Courseiva

SAP-C02 Continuous Improvement for Existing Solutions Practice Question

A company runs a latency-sensitive trading application on Amazon EC2 instances behind a Network Load Balancer. The application must maintain persistent TCP connections and uses a custom health check on port 8080. During a recent incident, the operations team observed that when an instance became unhealthy, existing connections continued to be routed to it for several minutes, causing failed trades. The team needs to ensure that unhealthy targets are removed from the load balancer rotation as quickly as possible while preserving connection draining for graceful shutdown. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

⚠ Common exam trap

The trap here is assuming that TCP keepalive settings on targets control how quickly the load balancer removes unhealthy targets, when in fact the health check configuration governs that behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the NLB health check with a shorter interval and lower unhealthy threshold, and enable connection draining with an appropriate deregistration delay.

The NLB health check interval and unhealthy threshold determine how quickly a target is marked unhealthy and removed from rotation. A shorter interval combined with a lower threshold accelerates detection. Enabling connection draining with a deregistration delay ensures that in-flight connections are allowed to complete, satisfying the graceful shutdown requirement. This approach requires only configuration changes on the existing NLB.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replace the Network Load Balancer with an Application Load Balancer and use HTTP health checks on port 8080.

    Why it's wrong here

    An Application Load Balancer operates at layer 7 and may not support the custom TCP-based protocol or persistent connections required by the trading application. Additionally, replacing the load balancer introduces significant operational overhead and does not inherently solve the rapid removal of unhealthy targets. This option is both disruptive and potentially incompatible.

  • ✓

    Configure the NLB health check with a shorter interval and lower unhealthy threshold, and enable connection draining with an appropriate deregistration delay.

    Why this is correct

    Shortening the health check interval and reducing the unhealthy threshold makes the NLB detect failures faster and remove targets from rotation sooner. Enabling connection draining with a suitable deregistration delay allows existing connections to complete gracefully. This directly addresses the requirement for rapid removal while preserving graceful shutdown, with minimal operational changes.

  • ✗

    Enable TCP keepalive on the targets and set the deregistration delay to 0 seconds.

    Why it's wrong here

    TCP keepalive helps detect dead peers but does not directly influence the load balancer's health check evaluation or deregistration behavior. Setting the deregistration delay to 0 seconds would immediately terminate connections, violating the requirement to preserve connection draining for graceful shutdown. This approach fails to balance rapid removal with graceful connection termination.

  • ✗

    Configure the NLB health check with a shorter interval and higher unhealthy threshold, and enable connection draining with a 300-second deregistration delay.

    Why it's wrong here

    A higher unhealthy threshold makes the load balancer slower to mark a target unhealthy, which would extend the time unhealthy targets remain in rotation, contrary to the goal. A 300-second deregistration delay is excessive for rapid removal, and the combination does not achieve the fastest possible removal while allowing graceful shutdown.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.