SAA-C03 Design Resilient Architectures Practice Question
You host a public API using Amazon API Gateway in two AWS Regions: us-east-1 (primary) and us-west-2 (secondary). You want Route 53 to send client traffic to the secondary region only when the primary API is unhealthy. Which Route 53 setup best meets this requirement?
⚠ Common exam trap
Watch out — candidates often confuse weighted routing with failover routing, mistakenly believing that Route 53 health checks can automatically adjust weights to achieve active-passive failover, when in fact weighted routing does not support dynamic weight adjustment based on health.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Route 53 failover routing with two ALIAS records (same DNS name) pointing to the API Gateway regional endpoints: one record is configured as PRIMARY with an associated health check, and the other is configured as SECONDARY.
Route 53 failover routing is designed for active-passive setups where traffic is sent to a primary resource unless it is unhealthy, in which case traffic is routed to a secondary resource. By creating two ALIAS records with the same DNS name, one marked PRIMARY with an associated health check and the other marked SECONDARY, Route 53 will automatically fail over to the secondary region when the health check for the primary API Gateway endpoint fails. This directly meets the requirement of sending traffic to the secondary region only when the primary API is unhealthy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use latency-based routing with one routing policy per region, and use CloudWatch alarms to update traffic weights between regions.
Why it's wrong here
Latency-based routing selects the endpoint with the lowest network latency for each user, not the healthiest one. Using CloudWatch alarms to update traffic weights would require custom automation, and latency-based routing does not support weight changes as a native failover mechanism. Even with alarms, this approach lacks the automatic, health-check-driven failover that Route 53 failover routing provides.
- ✓
Use Route 53 failover routing with two ALIAS records (same DNS name) pointing to the API Gateway regional endpoints: one record is configured as PRIMARY with an associated health check, and the other is configured as SECONDARY.
Why this is correct
Route 53 failover routing is purpose-built for active-passive architecture across two endpoints. The PRIMARY ALIAS record is tied to a health check that monitors the API Gateway regional endpoint in the primary region; when that health check fails, Route 53 automatically returns the SECONDARY record's endpoint, redirecting traffic to the secondary region. This is the correct, fully managed way to achieve automatic regional failover for public APIs.
- ✗
Use weighted routing across both regions and rely on Route 53 health checks to automatically set the secondary to 100% weight when the primary fails.
Why it's wrong here
Weighted routing simply distributes traffic according to static weights and does not modify those weights based on health check results. While Route 53 health checks can mark an endpoint as unhealthy, they have no built-in capability to change the weight of an unhealthy record to zero or to adjust the secondary's weight to 100%. Making such weight changes would require external automation, unlike the automatic failover inherent to failover routing.
- ✗
Use geolocation routing to map some client geographies to the secondary region and the rest to the primary region.
Why it's wrong here
Geolocation routing directs DNS queries based on the geographic location of the client, not on the health or availability of the endpoints. If the primary region becomes unhealthy, clients mapped to that region will still receive the primary endpoint's DNS answer, causing outages for those users. This option provides no health-based failover and is therefore incorrect for the requirement.
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.