Courseiva

SAA-C03 Design High-Performing Architectures Practice Question

A web service runs on an Auto Scaling group (ASG). The team updates configuration (AMIs, environment variables) in a Launch Template and wants new instances created during scale-out to use the latest Launch Template version. What should the architect do?

⚠ Common exam trap

A common mix-up: candidates think the ASG automatically updates existing instances when the Launch Template version is changed, but without an Instance Refresh, only new scale-out instances receive the update, leaving existing instances on the old configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the ASG to use the latest Launch Template version and optionally start an instance refresh for existing instances.

The ASG can be configured to use the latest version of a Launch Template by specifying the `$Latest` version alias. This ensures that any new instances launched during scale-out automatically use the most recent template configuration (e.g., updated AMI, environment variables). Additionally, an Instance Refresh can be triggered to roll the update across existing instances, aligning them with the same latest template version without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Leave the ASG attached to the previous Launch Template version so scale-out is stable.

    Why it's wrong here

    Pinning the ASG to the previous Launch Template version means any new instances spawned during scale-out events will launch without the updated configuration, creating a mixed fleet where some instances run the old settings and others run the new ones. ASG scale-out is meant to reflect the latest desired configuration, and stability should be achieved through controlled rollout mechanisms like instance refresh windows or CloudFormation update policies, not by freezing the template. Delaying the update also exposes the fleet to unresolved bugs or security fixes indefinitely.

  • ✓

    Set the ASG to use the latest Launch Template version and optionally start an instance refresh for existing instances.

    Why this is correct

    ASG scale-out uses the configured Launch Template version at instance launch time. Switching the ASG to the latest version ensures new instances are consistent. An instance refresh helps apply changes to running instances safely and predictably.

  • ✗

    Manually SSH into each new instance and reconfigure it after it launches.

    Why it's wrong here

    Manually SSHing into each new instance to reconfigure it after launch is inherently unscalable and violates the immutable-infrastructure principle. Auto Scaling groups can add many instances in rapid succession, so manual intervention introduces significant delays, risks missing instances, and causes configuration drift between identical roles. This approach also creates a dependency on human actions during scaling events, which is unreliable in production. The correct practice is to bake configuration into the Launch Template's user data or a custom AMI so instances are fully provisioned at boot.

    When this WOULD be correct

    In a scenario where a legacy system requires one-time manual configuration changes on a few instances (e.g., applying a hotfix that cannot be automated via AMI or user data), and the ASG is not expected to scale frequently, manual SSH could be acceptable for immediate remediation.

  • ✗

    Move the configuration changes into a security group rule so the ASG updates them automatically.

    Why it's wrong here

    Security groups are stateful network firewalls that filter traffic based on IP, port, and protocol; they cannot carry or apply application configuration such as runtime parameters, environment variables, or package versions. Moving configuration changes into a security group rule would not cause the ASG or instances to update anything, and it misuses a network-layer control for a completely different purpose. Instance configuration on an ASG is managed exclusively through its Launch Template or Launch Configuration, which supply metadata and startup scripts to each new instance.

    When this WOULD be correct

    If the question asked how to automatically allow new instances to receive traffic from a specific source after scaling out, updating a security group rule would be correct, as security groups apply to all instances in the ASG automatically.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Set the ASG to use the latest Launch Template version and optionally start an instance refresh for existing instances.Correct answer▾

Why this is correct

ASG scale-out uses the configured Launch Template version at instance launch time. Switching the ASG to the latest version ensures new instances are consistent. An instance refresh helps apply changes to running instances safely and predictably.

✗Manually SSH into each new instance and reconfigure it after it launches.Wrong answer — click to see why▾

Why this is wrong here

Manually SSHing into each new instance is not scalable, error-prone, and violates automation best practices for Auto Scaling groups. The ASG should automatically use the latest Launch Template version to ensure new instances are correctly configured without manual intervention.

★ When this WOULD be the correct answer

In a scenario where a legacy system requires one-time manual configuration changes on a few instances (e.g., applying a hotfix that cannot be automated via AMI or user data), and the ASG is not expected to scale frequently, manual SSH could be acceptable for immediate remediation.

Why candidates choose this

Candidates may think manual intervention is a quick fix for configuration updates, especially if they are unfamiliar with Launch Template versioning and instance refresh features, or underestimate the operational overhead of manual steps at scale.

✗Move the configuration changes into a security group rule so the ASG updates them automatically.Wrong answer — click to see why▾

Why this is wrong here

Security group rules control network traffic, not instance configuration like AMIs or environment variables. They cannot update ASG instances or launch templates.

★ When this WOULD be the correct answer

If the question asked how to automatically allow new instances to receive traffic from a specific source after scaling out, updating a security group rule would be correct, as security groups apply to all instances in the ASG automatically.

Why candidates choose this

Candidates may confuse security groups with configuration management, thinking they can propagate changes to instances, or they may overestimate the scope of security group rules.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.