SAA-C03 Design Resilient Architectures Practice Question
An internal API is deployed in two AWS Regions behind separate Application Load Balancers. The company wants clients to use the primary Region when it is healthy and automatically switch to the secondary Region if the primary health check fails. Which two Route 53 record configurations are required? Select two.
⚠ Common exam trap
Many candidates confuse failover routing with weighted or latency routing, assuming any health-aware routing provides automatic primary/secondary failover, but only failover records enforce a strict active-passive pattern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a primary failover record that points to the primary ALB and associates a Route 53 health check.
A primary failover record in Amazon Route 53 directs traffic to the primary ALB and is associated with a Route 53 health check. If the health check fails, Route 53 automatically fails over to the secondary failover record, ensuring high availability across Regions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a primary failover record that points to the primary ALB and associates a Route 53 health check.
Why this is correct
A primary failover record designates the active endpoint in an active-passive configuration. Route 53 associates a health check with this record, and as long as the check returns healthy, every DNS response returns the primary ALB's IP address. When that health check fails, Route 53 stops serving the primary record and instead returns the secondary failover record, enabling automatic regional failover.
- ✗
Create a weighted record set that sends 50 percent of traffic to each Region.
Why it's wrong here
A weighted record set with a 50/50 split balances traffic across both ALBs simultaneously, which is appropriate for load distribution or canary testing. Weighted routing does not define one endpoint as primary and another as backup; if a health check disables one record, Route 53 simply reroutes all traffic to the other healthy record, but there is no ordered failover relationship. The scenario calls for a deliberate primary/secondary design, not proportional traffic splitting.
- ✓
Create a secondary failover record that points to the secondary ALB.
Why this is correct
The secondary failover record provides the standby destination that Route 53 returns only after the primary health check has failed. It is configured as a failover record with a role of 'Secondary' and, unlike the primary, typically does not have its own health check because it should only serve traffic when the primary is unhealthy. Without this record, a failed primary would cause a DNS failure because Route 53 would have no fallback address to return.
- ✗
Create a latency-based record set so Route 53 always prefers the fastest Region.
Why it's wrong here
Latency-based routing selects the Region that offers the lowest latency for each individual client, so geographically distributed clients may be sent to different Regions concurrently. This creates an active-active pattern in which both ALBs normally serve traffic, rather than keeping one inactive until the other fails. The routing decision is based on network performance, not an explicit failover order, so it does not implement a strict primary-to-secondary failover policy.
- ✗
Create a multivalue answer record to return both ALB addresses on each lookup.
Why it's wrong here
A multivalue answer record returns up to eight healthy IP addresses per response, chosen randomly via DNS, and each value must be associated with its own health check. This approach improves availability by giving clients multiple endpoints to try, but it lacks any notion of a primary or secondary relationship among the records. It also requires clients to handle multiple addresses and retries, whereas Route 53 failover routing actively replaces an unhealthy primary with a designated secondary in the DNS response.
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.