even if those instances are healthy in other AZs. For true resilience, the load balancer must be enabled in subnets across at least two AZs so that DNS and routing can continue to direct traffic to surviving nodes.

  • ✗

    A single EC2 instance with detailed monitoring

    Why it's wrong here

    Detailed monitoring (1-minute CloudWatch metrics) gives you more granular visibility into an instance's CPU, network, and disk usage, but it does absolutely nothing to provide redundancy or automatic failover. A single EC2 instance remains a single point of failure: if the instance crashes, reboots, or becomes unavailable, there is no second instance to serve requests. Monitoring may alert you to the outage, but it cannot replace the failed instance or reroute traffic, so the application is still down until manual intervention occurs.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.