SAA-C03 Design Resilient Architectures Practice Question
A web application runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). After a new release, instances begin failing ALB health checks with errors like 502 while the application is still starting up. CloudWatch shows that the ASG replaces the instances before they finish initializing, so traffic never reaches healthy targets. Which change most directly prevents premature replacement during startup so traffic can resume as soon as the instances are actually healthy?
⚠ Common exam trap
Test-takers frequently confuse the ALB health check timeout or interval with the ASG health check grace period, thinking that adjusting ALB settings will fix the premature replacement issue, when in fact the ASG grace period is the direct control for delaying health check evaluation during startup.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the Auto Scaling group health check grace period to cover application startup and initialization time.
B is correct because the Auto Scaling group health check grace period allows instances a specified amount of time to initialize before the ASG starts checking their health status. By increasing this grace period to cover the application startup time, the ASG will not prematurely replace instances that are still initializing, allowing them to pass the ALB health checks and begin receiving traffic once they are actually healthy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduce the ALB health check timeout to 1 second so failures are detected faster.
Why it's wrong here
Reducing the ALB health check timeout to 1 second makes the health check overly sensitive to transient network latency and slow application startup. The ALB will often mark instances unhealthy due to a single slow response, causing Auto Scaling to terminate instances that are still initializing. This accelerates instance churn rather than solving the problem, because the grace period, not the health check speed, is what protects instances during boot.
- ✓
Increase the Auto Scaling group health check grace period to cover application startup and initialization time.
Why this is correct
The ASG health check grace period tells Auto Scaling to ignore failing health checks for a period after instance launch. This prevents newly launched instances from being replaced before the application has finished booting and can pass ALB health checks.
- ✗
Enable connection draining on the ALB target group but set deregistration delay to 0 seconds.
Why it's wrong here
Connection draining with a deregistration delay of 0 seconds disables the feature entirely, since the ALB will immediately close all connections when an instance deregisters. Even if draining were enabled, it only affects instances being intentionally deregistered, not instances being terminated by Auto Scaling because they failed health checks. The issue here is premature replacement due to missed grace period, which connection draining cannot address.
- ✗
Switch the ALB target group health checks from HTTP to TCP so the application does not need to return HTTP 200.
Why it's wrong here
TCP health checks only verify that the listener port accepts a TCP connection, not that the application can actually serve HTTP requests. During startup, the web server may be listening before it is ready to handle traffic, so TCP checks can mark the instance healthy prematurely and send production traffic to an unprepared instance. This increases the risk of user-facing errors and still does not fix the fundamental mismatch between the instance launch time and the Auto Scaling group's health check grace period.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.