Courseiva

SOA-C02 Practice Question: CodeDeploy blue/green deployment on ECS for…

A containerized API runs on Amazon ECS with an Application Load Balancer. The team wants to deploy new container versions with zero downtime, automatically route traffic to the new version only after health checks pass, and automatically roll back if error rates spike within 10 minutes of the shift. Which deployment strategy and configuration implements all three requirements?

⚠ Common exam trap

It's easy for candidates to confuse the ECS circuit breaker (which only handles task-level failures during deployment) with the need for post-deployment error rate monitoring and traffic shifting, leading them to select Option D without realizing it lacks the canary/linear traffic shifting and CloudWatch alarm integration required for automatic rollback based on error spikes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use CodeDeploy with the ECS blue/green deployment type, configure a Canary or Linear traffic shifting strategy, and attach a CloudWatch alarm for error rate as a deployment alarm

CodeDeploy's ECS blue/green deployment type supports canary or linear traffic shifting, which automatically routes traffic to the new version only after health checks pass. By attaching a CloudWatch alarm for error rate as a deployment alarm, CodeDeploy can automatically trigger a rollback if error rates spike within the specified monitoring period (e.g., 10 minutes), meeting all three requirements: zero downtime, health-check-gated traffic shifting, and automatic rollback on error rate spikes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use CodeDeploy with the ECS blue/green deployment type, configure a Canary or Linear traffic shifting strategy, and attach a CloudWatch alarm for error rate as a deployment alarm

    Why this is correct

    The ECS blue/green deployment starts the green task set, registers it with a second target group, and uses ALB weighted routing to shift traffic progressively. The deployment alarm monitors a 5xx error rate metric. If the alarm enters ALARM state at any point during traffic shifting or the bake period, CodeDeploy automatically shifts traffic back to the original blue target group. The team defines the 10-minute bake window via the deployment configuration's terminationWaitTimeInMinutes.

  • ✗

    Update the ECS service with a rolling update deployment configuration and set the minimum healthy percent to 100

    Why it's wrong here

    Rolling updates on ECS replace tasks in-place — they do not create a parallel task set and do not support weighted ALB traffic shifting between old and new versions. Rollback requires a new deployment of the previous task definition, not an automatic revert. Rolling updates cannot satisfy the traffic-shift health check gating and automatic rollback requirements.

  • ✗

    Create a second ECS service with the new task definition and use Route 53 weighted routing to shift traffic at the DNS level

    Why it's wrong here

    Route 53 weighted routing shifts traffic at the DNS level with TTL-based propagation delays (minutes). DNS clients cache the old record, making precise traffic percentages approximate. ALB-level traffic shifting in CodeDeploy ECS blue/green is more accurate and immediate. DNS-based shifting also cannot easily achieve automatic rollback based on CloudWatch alarms.

  • ✗

    Enable ECS circuit breaker on the service to roll back failed deployments automatically

    Why it's wrong here

    The ECS circuit breaker rolls back a deployment if the new task set fails to start (tasks keep failing health checks and entering STOPPED state). It does not monitor application-level error rates after traffic is successfully shifted. It cannot implement a post-shift alarm-based rollback during a defined bake period.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.