Courseiva

SOA-C02 Reliability and Business Continuity Practice Question

A company runs a production database on Amazon RDS for MySQL with Multi-AZ enabled. During a recent Availability Zone outage, the database experienced a failover. After the failover, the application team notices that the database endpoint in the connection string no longer works. What is the most likely cause?

⚠ Common exam trap

It's easy for candidates to assume the endpoint itself changes or that the instance identifier is modified, when in fact only the underlying IP address changes and the DNS record is updated automatically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application is using the IP address of the database instance instead of the DNS endpoint.

When Multi-AZ failover occurs, RDS updates the DNS CNAME record to point to the new primary instance in a different Availability Zone. If the application uses the IP address directly instead of the DNS endpoint, it will continue to resolve to the old (now failed) instance's IP, which is no longer accessible. The DNS endpoint is the only stable reference that automatically follows the failover.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The application is using the IP address of the database instance instead of the DNS endpoint.

    Why this is correct

    When a Multi-AZ failover occurs, RDS promotes the standby database instance in a different Availability Zone, which has a different private IP address. The DNS CNAME for the RDS endpoint is automatically updated to point to the new instance's IP. If the application has hardcoded the old IP address rather than using the endpoint, it will not re-resolve DNS and will fail to connect to the new active instance. Always use the RDS DNS endpoint so that connections are directed to the current primary.

  • ✗

    The DB instance identifier changed after the failover.

    Why it's wrong here

    The DB instance identifier is a logical name that remains unchanged across a failover. RDS preserves the identifier, the endpoint, and the master credentials for the DB instance even when the underlying compute and storage are replaced. A Multi-AZ failover simply promotes a pre-provisioned standby to primary; it does not create a new DB instance record. Therefore, any application that references the instance by identifier (such as with IAM authentication or resource policies) will continue to work without modification.

  • ✗

    The security group for the RDS instance was modified during the failover.

    Why it's wrong here

    RDS does not modify security group configurations during a failover. The security groups attached to an RDS instance are stored at the service layer and applied to whichever underlying host is running. However, the new primary instance's private IP address will differ from the old one, so if the application's outbound security group or network ACL restricts traffic to the exact old IP rather than the RDS DNS endpoint, connectivity will be lost despite the security group itself being unchanged. This is a client-side network rule issue, not a modification by AWS.

  • ✗

    The DNS CNAME record for the RDS endpoint was manually changed.

    Why it's wrong here

    The RDS endpoint is a CNAME record that is fully managed by AWS and automatically repointed to the promoted standby's IP address during a failover. A manual change to the CNAME is neither supported nor typical; customers cannot modify the RDS-managed DNS entries through Route 53 or their own DNS servers. Even if someone tried to create an override, the original endpoint would still be owned by AWS. The automation of the DNS update is the reason applications using the endpoint automatically recover, so a manual CNAME change is not part of the failover behavior.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.