Courseiva

SAA-C03 Design Resilient Architectures Practice Question

Exhibit

Disaster recovery test results:
- Requirement: RTO <= 15 minutes, RPO <= 5 minutes
- Primary Region: full application stack running 24/7
- Secondary Region:
  - RDS cross-Region replica current within 2 minutes
  - AMIs copied to secondary Region
  - Auto Scaling group desired=0, min=0, max=6
  - No load balancer or application instances running until failover

Measured failover drill:
- Start application stack in secondary Region: 12 minutes
- Promote database replica: 4 minutes
- Update DNS and propagate: 2 minutes
- Total recovery time: 18 minutes

Based on the exhibit, the current disaster recovery design misses the RTO target even though the database replica is current. Which deployment model best meets the requirements with the least always-on cost?

⚠ Common exam trap

A common mix-up: candidates confuse pilot light with warm standby, assuming that only the database needs to be running to meet the RTO, but they overlook the time required to provision the application stack on failover.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Warm standby, because a scaled-down application stack stays running in the secondary Region and can take over faster.

Warm standby is the correct choice because it keeps a scaled-down application stack running in the secondary Region, which can be scaled up quickly to handle production traffic. This design meets the RTO target by reducing failover time compared to a pilot light, while avoiding the higher always-on cost of an active-active deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pilot light, because only the database needs to be running in the secondary Region.

    Why it's wrong here

    Pilot light keeps only a minimal set of components active in the secondary Region. In this exhibit, the database replica is already current, but the measured recovery time still exceeds the RTO because the application tier must be started from zero.

    When this WOULD be correct

    A question where the RTO is longer (e.g., hours) and the primary concern is minimizing cost while keeping critical data available. For example: 'A company needs a DR strategy that minimizes cost but can restore database access within 4 hours. The application can be rebuilt quickly from scripts.'

  • ✓

    Warm standby, because a scaled-down application stack stays running in the secondary Region and can take over faster.

    Why this is correct

    Warm standby is the best fit when you need faster recovery than pilot light but do not want the cost of full active-active capacity. The exhibit shows that starting the application stack from zero consumes most of the recovery time. Keeping a reduced but functional stack running in the secondary Region removes that startup delay and should bring the total recovery time within the 15-minute RTO while still keeping always-on cost below full production duplication.

  • ✗

    Active-active, because both Regions should always serve traffic to guarantee the RTO.

    Why it's wrong here

    Active-active can provide very fast recovery, but it requires both Regions to run at production scale and introduces significant operational complexity. The requirement asks for the least always-on cost, so this is more than necessary.

    When this WOULD be correct

    An exam scenario where the application requires near-zero RTO (e.g., under 1 minute) and can tolerate the higher cost, such as a global e-commerce platform that must remain available during a regional outage without any traffic rerouting delay.

  • ✗

    Backup and restore, because restoring from backups is the least expensive DR model available.

    Why it's wrong here

    Backup and restore is the lowest-cost disaster recovery model, but it is the slowest to recover. In this scenario, the measured recovery time already exceeds the 15-minute RTO at 18 minutes even with a warm database replica, and a true backup/restore approach would require rehydrating snapshots, rebuilding EC2 instances, and redeploying the application stack—typically taking hours, not minutes. It would also introduce RPO risk because any data changes after the last backup would be lost, making it unsuitable for this workload's recovery objectives.

    When this WOULD be correct

    A question where the RTO is lenient (e.g., hours) and the primary goal is to minimize cost, with no requirement for a current database replica. For example: 'Which DR model is the least expensive and can tolerate an RTO of several hours?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Warm standby, because a scaled-down application stack stays running in the secondary Region and can take over faster.Correct answer▾

Why this is correct

Warm standby is the best fit when you need faster recovery than pilot light but do not want the cost of full active-active capacity. The exhibit shows that starting the application stack from zero consumes most of the recovery time. Keeping a reduced but functional stack running in the secondary Region removes that startup delay and should bring the total recovery time within the 15-minute RTO while still keeping always-on cost below full production duplication.

✗Pilot light, because only the database needs to be running in the secondary Region.Wrong answer — click to see why▾

Why this is wrong here

The pilot light model only keeps the database running in the secondary Region, not the application stack. This means the application must be provisioned and scaled up after a disaster, which takes too long to meet the RTO, even if the database is current.

★ When this WOULD be the correct answer

A question where the RTO is longer (e.g., hours) and the primary concern is minimizing cost while keeping critical data available. For example: 'A company needs a DR strategy that minimizes cost but can restore database access within 4 hours. The application can be rebuilt quickly from scripts.'

Why candidates choose this

Candidates may think that because the database replica is current, only the database needs to be running to meet the RTO, overlooking the time required to start and configure the application stack.

✗Active-active, because both Regions should always serve traffic to guarantee the RTO.Wrong answer — click to see why▾

Why this is wrong here

Active-active requires both regions to serve live traffic continuously, which incurs higher always-on costs than warm standby. The question asks for the 'least always-on cost' while meeting RTO, and active-active is more expensive because it runs full production capacity in both regions.

★ When this WOULD be the correct answer

An exam scenario where the application requires near-zero RTO (e.g., under 1 minute) and can tolerate the higher cost, such as a global e-commerce platform that must remain available during a regional outage without any traffic rerouting delay.

Why candidates choose this

Candidates may think active-active is the fastest failover model and assume it always meets RTO best, overlooking the cost constraint and that warm standby can achieve the same RTO at lower cost.

✗Backup and restore, because restoring from backups is the least expensive DR model available.Wrong answer — click to see why▾

Why this is wrong here

Backup and restore typically has a high RTO because it involves restoring data from backups, which is slower than having a running replica. The question states the database replica is current, so a warm standby with a scaled-down application stack can meet the RTO faster.

★ When this WOULD be the correct answer

A question where the RTO is lenient (e.g., hours) and the primary goal is to minimize cost, with no requirement for a current database replica. For example: 'Which DR model is the least expensive and can tolerate an RTO of several hours?'

Why candidates choose this

Candidates may think backup and restore is the cheapest option and assume it can meet any RTO if backups are frequent, overlooking the time needed to restore and the fact that a current replica already exists.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.