SAP ASCS/ERS High Availability Architecture on AWS
A company is running SAP on AWS and wants to ensure high availability for SAP Central Services (ASCS) and Enqueue Replication Server (ERS). Which architecture meets this requirement?
Quick Answer
The correct architecture for SAP ASCS/ERS high availability on AWS is to deploy ASCS and ERS on separate EC2 instances in different Availability Zones, fronted by a Network Load Balancer. This design is essential because SAP’s enqueue replication mechanism (enrep) synchronizes the lock table between the two instances, enabling automatic failover without data loss only when they reside in distinct failure domains. On the AWS Certified SAP on AWS Specialty PAS-C01 exam, this question tests your understanding of the fundamental HA requirement that ASCS and ERS must never share a single Availability Zone or EC2 instance—a common trap is assuming a single AZ with a second instance suffices, which violates SAP’s split-brain prevention logic. Remember the mnemonic: “Separate Zones, Single NLB, Sync Locks” to recall that the NLB provides a stable endpoint while enrep handles state replication across AZs.
⚠ Common exam trap
Candidates often assume ASCS and ERS can be co-located on the same instance or in the same AZ for simplicity, but the PAS-C01 exam explicitly tests the requirement for separate instances in different AZs with an NLB to meet SAP's HA architecture for critical services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy ASCS and ERS on separate EC2 instances in different Availability Zones, with a Network Load Balancer.
SAP Central Services (ASCS) and Enqueue Replication Server (ERS) must run on separate EC2 instances in different Availability Zones to achieve high availability. A Network Load Balancer (NLB) is used to distribute traffic and provide a single endpoint, while the enqueue replication mechanism (enrep) synchronizes the lock table between the two instances, enabling automatic failover without data loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy ASCS and ERS on the same EC2 instance with S3 replication.
Why it's wrong here
Single instance does not provide HA.
- ✗
Configure Route 53 health checks to switch between two instances in the same AZ.
Why it's wrong here
Same AZ does not protect against AZ failure.
- ✓
Deploy ASCS and ERS on separate EC2 instances in different Availability Zones, with a Network Load Balancer.
Why this is correct
Multi-AZ with separate instances and NLB ensures HA.
- ✗
Use a single EC2 instance with an S3 bucket for shared storage and Lambda for failover.
Why it's wrong here
S3 and Lambda do not provide SAP HA.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PAS-C01 question from scratch — 1,616 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
8 more ways this is tested on PAS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is deploying SAP NetWeaver on AWS and needs to ensure high availability for the SAP Central Services (ASCS) and Enqueue Replication Server (ERS). Which AWS services can be used to implement a failover cluster for ASCS and ERS? (Select THREE.)
medium- A.AWS CloudTrail
- ✓ B.Elastic Load Balancing
- ✓ C.Amazon Route 53
- D.AWS Config
- ✓ E.Custom scripts to manage floating IP and start/stop services
Why B: Elastic Load Balancing (ELB) is correct because it can be used in conjunction with a Network Load Balancer (NLB) to provide a stable endpoint for SAP ASCS and ERS failover. The NLB supports static IP addresses and can be configured with health checks that monitor the SAP service, automatically routing traffic to the healthy node in the cluster. This eliminates the need for a traditional floating IP and integrates with AWS-native failover mechanisms.
Variation 2. A company is running SAP HANA on AWS and needs to ensure high availability for the SAP Central Services (ASCS/ERS) instance. Which TWO actions should be taken to achieve this? (Choose two.)
medium- ✓ A.Configure ASCS and ERS on separate EC2 instances in different Availability Zones.
- B.Use an Application Load Balancer to distribute traffic between ASCS and ERS instances.
- ✓ C.Use a Network Load Balancer with a floating IP address for the SAP virtual hostname.
- D.Deploy both ASCS and ERS on the same EC2 instance to reduce latency.
- E.Place both ASCS and ERS in the same Availability Zone to minimize network latency.
Why A: SAP Central Services (ASCS/ERS) must run on separate EC2 instances to avoid a single point of failure. Placing them in different Availability Zones (AZs) ensures that if one AZ fails, the other instance can take over, providing high availability. This aligns with SAP's recommendation for a multi-AZ architecture for ASCS/ERS in an SAP HANA on AWS environment.
Variation 3. A company is running SAP ERP on AWS and wants to ensure high availability for the SAP Central Services (ASCS) instance. Which AWS service should be used to achieve this?
medium- A.EC2 Auto Scaling
- ✓ B.Elastic Load Balancer (NLB)
- C.Amazon Route 53
- D.AWS Global Accelerator
Why B: For SAP ASCS high availability, AWS recommends using a Network Load Balancer (NLB) to manage the virtual IP address (VIP) required by SAP. The NLB handles the failover of the ASCS instance between two EC2 nodes by directing traffic to the active node, ensuring seamless client connectivity without relying on a floating IP or custom scripts.
