SAA-C03 Design High-Performing Architectures Practice Question
A travel booking site uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured? The architecture review board prefers a managed AWS-native control.
⚠ Common exam trap
Test-takers frequently confuse monitoring (VPC endpoints) or data protection (S3 Object Lock) with performance scaling, overlooking that Auto Scaling is the direct AWS-native solution for handling variable load and high CPU.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Auto Scaling policy based on an appropriate CloudWatch metric
An Auto Scaling policy based on an appropriate CloudWatch metric (such as CPUUtilization or request latency) dynamically adds or removes EC2 instances to match demand. This managed AWS-native control directly addresses high CPU and rising latency during peak traffic by scaling out capacity, which is the preferred approach per the architecture review board's requirement for a managed solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A VPC endpoint for CloudWatch only
Why it's wrong here
A VPC endpoint for CloudWatch only alters the network path used by EC2 instances to reach CloudWatch APIs, enabling private traffic that avoids the public internet. It is a connectivity and security feature, not a capacity-management mechanism. Even with a private, low-latency path to CloudWatch, the instances' vCPU resources remain unchanged, so sustained CPU saturation on the existing fleet is not resolved. The endpoint would neither add instances nor relieve compute load, leaving the ALB backend still overwhelmed.
- ✓
Auto Scaling policy based on an appropriate CloudWatch metric
Why this is correct
An Auto Scaling policy based on an appropriate CloudWatch metric—most commonly average CPUUtilization across the Auto Scaling group—directly addresses the high CPU condition. With target tracking, Auto Scaling dynamically adjusts desired capacity to keep the metric near a defined value, such as 60%. When CPU rises above the target, it launches additional EC2 instances to spread the load; when it falls, it terminates instances to reduce cost. This is the standard, correct solution for a workload whose compute demand varies and is currently saturating existing instances.
- ✗
S3 Object Lock
Why it's wrong here
S3 Object Lock is a data-protection feature that enforces a retention period on objects in Amazon S3, preventing them from being deleted or overwritten for compliance or legal hold purposes. It has no interaction with EC2 compute capacity, Auto Scaling, or the CPU utilization of an application server. Applying Object Lock to an S3 bucket neither increases the number of EC2 instances nor changes how the ALB distributes traffic, so it cannot alleviate high CPU load. This option is a distractor that confuses a storage governance control with a compute scaling solution.
- ✗
Disable health checks
Why it's wrong here
Disabling health checks on the Application Load Balancer would stop it from detecting unhealthy or overloaded EC2 instances, causing traffic to be routed to targets that may be failing or saturated. This would degrade availability and likely worsen perceived performance, as requests could be sent to instances that cannot handle them. Moreover, health checks are not a scaling control—they do not adjust instance count or CPU capacity. Removing them eliminates the ALB's ability to stop sending requests to impaired instances, so the existing CPU pressure on the fleet remains or increases.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.