hardMultiple Choice
CCSP Practice Question: Is designing a cloud application that must remain…
An organization is designing a cloud application that must remain available even if an entire AWS availability zone fails. Which architecture pattern should they implement?
⚠ Common exam trap
ISC2 often tests the distinction between surviving an AZ failure versus a region failure, and the trap here is that candidates may overcomplicate the solution by choosing multi-region active-active, not realizing that a single region with multiple AZs is sufficient and more cost-effective for the given requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Single region with multiple AZs active-active
The correct architecture is a single region with multiple Availability Zones (AZs) in an active-active configuration. This ensures that if one AZ fails, the application continues to serve traffic from the remaining AZs without any manual intervention, as all AZs are actively handling requests. AWS Availability Zones are physically separate data centers within a region, and an active-active pattern distributes the workload across them to achieve high availability and fault tolerance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Single region with multiple AZs active-active
Why this is correct
Running active-active across multiple availability zones within one region lets traffic fail over instantly when an entire AZ becomes unavailable, because each AZ has independent power, cooling and networking. This satisfies the requirement to survive a full AZ failure without regional latency penalties.
- ✗
Single region with multiple AZs active-standby
Why it's wrong here
Active-standby within one region leaves the standby idle and still tied to that region's control plane; a full AZ loss triggers failover delay rather than continuous serving. It suits cost-sensitive workloads needing only AZ-level redundancy with an acceptable recovery window, not uninterrupted availability.
- ✗
Active-passive in a single region
Why it's wrong here
Active-passive leaves the passive node idle until failover, so an AZ outage causes downtime during promotion and DNS or load-balancer reconfiguration. It fits disaster recovery with a defined RTO, not continuous availability across an AZ failure.
- ✗
Multi-region active-active
Why it's wrong here
Multi-region active-active exceeds the stated requirement, adding cross-region data replication, conflict resolution and traffic-routing complexity that an AZ-failure scenario does not demand. It is the right pattern when a whole region, not merely one availability zone, must be survived.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.