Variation 4. A company runs SAP on AWS and wants to implement a high-availability (HA) solution for SAP Central Services (ASCS/ERS) using Amazon EC2 instances. Which AWS service is essential for managing the virtual IP address (VIP) required for the HA cluster?
medium- A.AWS Global Accelerator
- ✓ B.Amazon Route 53
- C.AWS WAF
- D.Application Load Balancer
Why B: Amazon Route 53 is essential for managing the virtual IP address (VIP) required for the SAP Central Services (ASCS/ERS) HA cluster because it provides DNS-based failover. When the active ASCS instance fails, the HA cluster updates a Route 53 DNS record to point to the standby instance's IP address, effectively migrating the VIP. This allows clients to reconnect using the same DNS name without needing an elastic IP or a network-level VIP, which is not natively supported in AWS for this use case.
Variation 5. A company is migrating its SAP ERP system to AWS. The system requires high availability for the SAP Central Services (ASCS) instance. Which AWS architecture should be used to meet this requirement?
medium- ✓ A.Use a multi-AZ deployment with Amazon FSx for NetApp ONTAP as a shared file system and place ASCS on two EC2 instances in different Availability Zones with an Elastic IP address.
- B.Use Amazon S3 to store the ASCS configuration and launch a single EC2 instance with an Auto Scaling group.
- C.Deploy ASCS on a single EC2 instance in one Availability Zone with an EBS volume snapshot for recovery.
- D.Use Amazon RDS for SAP Central Services running in a Multi-AZ configuration.
Why A: SAP ASCS requires a highly available shared file system and a floating IP address for failover. Amazon FSx for NetApp ONTAP provides a highly available, NFS-based shared file system that supports the SAP transport and profile directories across Availability Zones. Placing two EC2 instances in different AZs with an Elastic IP address allows the ASCS instance to be failed over manually or via a cluster manager, meeting the high availability requirement.
Variation 6. A company is migrating its SAP ERP system to AWS. The system requires high availability for the SAP central services (ASCS) and must support automatic failover. Which AWS architecture should the company use to meet these requirements?
medium- A.Configure a Network Load Balancer in front of two ASCS instances in different Availability Zones.
- B.Use Amazon RDS Multi-AZ to host the SAP central services.
- ✓ C.Deploy ASCS on an EC2 instance in an Auto Scaling group with a lifecycle hook that triggers a Lambda function to reattach the ASCS cluster resources.
- D.Run ASCS on a single EC2 instance in a single Availability Zone with an Elastic IP address.
Why C: It describes a pattern for achieving automatic failover of SAP ASCS using an Auto Scaling group with a lifecycle hook. When the ASCS instance fails, the Auto Scaling group launches a new instance, and the lifecycle hook triggers a Lambda function that reattaches the cluster resources (e.g., EIP, EBS volumes, or shared file systems) to the new instance, enabling the SAP ENSA2 or ENSA1 cluster to resume operations without manual intervention.
Variation 7. A company is migrating its SAP ERP system to AWS. They need to ensure high availability for the SAP Central Services (ASCS) instance. Which AWS architecture should they implement?
medium- ✓ A.Configure a two-node cluster with a virtual IP (VIP) using AWS Route 53 health checks and failover
- B.Run ASCS on Amazon RDS for SAP with Multi-AZ
- C.Deploy ASCS on a single large EC2 instance
- D.Use an Auto Scaling group with a minimum of 2 instances
Why A: SAP ASCS requires a highly available cluster with a virtual IP (VIP) that can fail over between two EC2 instances. AWS Route 53 health checks can monitor the VIP and update DNS records to redirect traffic to the standby node upon failure, providing the necessary high availability for the ASCS instance without relying on a single point of failure.
Variation 8. A company is migrating its SAP NetWeaver system to AWS and wants to implement a high-availability architecture for the SAP Central Services (ASCS) and Enqueue Replication Server (ERS). Which TWO of the following are required components in a recommended AWS HA setup for ASCS and ERS?
medium- ✓ A.A shared file system (e.g., Amazon EFS) to store the SAP transport directory and global profile.
- B.An Application Load Balancer to distribute traffic between ASCS and ERS instances.
- ✓ C.A floating IP address (using Elastic IP or Route 53 health checks) to manage the ASCS virtual hostname.
- D.A read replica of the SAP HANA database to offload application traffic.
- E.A secondary Windows Server Failover Cluster in a different Availability Zone.
Why A: In an SAP NetWeaver high-availability architecture on AWS, a shared file system such as Amazon EFS is required to store the SAP transport directory and global profile. This ensures that both the ASCS and ERS instances can access consistent configuration and transport files, which is essential for failover and cluster operations. Without a shared file system, the instances would have divergent configurations, breaking the HA setup.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PAS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PAS-C01 exam.