Courseiva

SAA-C03 Design Resilient Architectures Practice Question

Exhibit

Route 53 record sets for app.example.com:
- Record 1: Type A, RoutingPolicy=Simple, AliasTarget=alb-use1.amazonaws.com
- Record 2: Type A, RoutingPolicy=Simple, AliasTarget=alb-usw2.amazonaws.com

Health check status:
hc-primary: FAILED
hc-secondary: HEALTHY

Resolver test:
$ dig +short app.example.com
alb-use1.amazonaws.com

Ops note:
The intent is to send all traffic to us-east-1 normally and fail over to us-west-2 only when the primary is unhealthy.

Based on the exhibit, DNS still sends traffic to the primary Region even though Route 53 health checks show the primary endpoint is unhealthy. What is the best change to make failover work as intended?

⚠ Common exam trap

Candidates often assume Route 53 automatically uses health check status to influence routing regardless of the routing policy, but in reality, health checks only affect routing when explicitly attached to a record in a failover or weighted routing policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a failover routing policy with a primary record and a secondary record, and attach the health check to the primary record.

A failover routing policy with a health check attached to the primary record is the only configuration that allows Route 53 to automatically stop sending traffic to an unhealthy primary endpoint and redirect it to the secondary endpoint. Without the health check attached to the primary record, Route 53 has no mechanism to detect the failure and will continue routing traffic to the primary Region, even if the health check status shows unhealthy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change both records to weighted routing with a 50/50 split so Route 53 can shift traffic gradually.

    Why it's wrong here

    Weighted routing distributes traffic according to assigned weights (e.g., 50/50) and does not incorporate health checks, so Route 53 would continue to send a portion of traffic to the primary even if it is healthy, while also sending half to the secondary. This split does not implement the required active-passive failover model, because no automatic switch occurs when the primary becomes unhealthy. The symptom of 'still sends traffic to primary' would persist because weighted routing does not evaluate endpoint health when choosing answers. For health-based failover, Route 53 needs failover routing with a health check attached to the primary record.

    When this WOULD be correct

    When you need to gradually shift traffic between two healthy endpoints (e.g., for blue/green deployment or load balancing) without health-based failover, weighted routing with a 50/50 split is appropriate.

  • ✓

    Use a failover routing policy with a primary record and a secondary record, and attach the health check to the primary record.

    Why this is correct

    Failover routing is designed for active-passive DNS behavior. With a primary and secondary record, Route 53 answers with the primary record when it is healthy and returns the secondary record when the primary health check fails. The exhibit shows simple routing, which does not express the failover intent. Switching to failover routing aligns the DNS policy with the stated requirement.

  • ✗

    Switch to latency-based routing so users are always directed to the lowest-latency Region.

    Why it's wrong here

    Latency-based routing selects the region that offers the lowest network latency for the specific client, optimizing user experience rather than enforcing a business preference for a primary region. It does not use health checks to fail over; if the primary endpoint remains the lowest-latency target even while unhealthy, Route 53 will continue directing traffic there, matching the reported symptom. This policy cannot implement a strict active-passive model because it lacks a primary/secondary hierarchy and would not automatically shift traffic solely on health status. A failover routing policy with a health check on the primary record is required to achieve the desired behavior.

    When this WOULD be correct

    This option would be correct in a scenario where the goal is to optimize performance by directing users to the region with the lowest latency, and health checks are not the primary concern (e.g., both endpoints are healthy and the focus is on reducing latency).

  • ✗

    Use geolocation routing so clients in one Region are sent to the healthier endpoint.

    Why it's wrong here

    Geolocation routing determines DNS responses based on the geographic location of the requesting client, not on the operational health of the target endpoints. Even if one region is 'healthier,' Route 53 would continue to serve the record mapped to each client's location, ignoring any health-check failures on the primary. This approach cannot express the requirement of preferring one region and failing over only when it is unhealthy, because geo policies do not include health evaluation in their decision logic. The observed behavior of traffic still going to the primary would remain unchanged unless the client’s location happens to map elsewhere.

    When this WOULD be correct

    A company needs to route users to specific endpoints based on their geographic origin (e.g., comply with data sovereignty laws) and has healthy endpoints in each region. Geolocation routing would ensure users are directed to the correct regional endpoint regardless of latency or failover needs.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Use a failover routing policy with a primary record and a secondary record, and attach the health check to the primary record.Correct answer▾

Why this is correct

Failover routing is designed for active-passive DNS behavior. With a primary and secondary record, Route 53 answers with the primary record when it is healthy and returns the secondary record when the primary health check fails. The exhibit shows simple routing, which does not express the failover intent. Switching to failover routing aligns the DNS policy with the stated requirement.

✗Change both records to weighted routing with a 50/50 split so Route 53 can shift traffic gradually.Wrong answer — click to see why▾

Why this is wrong here

Weighted routing distributes traffic based on weights, not health; it does not automatically failover when a health check fails, so unhealthy primary would still receive traffic.

★ When this WOULD be the correct answer

When you need to gradually shift traffic between two healthy endpoints (e.g., for blue/green deployment or load balancing) without health-based failover, weighted routing with a 50/50 split is appropriate.

Why candidates choose this

Candidates may think a 50/50 split allows Route 53 to balance traffic and automatically shift away from unhealthy endpoints, but weighted routing lacks health-based failover logic.

✗Switch to latency-based routing so users are always directed to the lowest-latency Region.Wrong answer — click to see why▾

Why this is wrong here

Latency-based routing directs users to the region with the lowest latency, not based on health. Even if the primary endpoint is unhealthy, it may still receive traffic if it has lower latency, failing to achieve the desired failover.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the goal is to optimize performance by directing users to the region with the lowest latency, and health checks are not the primary concern (e.g., both endpoints are healthy and the focus is on reducing latency).

Why candidates choose this

Candidates may think latency-based routing inherently handles failover by routing away from unhealthy endpoints, but it does not consider health status; it only considers latency measurements.

✗Use geolocation routing so clients in one Region are sent to the healthier endpoint.Wrong answer — click to see why▾

Why this is wrong here

Geolocation routing directs traffic based on the client's geographic location, not health status. Even if the primary endpoint is unhealthy, clients in the primary region would still be routed to it, failing to achieve failover.

★ When this WOULD be the correct answer

A company needs to route users to specific endpoints based on their geographic origin (e.g., comply with data sovereignty laws) and has healthy endpoints in each region. Geolocation routing would ensure users are directed to the correct regional endpoint regardless of latency or failover needs.

Why candidates choose this

Candidates may think geolocation routing can be used to send traffic away from an unhealthy region by associating the unhealthy region with a different endpoint, but Route 53 geolocation does not consider health checks for routing decisions.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.