SAA-C03 Design Resilient Architectures Practice Question
Exhibit
Route 53 record sets for app.example.com: - Record 1: Type A, RoutingPolicy=Simple, AliasTarget=alb-use1.amazonaws.com - Record 2: Type A, RoutingPolicy=Simple, AliasTarget=alb-usw2.amazonaws.com Health check status: hc-primary: FAILED hc-secondary: HEALTHY Resolver test: $ dig +short app.example.com alb-use1.amazonaws.com Ops note: The intent is to send all traffic to us-east-1 normally and fail over to us-west-2 only when the primary is unhealthy.
Based on the exhibit, DNS still sends traffic to the primary Region even though Route 53 health checks show the primary endpoint is unhealthy. What is the best change to make failover work as intended?
⚠ Common exam trap
Candidates often assume Route 53 automatically uses health check status to influence routing regardless of the routing policy, but in reality, health checks only affect routing when explicitly attached to a record in a failover or weighted routing policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a failover routing policy with a primary record and a secondary record, and attach the health check to the primary record.
A failover routing policy with a health check attached to the primary record is the only configuration that allows Route 53 to automatically stop sending traffic to an unhealthy primary endpoint and redirect it to the secondary endpoint. Without the health check attached to the primary record, Route 53 has no mechanism to detect the failure and will continue routing traffic to the primary Region, even if the health check status shows unhealthy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change both records to weighted routing with a 50/50 split so Route 53 can shift traffic gradually.
Why it's wrong here
Weighted routing distributes traffic according to assigned weights (e.g., 50/50) and does not incorporate health checks, so Route 53 would continue to send a portion of traffic to the primary even if it is healthy, while also sending half to the secondary. This split does not implement the required active-passive failover model, because no automatic switch occurs when the primary becomes unhealthy. The symptom of 'still sends traffic to primary' would persist because weighted routing does not evaluate endpoint health when choosing answers. For health-based failover, Route 53 needs failover routing with a health check attached to the primary record.
When this WOULD be correct
When you need to gradually shift traffic between two healthy endpoints (e.g., for blue/green deployment or load balancing) without health-based failover, weighted routing with a 50/50 split is appropriate.
- ✓
Use a failover routing policy with a primary record and a secondary record, and attach the health check to the primary record.
Why this is correct
Failover routing is designed for active-passive DNS behavior. With a primary and secondary record, Route 53 answers with the primary record when it is healthy and returns the secondary record when the primary health check fails. The exhibit shows simple routing, which does not express the failover intent. Switching to failover routing aligns the DNS policy with the stated requirement.
- ✗
Switch to latency-based routing so users are always directed to the lowest-latency Region.
Why it's wrong here
Latency-based routing selects the region that offers the lowest network latency for the specific client, optimizing user experience rather than enforcing a business preference for a primary region. It does not use health checks to fail over; if the primary endpoint remains the lowest-latency target even while unhealthy, Route 53 will continue directing traffic there, matching the reported symptom. This policy cannot implement a strict active-passive model because it lacks a primary/secondary hierarchy and would not automatically shift traffic solely on health status. A failover routing policy with a health check on the primary record is required to achieve the desired behavior.
When this WOULD be correct
This option would be correct in a scenario where the goal is to optimize performance by directing users to the region with the lowest latency, and health checks are not the primary concern (e.g., both endpoints are healthy and the focus is on reducing latency).
- ✗
Use geolocation routing so clients in one Region are sent to the healthier endpoint.
Why it's wrong here
Geolocation routing determines DNS responses based on the geographic location of the requesting client, not on the operational health of the target endpoints. Even if one region is 'healthier,' Route 53 would continue to serve the record mapped to each client's location, ignoring any health-check failures on the primary. This approach cannot express the requirement of preferring one region and failing over only when it is unhealthy, because geo policies do not include health evaluation in their decision logic. The observed behavior of traffic still going to the primary would remain unchanged unless the client’s location happens to map elsewhere.
When this WOULD be correct
A company needs to route users to specific endpoints based on their geographic origin (e.g., comply with data sovereignty laws) and has healthy endpoints in each region. Geolocation routing would ensure users are directed to the correct regional endpoint regardless of latency or failover needs.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Use a failover routing policy with a primary record and a secondary record, and attach the health check to the primary record.Correct answer▾
Why this is correct
Failover routing is designed for active-passive DNS behavior. With a primary and secondary record, Route 53 answers with the primary record when it is healthy and returns the secondary record when the primary health check fails. The exhibit shows simple routing, which does not express the failover intent. Switching to failover routing aligns the DNS policy with the stated requirement.
✗Change both records to weighted routing with a 50/50 split so Route 53 can shift traffic gradually.Wrong answer — click to see why▾
Why this is wrong here
Weighted routing distributes traffic based on weights, not health; it does not automatically failover when a health check fails, so unhealthy primary would still receive traffic.
★ When this WOULD be the correct answer
When you need to gradually shift traffic between two healthy endpoints (e.g., for blue/green deployment or load balancing) without health-based failover, weighted routing with a 50/50 split is appropriate.
Why candidates choose this
Candidates may think a 50/50 split allows Route 53 to balance traffic and automatically shift away from unhealthy endpoints, but weighted routing lacks health-based failover logic.
✗Switch to latency-based routing so users are always directed to the lowest-latency Region.Wrong answer — click to see why▾
Why this is wrong here
Latency-based routing directs users to the region with the lowest latency, not based on health. Even if the primary endpoint is unhealthy, it may still receive traffic if it has lower latency, failing to achieve the desired failover.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the goal is to optimize performance by directing users to the region with the lowest latency, and health checks are not the primary concern (e.g., both endpoints are healthy and the focus is on reducing latency).
Why candidates choose this
Candidates may think latency-based routing inherently handles failover by routing away from unhealthy endpoints, but it does not consider health status; it only considers latency measurements.
✗Use geolocation routing so clients in one Region are sent to the healthier endpoint.Wrong answer — click to see why▾
Why this is wrong here
Geolocation routing directs traffic based on the client's geographic location, not health status. Even if the primary endpoint is unhealthy, clients in the primary region would still be routed to it, failing to achieve failover.
★ When this WOULD be the correct answer
A company needs to route users to specific endpoints based on their geographic origin (e.g., comply with data sovereignty laws) and has healthy endpoints in each region. Geolocation routing would ensure users are directed to the correct regional endpoint regardless of latency or failover needs.
Why candidates choose this
Candidates may think geolocation routing can be used to send traffic away from an unhealthy region by associating the unhealthy region with a different endpoint, but Route 53 geolocation does not consider health checks for routing decisions.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.