SAA-C03 Design Secure Architectures Practice Question
A company wants to protect a critical application from a full Region outage. The secondary Region should keep only a small amount of infrastructure running most of the time to control cost. Which disaster recovery strategy fits best?
⚠ Common exam trap
It's easy for candidates to confuse 'pilot light' with 'active-active' or 'warm standby,' mistakenly thinking that any multi-Region setup must run full capacity, when the pilot light specifically minimizes cost by keeping only a minimal footprint until failover is triggered.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pilot light
The pilot light strategy is correct because it keeps a minimal core of infrastructure (e.g., a small database, a few EC2 instances) running in the secondary Region, while the bulk of the application remains dormant. In a full Region outage, the pilot light can be rapidly scaled up to full production capacity, meeting the requirement of low ongoing cost with the ability to recover from a complete Region failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Pilot light
Why this is correct
Pilot light is a disaster recovery pattern that keeps a minimal, low-cost core of the application running in the backup Region—often just the database, replication, and a small compute tier—so that in a full Region outage you can quickly scale out the remaining services by invoking pre-written IaC and orchestration runbooks. It deliberately avoids paying for idle production-scale capacity, trading a longer failover time (typically minutes to an hour) for significant cost savings while still preserving recovery capability.
- ✗
Active-active
Why it's wrong here
Active-active (multi-site active-active) serves live production traffic from two or more Regions simultaneously, requiring full application stacks, synchronized data, and global traffic routing in every location. This architecture therefore multiplies infrastructure and operational costs, introduces data-conflict and consistency challenges, and is far more expensive than the minimal-footprint approach the requirement is asking for. If the business need is only to survive a regional outage with reduced cost, active-active over-provisions for that goal.
When this WOULD be correct
Active-active would be correct for a scenario requiring zero downtime and immediate failover, where the application must serve traffic from multiple regions concurrently to handle high availability and low latency, and cost is not a primary constraint.
- ✗
Single-AZ deployment
Why it's wrong here
A single-AZ deployment places all resources within one Availability Zone, which is a physically isolated data center facility inside a single Region. Because an entire Region sustains an outage—for example, a natural disaster or loss of utility power affecting all AZs—this topology has no capacity to fail over to another geographic location. Even if you mitigate with multi-AZ replication, you remain confined to that one Region and cannot meet the protection requirement.
When this WOULD be correct
This option would be correct for a question asking for a cost-effective deployment that maximizes availability within a single Region, where the application can tolerate a single AZ failure and the goal is to minimize complexity and cost.
- ✗
Blue/green deployment
Why it's wrong here
Blue/green deployment is a release-management technique where two identical environments coexist and traffic is switched from the current 'blue' version to the new 'green' version after validation. It does not by itself create any geographically distributed standby architecture, nor does it include data replication or failover mechanisms to another Region. While it enables rapid rollback and zero-downtime application updates, it is not a disaster recovery strategy and cannot address a full Region outage.
When this WOULD be correct
A company wants to deploy a new version of an application with zero downtime and the ability to quickly roll back if issues arise. Blue/green deployment would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Pilot lightCorrect answer▾
Why this is correct
Pilot light is a disaster recovery pattern that keeps a minimal, low-cost core of the application running in the backup Region—often just the database, replication, and a small compute tier—so that in a full Region outage you can quickly scale out the remaining services by invoking pre-written IaC and orchestration runbooks. It deliberately avoids paying for idle production-scale capacity, trading a longer failover time (typically minutes to an hour) for significant cost savings while still preserving recovery capability.
✗Active-activeWrong answer — click to see why▾
Why this is wrong here
Active-active runs full production workloads in both regions simultaneously, which does not minimize infrastructure in the secondary region and increases cost, contrary to the requirement to keep only a small amount of infrastructure running most of the time.
★ When this WOULD be the correct answer
Active-active would be correct for a scenario requiring zero downtime and immediate failover, where the application must serve traffic from multiple regions concurrently to handle high availability and low latency, and cost is not a primary constraint.
Why candidates choose this
Candidates may choose active-active because it provides high availability and fast failover, but they overlook the cost implication of running full infrastructure in both regions, which contradicts the cost control requirement.
✗Single-AZ deploymentWrong answer — click to see why▾
Why this is wrong here
Single-AZ deployment provides no protection against a full Region outage because it operates within a single Availability Zone. The question requires cross-Region disaster recovery, which this option does not address.
★ When this WOULD be the correct answer
This option would be correct for a question asking for a cost-effective deployment that maximizes availability within a single Region, where the application can tolerate a single AZ failure and the goal is to minimize complexity and cost.
Why candidates choose this
Candidates may think that deploying in a single AZ is sufficient for basic high availability, or they confuse AZ-level redundancy with Region-level disaster recovery, overlooking the requirement for cross-Region protection.
✗Blue/green deploymentWrong answer — click to see why▾
Why this is wrong here
Blue/green deployment is a release strategy for updating applications with minimal downtime, not a disaster recovery strategy for region outages. It does not address infrastructure in a secondary region.
★ When this WOULD be the correct answer
A company wants to deploy a new version of an application with zero downtime and the ability to quickly roll back if issues arise. Blue/green deployment would be the correct answer.
Why candidates choose this
Candidates may confuse blue/green deployment with failover scenarios because both involve switching between environments, but blue/green is for updates, not disaster recovery.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.