SOA-C02 Networking and Content Delivery Practice Question
A SysOps administrator is setting up Amazon Route 53 for a domain that will be used for a web application. The application requires failover to a backup data center in another region if the primary becomes unhealthy. The administrator creates a failover routing policy with two records (primary and secondary) associated with health checks. After testing, the failover does not occur when the primary endpoint fails. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The health check is configured to monitor the secondary endpoint instead of the primary
Failover routing relies on health checks to determine the health of the primary endpoint. If the health check is mistakenly configured to monitor the secondary endpoint, it will not assess the primary's health. Consequently, Route 53 will not trigger a failover to the secondary when the primary fails. Option A is incorrect because alias records are not required for failover; they are only needed for AWS resources. Option B is incorrect because the registrar's nameservers do not affect Route 53's failover logic once the domain is delegated. Option D is incorrect because while a high TTL can delay propagation, it does not prevent failover from occurring; failover depends on health check status, not TTL.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The primary record is not an alias record
Why it's wrong here
Alias records in Route 53 are only required when you want to route traffic to AWS resources like Elastic Load Balancers or CloudFront distributions without paying for queries, but failover routing works equally with standard A or AAAA records. In a failover configuration, the routing decision is based on the health check associated with the record, not on whether the record is an alias. The lack of an alias record would not prevent Route 53 from evaluating the health status and switching to the secondary record, so this is not the cause of the problem.
- ✗
The domain registrar's nameservers are not pointing to Route 53
Why it's wrong here
For the domain to resolve at all, the registrar's nameservers must delegate the zone to the Route 53 hosted zone's nameservers; if they are not pointing correctly, end users would get NXDOMAIN or a different answer, and Route 53 would never receive queries for the record. Since the symptom is that failover does not occur rather than that the domain is entirely unresolvable, DNS resolution is already working, so delegation is not the issue. Nameserver delegation affects query routing, not Route 53's ability to monitor health checks or execute failover.
- ✓
The health check is configured to monitor the secondary endpoint instead of the primary
Why this is correct
In Route 53 failover routing, the primary record must be associated with a health check that monitors the primary endpoint. If the health check instead monitors the secondary endpoint, it will remain healthy even when the primary goes down, so Route 53 will never see the failure and will continue returning the primary record in responses. This configuration directly prevents failover from triggering, making it the correct explanation for why the secondary resource is never used.
- ✗
The TTL on the primary record is set too high
Why it's wrong here
The TTL determines how long recursive resolvers and clients cache DNS responses; it does not influence Route 53's server-side decision to switch records when a health check fails. If the TTL were too high, you might observe that some clients continue using the old primary IP for a while after failover occurs, but you would still expect Route 53 to eventually respond with the secondary. In a scenario where failover never happens, the faulty logic lies in the health check configuration, not in the TTL value.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.