Courseiva
Coordinate rolling updates →mediumMultiple Choice

EX294 Coordinate rolling updates Practice Question

A team uses Ansible to update a database cluster with one primary and two replicas. The goal is zero downtime. Which update order is the safest?

⚠ Common exam trap

Test-takers frequently assume updating the primary first is safer because it is the 'source of truth,' but in a clustered environment with zero-downtime requirements, updating replicas first is the standard practice to preserve write availability and allow safe rollback.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update replicas first, then the primary.

Updating replicas first ensures that if the update introduces a regression, it affects only the read-only replicas, which can be quickly rolled back without impacting write availability. Once replicas are confirmed healthy, the primary is updated and a controlled failover (e.g., using `patronictl switchover` or `repmgr standby switchover`) promotes a replica to primary, minimizing downtime to seconds. This order aligns with the principle of reducing blast radius and maintaining quorum in a cluster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Update replicas first, then the primary.

    Why this is correct

    Updating replicas first keeps the primary serving traffic throughout, so no write outage occurs. Each replica is drained from the load balancer, patched, and rejoined before touching the next. Only after both replicas run the new version is the primary failed over and updated, satisfying the zero-downtime constraint.

  • ✗

    Update in random order.

    Why it's wrong here

    Random ordering gives no control over which node is updated when, so a replica could be patched while the primary still runs incompatible code, breaking replication. Random selection suits stateless fleets where any host can be replaced independently.

  • ✗

    Update all nodes simultaneously.

    Why it's wrong here

    Updating every node at once takes the entire cluster offline, since no primary or replica remains to serve queries. Simultaneous updates are acceptable for stateless web tiers behind a load balancer, where other instances absorb the traffic.

  • ✗

    Update the primary first, then replicas.

    Why it's wrong here

    Updating the primary first causes a failover or write outage, so replicas briefly serve stale or unavailable data. Replicas should be updated before the primary, allowing promotion and rollback. Primary-first is tempting because it mirrors the cluster's logical hierarchy, but it inverts the safe rolling order.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.