SAA-C03 Design Resilient Architectures Practice Question
A trading dashboard runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include?
⚠ Common exam trap
It's easy for candidates to confuse high availability with fault tolerance, thinking a single large subnet or a single instance with monitoring is sufficient, when in fact distributing across multiple Availability Zones is the key to surviving an AZ failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Subnets in at least two Availability Zones with health checks enabled
Distributing EC2 instances across subnets in at least two Availability Zones ensures that if one AZ fails, the Auto Scaling group can maintain capacity using instances in the remaining AZ(s). Enabling health checks allows the group to detect and replace unhealthy instances, which is essential for fault tolerance. This configuration meets the requirement to tolerate the failure of one Availability Zone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A single EC2 instance with detailed monitoring
Why it's wrong here
Detailed monitoring with CloudWatch (1-minute metrics) only increases the frequency of metric collection and alarms; it has no effect on fault tolerance or instance replacement. A single EC2 instance still resides in one Availability Zone, so an AZ outage, hardware failure, or maintenance event terminates the instance and takes the dashboard offline until manual intervention or a separate recovery mechanism acts. Detailed monitoring can help you react faster to performance issues, but it cannot restart, replace, or relocate the instance, leaving the application with a single point of failure.
- ✓
Subnets in at least two Availability Zones with health checks enabled
Why this is correct
Placing subnets in at least two Availability Zones (AZs) and attaching health checks to the Auto Scaling group allows the group to detect and replace unhealthy instances while maintaining desired capacity across AZs. If one AZ fails, the remaining healthy instances in the other AZ continue serving traffic, and Auto Scaling launches new instances in the surviving AZs to compensate. Health checks (ELB or EC2 status checks) drive the replacement process, and distributing subnets across AZs makes the architecture resilient to both instance-level and AZ-level failures, which is the key requirement for a fault-tolerant trading dashboard.
- ✗
All instances in one larger subnet
Why it's wrong here
Expanding a subnet to include more IP addresses does not change the underlying physical location; a subnet exists entirely within a single Availability Zone. If all EC2 instances are launched into that one larger subnet, they all share the same AZ, so any failure of that AZ—power loss, network partition, or cooling failure—takes every instance down simultaneously. Larger subnets only provide more capacity for launching instances, not geographical or fault-domain diversity, and therefore do not address availability or redundancy requirements.
- ✗
A Network Load Balancer in one subnet
Why it's wrong here
A Network Load Balancer (NLB) is a regional service that can route traffic to targets across multiple AZs; however, if the NLB itself is placed in a single subnet (single AZ), it becomes a single point of failure at the network layer. Even if the backend instances are in multiple AZs, an AZ failure that includes the NLB's subnet will make the load balancer unreachable, and the entire application loses connectivity. NLB nodes must be deployed in at least two AZs—or the NLB must automatically have a node in each enabled AZ—to provide high availability; simply having a load balancer in one subnet adds a dependency that defeats resilience.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.