SAA-C03 Design Resilient Architectures Practice Question
Your public API is hosted in two regions. You want Route 53 to automatically send traffic to the secondary region when the primary region’s endpoint fails. The primary API health check is returning failure codes, but clients still reach the primary region for several minutes. Which Route 53 configuration most directly addresses this behavior?
⚠ Common exam trap
Many candidates assume a short TTL alone (Option A) is sufficient for fast failover, but without health checks, Route 53 has no mechanism to detect endpoint failure and will continue returning the primary record until the TTL expires and the record is manually updated, causing the observed delay.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Route 53 failover routing with a primary record and a secondary record, each associated with its own health check, so Route 53 answers with the healthy region.
Route 53 failover routing with health checks on both primary and secondary records ensures that when the primary health check fails, Route 53 stops returning the primary record's IP and instead returns the secondary record's IP. This directly addresses the observed behavior where clients still reach the primary region for several minutes—likely because the primary record's health check was not configured or associated, or a simple routing policy was used without health check integration, causing stale DNS responses to be served until TTL expires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a single Alias A record with simple routing and a short TTL so Route 53 quickly changes the IP address.
Why it's wrong here
A single Alias A record with simple routing always returns the same endpoint regardless of its health; Route 53 does not evaluate health checks for simple routing policies. A short TTL only reduces the DNS cache duration, so clients will eventually retry, but they will keep getting the same IP address until it is manually changed. There is no automatic switch to another region, so this configuration cannot provide failover.
- ✓
Use Route 53 failover routing with a primary record and a secondary record, each associated with its own health check, so Route 53 answers with the healthy region.
Why this is correct
Failover routing is designed for this: Route 53 evaluates health checks and returns the primary record while it is healthy. When the primary health check fails, Route 53 automatically returns the secondary record. Note that clients may still see traffic for a few minutes due to DNS caching, but failover routing is the configuration that enables automatic region switching.
- ✗
Use weighted routing to send a small percentage of traffic to the secondary region, increasing it manually when the primary fails.
Why it's wrong here
Weighted routing distributes traffic by assigned weights, but it does not consider endpoint health; Route 53 will continue sending requests to the primary even if its health check fails unless you manually modify the weights. Manual adjustment is slow, relies on DNS TTL expirations, and introduces human error, making it unsuitable for automated disaster recovery. Failover routing, by contrast, changes answers automatically when the associated health check fails.
- ✗
Use latency routing only, letting Route 53 choose the lowest-latency region at query time, without health checks.
Why it's wrong here
Latency routing selects the region that offers the lowest latency for each client, but it makes this choice purely on network performance, not on whether the endpoint is actually healthy. If the primary region is down but still responds to DNS queries with the same IP, latency routing will keep directing users there because no health check is involved. It therefore lacks the deterministic health-check-based failover behavior required for active/passive disaster recovery.
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.