SAA-C03 Design Secure Architectures Practice Question
An order-processing application becomes slow when traffic spikes. The frontend should stay responsive even if downstream workers are temporarily overloaded. What should the team add to the design?
⚠ Common exam trap
Many candidates confuse scaling solutions (like larger instances or NAT Gateways) with decoupling patterns, failing to recognize that asynchronous message queuing is the correct approach to keep the frontend responsive under load.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon SQS queue between the frontend and the workers
Adding an Amazon SQS queue between the frontend and the workers decouples the components, allowing the frontend to remain responsive by immediately offloading requests to the queue even when downstream workers are overloaded. The workers can then process messages at their own pace, and the queue acts as a buffer to absorb traffic spikes without blocking the frontend.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon SQS queue between the frontend and the workers
Why this is correct
Amazon SQS acts as a durable buffer between the frontend and the worker instances, so incoming orders are immediately acknowledged and stored in the queue while workers consume messages at a pace they can handle. During a traffic spike, the queue absorbs the burst, preventing the frontend from being overwhelmed and allowing workers to scale out independently. It also provides at-least-once delivery and retries, which improves resilience when processing is temporarily slow or fails.
- ✗
A larger NAT Gateway
Why it's wrong here
A larger NAT Gateway only increases the throughput of outbound internet connections for resources in private subnets; it does not store or process order messages. Application latency spikes are not caused by lack of network address translation capacity, but by workers being unable to handle the sudden increase in workload. Since no queueing or compute capacity is added, the workers remain the bottleneck and the application stays slow.
When this WOULD be correct
In a scenario where the application experiences high outbound traffic from private subnets to the internet and is hitting NAT Gateway bandwidth limits, a larger NAT Gateway would be the correct answer to increase throughput.
- ✗
A single bigger EC2 instance for the worker
Why it's wrong here
Scaling up to a single larger EC2 instance gives the worker more vCPUs and memory, which can raise the maximum processing rate, but it does not provide any buffering for traffic bursts. Once the spike exceeds the instance's throughput, orders are still delayed, and the instance becomes a single point of failure. The correct approach is to scale out horizontally behind a queue, so multiple workers can process concurrently and capacity can be adjusted to match demand.
When this WOULD be correct
A question where the bottleneck is CPU or memory on a single worker instance, and the goal is to handle increased load without redesigning the architecture (e.g., a legacy monolithic application that cannot be distributed).
- ✗
An Amazon Route 53 health check on the frontend
Why it's wrong here
A Route 53 health check continuously tests the frontend's availability and can route DNS traffic to healthy endpoints, but it sends traffic to the application and does nothing to absorb a spike in order volume. Even if the frontend remains healthy, the backend workers are still the constrained resource, and the health check cannot decouple the two tiers or add processing capacity. It is designed for failover and latency-based routing, not for smoothing bursts of asynchronous work.
When this WOULD be correct
A Route 53 health check on the frontend would be correct in a scenario where the application needs to detect frontend failure and route traffic to a standby frontend in a different region for high availability.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Amazon SQS queue between the frontend and the workersCorrect answer▾
Why this is correct
Amazon SQS acts as a durable buffer between the frontend and the worker instances, so incoming orders are immediately acknowledged and stored in the queue while workers consume messages at a pace they can handle. During a traffic spike, the queue absorbs the burst, preventing the frontend from being overwhelmed and allowing workers to scale out independently. It also provides at-least-once delivery and retries, which improves resilience when processing is temporarily slow or fails.
✗A larger NAT GatewayWrong answer — click to see why▾
Why this is wrong here
A larger NAT Gateway increases outbound bandwidth but does not decouple the frontend from workers; it does not help the frontend stay responsive when workers are overloaded.
★ When this WOULD be the correct answer
In a scenario where the application experiences high outbound traffic from private subnets to the internet and is hitting NAT Gateway bandwidth limits, a larger NAT Gateway would be the correct answer to increase throughput.
Why candidates choose this
Candidates may think that scaling network capacity (NAT Gateway) will resolve performance issues, confusing network bandwidth with application-level decoupling needed to handle worker overload.
✗A single bigger EC2 instance for the workerWrong answer — click to see why▾
Why this is wrong here
Scaling vertically to a single bigger EC2 instance does not address traffic spikes that overwhelm workers; it creates a single point of failure and does not provide elasticity or decoupling. The frontend would still block if the single worker is overloaded.
★ When this WOULD be the correct answer
A question where the bottleneck is CPU or memory on a single worker instance, and the goal is to handle increased load without redesigning the architecture (e.g., a legacy monolithic application that cannot be distributed).
Why candidates choose this
Candidates may think that a larger instance can handle more load, ignoring that spikes require horizontal scaling and decoupling to keep the frontend responsive.
✗An Amazon Route 53 health check on the frontendWrong answer — click to see why▾
Why this is wrong here
Route 53 health checks monitor endpoint availability and trigger DNS failover, but they do not decouple the frontend from downstream workers or absorb traffic spikes. The frontend would still directly invoke workers, causing overload and slowdowns.
★ When this WOULD be the correct answer
A Route 53 health check on the frontend would be correct in a scenario where the application needs to detect frontend failure and route traffic to a standby frontend in a different region for high availability.
Why candidates choose this
Candidates may think health checks can detect worker overload and redirect traffic, but health checks only assess endpoint health (e.g., HTTP 200), not load or queue depth, and cannot buffer requests.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.