SAA-C03 Design Resilient Architectures Practice Question
Exhibit
Application Load Balancer Subnets: subnet-a1 (us-east-1a), subnet-b1 (us-east-1b) Auto Scaling group VPCZoneIdentifier: subnet-a1 (us-east-1a) DesiredCapacity: 2 MinSize: 2 MaxSize: 4 CloudWatch HealthyHostCount: 2 HTTPCode_Target_5XX_Count: 0 Troubleshooting note A planned test that disabled us-east-1a caused the application to become unreachable.
Based on the exhibit, the web application must remain available even if one Availability Zone fails. What is the best change to improve resilience with the least redesign?
⚠ Common exam trap
Test-takers frequently think increasing instance count or changing load balancer type improves resilience, but without multi-AZ distribution, a single AZ failure still causes a total outage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add subnet-b1 in a different Availability Zone to the Auto Scaling group.
Adding subnet-b1 in a different Availability Zone to the Auto Scaling group ensures that EC2 instances are launched across two Availability Zones. If one zone fails, the ALB can route traffic to healthy instances in the other zone, maintaining application availability. This change requires minimal redesign because it only modifies the Auto Scaling group's subnet configuration without altering the load balancer or compute architecture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase DesiredCapacity to 4 while keeping all instances in subnet-a1.
Why it's wrong here
This adds more instances, but they are still all in the same Availability Zone. If us-east-1a fails, every instance is lost together and the application still goes down. Capacity is not the same as fault isolation.
When this WOULD be correct
This option would be correct if the question asked for a way to handle increased traffic while keeping all instances in the same subnet, and resilience across AZs was not required.
- ✓
Add subnet-b1 in a different Availability Zone to the Auto Scaling group.
Why this is correct
This spreads EC2 instances across two Availability Zones, so the Auto Scaling group can continue serving traffic if one AZ becomes unavailable. Because the ALB is already deployed in both subnets, this is the smallest change that adds true zonal resilience to the compute tier.
- ✗
Replace the Application Load Balancer with a Network Load Balancer.
Why it's wrong here
A Network Load Balancer changes the load-balancing layer, but it does not fix the root problem: all instances are still in one AZ. If that AZ fails, there are still no healthy targets to receive traffic.
When this WOULD be correct
This option would be correct if the question required handling millions of requests per second with low latency, or if the application needed to preserve the source IP address for backend processing, as NLB operates at Layer 4 and supports these use cases.
- ✗
Enable EBS encryption on the launch template volumes.
Why it's wrong here
Enabling EBS encryption on the launch template volumes encrypts data at rest, which protects the confidentiality of data stored on the volumes, but it has no impact on availability or failover behavior. The Auto Scaling group still launches all EC2 instances in subnet-a1 within us-east-1a, so if that Availability Zone experiences an outage, all instances and their encrypted volumes become unreachable simultaneously. Encryption is a security control, not a resilience mechanism; it neither introduces redundant compute in another zone nor changes the failure domain, and it does not alter how the load balancer routes traffic or how the ASG replaces unhealthy instances.
When this WOULD be correct
This would be correct in a scenario where the question asks for a security improvement to protect sensitive data on EBS volumes, with no requirement for high availability or multi-AZ resilience.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Add subnet-b1 in a different Availability Zone to the Auto Scaling group.Correct answer▾
Why this is correct
This spreads EC2 instances across two Availability Zones, so the Auto Scaling group can continue serving traffic if one AZ becomes unavailable. Because the ALB is already deployed in both subnets, this is the smallest change that adds true zonal resilience to the compute tier.
✗Increase DesiredCapacity to 4 while keeping all instances in subnet-a1.Wrong answer — click to see why▾
Why this is wrong here
Increasing DesiredCapacity to 4 in a single subnet (subnet-a1) does not add resilience across Availability Zones; all instances remain in one AZ, so a failure of that AZ still causes total outage.
★ When this WOULD be the correct answer
This option would be correct if the question asked for a way to handle increased traffic while keeping all instances in the same subnet, and resilience across AZs was not required.
Why candidates choose this
Candidates may think that simply adding more instances provides high availability, overlooking that they must be distributed across multiple Availability Zones to survive an AZ failure.
✗Replace the Application Load Balancer with a Network Load Balancer.Wrong answer — click to see why▾
Why this is wrong here
Replacing the Application Load Balancer with a Network Load Balancer does not improve resilience across Availability Zones; it only changes the load balancer type, which operates at a different layer and does not address the single-AZ failure risk.
★ When this WOULD be the correct answer
This option would be correct if the question required handling millions of requests per second with low latency, or if the application needed to preserve the source IP address for backend processing, as NLB operates at Layer 4 and supports these use cases.
Why candidates choose this
Candidates may think that a Network Load Balancer is inherently more resilient or that changing load balancer types can fix availability issues, but resilience depends on multi-AZ deployment, not the load balancer type.
✗Enable EBS encryption on the launch template volumes.Wrong answer — click to see why▾
Why this is wrong here
Enabling EBS encryption does not improve availability or resilience across Availability Zones; it only protects data at rest. The question requires resilience against an AZ failure, which encryption does not address.
★ When this WOULD be the correct answer
This would be correct in a scenario where the question asks for a security improvement to protect sensitive data on EBS volumes, with no requirement for high availability or multi-AZ resilience.
Why candidates choose this
Candidates may confuse security measures with availability measures, or think that encryption adds redundancy, but encryption has no impact on fault tolerance.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.