SAA-C03 Design Resilient Architectures Practice Question
An engineering team deploys a stateless web API on EC2 using an Auto Scaling group and an Application Load Balancer (ALB). During a recent test, they noticed that when one Availability Zone was unavailable, traffic failed until new instances were manually launched. Which change most directly improves automatic failover for the compute layer within a single Region?
⚠ Common exam trap
Candidates often think a single-AZ deployment with a load balancer provides failover, but without multiple AZs, the load balancer itself becomes a single point of failure and cannot reroute traffic when the AZ goes down.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the ALB and Auto Scaling group span multiple subnets in at least two Availability Zones.
An Application Load Balancer (ALB) and Auto Scaling group must span multiple subnets in at least two Availability Zones (AZs) to provide automatic failover. When one AZ becomes unavailable, the ALB automatically reroutes traffic to healthy targets in the remaining AZs, and the Auto Scaling group can launch replacement instances in the surviving AZs. This architecture ensures that the compute layer remains available without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place the Auto Scaling group in only one subnet so instance launches are simpler.
Why it's wrong here
Placing the Auto Scaling group in only one subnet deliberately strips out redundancy; the group can only launch instances in that single Availability Zone. An outage of that AZ means all instances are unreachable, and the Auto Scaling group cannot automatically replace them in a healthy zone because it has no capacity configured there. Simpler launches do not outweigh the availability risk for a production web API.
When this WOULD be correct
If the question asked for a cost-optimized design for a non-critical application where high availability is not required, and the goal is to simplify management and reduce cross-AZ data transfer costs, then using a single subnet would be appropriate.
- ✓
Ensure the ALB and Auto Scaling group span multiple subnets in at least two Availability Zones.
Why this is correct
An Application Load Balancer is a regional service that routes traffic to healthy targets across the Availability Zones it is enabled in. By spanning the ALB and Auto Scaling group across at least two AZs, an AZ failure leaves the remaining instances serving traffic while health checks automatically redirect requests away from the failed zone, preserving availability for the stateless web API. This aligns with AWS best practices for fault-tolerant multi-AZ architectures.
- ✗
Increase the target group deregistration delay to allow old instances to stay longer.
Why it's wrong here
The deregistration delay controls how long a target that is being removed from the target group can continue to accept requests so in-flight connections can drain gracefully. Increasing it only makes old instances live longer during scaling operations or deployments; it has zero impact on how many instances are running, where they are placed, or whether the group spans multiple Availability Zones. It therefore cannot improve resilience to an AZ failure.
When this WOULD be correct
This option would be correct in a scenario where the question asks how to ensure in-flight requests complete gracefully during a deployment or scaling event, without dropping connections. For example: 'An application requires that all active requests finish before instances are terminated during a rolling update. Which setting should be adjusted?'
- ✗
Use a Network Load Balancer, but keep all subnets in a single Availability Zone.
Why it's wrong here
Switching to a Network Load Balancer does not fix the root cause because the load balancer and targets remain confined to a single Availability Zone. An NLB is zonal per enabled subnet; if that one AZ experiences an outage, both the load balancer entry point and all registered instances become unavailable, so requests fail despite the different load balancer type. High availability requires multiple AZs regardless of which load balancer you choose.
When this WOULD be correct
When the requirement is to handle extremely high throughput and low latency for a TCP/UDP workload, and the application is designed to run in a single Availability Zone (e.g., due to data locality constraints), a Network Load Balancer in that zone would be the correct choice.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Ensure the ALB and Auto Scaling group span multiple subnets in at least two Availability Zones.Correct answer▾
Why this is correct
An Application Load Balancer is a regional service that routes traffic to healthy targets across the Availability Zones it is enabled in. By spanning the ALB and Auto Scaling group across at least two AZs, an AZ failure leaves the remaining instances serving traffic while health checks automatically redirect requests away from the failed zone, preserving availability for the stateless web API. This aligns with AWS best practices for fault-tolerant multi-AZ architectures.
✗Place the Auto Scaling group in only one subnet so instance launches are simpler.Wrong answer — click to see why▾
Why this is wrong here
Placing the Auto Scaling group in only one subnet (single AZ) defeats the purpose of high availability; if that AZ fails, all instances are lost, and the ALB has no healthy targets in other AZs to route traffic to, causing complete failure.
★ When this WOULD be the correct answer
If the question asked for a cost-optimized design for a non-critical application where high availability is not required, and the goal is to simplify management and reduce cross-AZ data transfer costs, then using a single subnet would be appropriate.
Why candidates choose this
Candidates may think that simplifying subnet configuration reduces complexity and potential misconfigurations, overlooking that this eliminates fault tolerance and the ability to survive an AZ outage.
✗Increase the target group deregistration delay to allow old instances to stay longer.Wrong answer — click to see why▾
Why this is wrong here
Increasing the deregistration delay keeps old instances longer, but does not help automatically launch new instances in a healthy AZ when one AZ fails. It only delays connection draining, not failover.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the question asks how to ensure in-flight requests complete gracefully during a deployment or scaling event, without dropping connections. For example: 'An application requires that all active requests finish before instances are terminated during a rolling update. Which setting should be adjusted?'
Why candidates choose this
Candidates may think that keeping instances longer provides more time for failover, confusing connection draining with automatic recovery. They overlook that the core issue is lack of multi-AZ redundancy, not connection timeout.
✗Use a Network Load Balancer, but keep all subnets in a single Availability Zone.Wrong answer — click to see why▾
Why this is wrong here
Using a single Availability Zone for all subnets does not provide automatic failover; if that zone fails, the NLB and instances become unavailable, which does not solve the problem described.
★ When this WOULD be the correct answer
When the requirement is to handle extremely high throughput and low latency for a TCP/UDP workload, and the application is designed to run in a single Availability Zone (e.g., due to data locality constraints), a Network Load Balancer in that zone would be the correct choice.
Why candidates choose this
Candidates may think that a Network Load Balancer inherently provides better failover than an ALB, but failover depends on multi-AZ architecture, not the load balancer type.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.