Skip to content
BytePatterns

SOA-C03 · Domain 2: Reliability and Business Continuity · 22% of the exam

Task 2.2: Implement highly available and resilient environments.

Staying up when a part fails: load balancer and Route 53 health checks that take bad targets out, and Multi-AZ deployments that fail over on their own.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A web application runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. Sometimes the application process on an instance hangs. The load balancer then marks that target unhealthy and stops routing to it, but the instance stays InService in the group and is never replaced, so the group runs with less working capacity. What should the operations team change?

  1. ARaise the target group's unhealthy threshold count to its maximum value
  2. BTurn on cross-zone load balancing for the load balancer
  3. CTurn on Elastic Load Balancing health checks for the Auto Scaling group
  4. DLengthen the health check grace period of the Auto Scaling group
Show the answer and why
  • ARaise the target group's unhealthy threshold count to its maximum value

    Incorrect

    More consecutive failures would only delay when the load balancer marks the target unhealthy. The group still would not act on it.

  • BTurn on cross-zone load balancing for the load balancer

    Incorrect

    Cross-zone load balancing spreads requests across targets in all enabled zones. It does not tell the group which instances to replace.

  • CTurn on Elastic Load Balancing health checks for the Auto Scaling group

    Correct

    With this health check type on, the group uses the load balancer's view of each instance, so an instance that fails it is marked unhealthy and replaced.

  • DLengthen the health check grace period of the Auto Scaling group

    Incorrect

    The grace period only protects newly launched instances from being replaced while they start. It does not detect a hung application.

By default an Auto Scaling group uses only EC2 status checks, which pass as long as the instance itself runs. Load balancer health checks must be turned on for the group to replace instances whose application is broken.

Question 2 · choose 1

An internal service is reached through failover records in an Amazon Route 53 private hosted zone. The primary record points to an Amazon EC2 instance that has only a private IP address. The Route 53 health check that the team attached to the primary record checks that private IP address and always reports the endpoint as unhealthy, although the service works. How should the team monitor the primary's health?

  1. AAllow the published Route 53 health checker IP ranges in the instance's security group
  2. BSwitch the health check to HTTPS with string matching on the response body
  3. CReplace the failover records with multivalue answer records for both instances
  4. DBase the health check on a CloudWatch alarm that watches the instance
Show the answer and why
  • AAllow the published Route 53 health checker IP ranges in the instance's security group

    Incorrect

    Route 53 health checkers run outside the VPC. To check an endpoint in a VPC by IP address, the instance needs a public IP address, so opening the security group is not enough.

  • BSwitch the health check to HTTPS with string matching on the response body

    Incorrect

    Any endpoint check still has to reach the private IP address from outside the VPC, which it cannot do.

  • CReplace the failover records with multivalue answer records for both instances

    Incorrect

    Multivalue answer records also rely on the health checks linked to them, so the primary would still look unhealthy.

  • DBase the health check on a CloudWatch alarm that watches the instance

    Correct

    A health check can monitor a CloudWatch alarm instead of an endpoint. AWS gives this pattern for instances in a VPC that have only private IP addresses.

Route 53 health checkers probe from the internet. For private resources, let CloudWatch watch the resource and let Route 53 watch the alarm.

Question 3 · choose 1

An order database runs on a Single-AZ Amazon RDS for MySQL DB instance. A new requirement says the database must survive the loss of an Availability Zone automatically, without losing committed transactions, and the applications must keep using the same endpoint. What should the operations team do?

  1. AModify the DB instance into a Multi-AZ DB instance deployment with one standby
  2. BCreate a read replica in another Availability Zone and promote it during an outage
  3. CCopy the automated snapshots of the DB instance to another AWS Region every day
  4. DRaise the backup retention period to 35 days for point-in-time recovery
Show the answer and why
  • AModify the DB instance into a Multi-AZ DB instance deployment with one standby

    Correct

    RDS keeps a synchronous standby in another zone and fails over to it automatically, changing the DB instance's DNS record to point to the standby.

  • BCreate a read replica in another Availability Zone and promote it during an outage

    Incorrect

    Promotion is a manual step that reboots the replica and can take several minutes or longer, and read replicas are updated asynchronously.

  • CCopy the automated snapshots of the DB instance to another AWS Region every day

    Incorrect

    Restoring a snapshot is a manual rebuild into a new DB instance, and everything written after the last snapshot would be lost.

  • DRaise the backup retention period to 35 days for point-in-time recovery

    Incorrect

    Point-in-time recovery creates a new DB instance from backups. It is neither automatic nor on the same endpoint.

Automatic failover with synchronous replication and an unchanged endpoint is exactly what a Multi-AZ DB instance deployment provides. Replicas, snapshots and backups all need a manual step and a new endpoint.

Question 4 · choose 2

An Application Load Balancer is enabled in Availability Zones A and B. Its targets come from an Auto Scaling group of four Amazon EC2 instances, all launched in one subnet in Availability Zone A. The company wants the web tier to keep serving users if any one Availability Zone fails, and the operations team decides to spread the group across Zones A, B and C. Which changes are required? (Choose TWO.)

  1. AAdd subnets in Availability Zones B and C to the Auto Scaling group
  2. BLaunch the instances in a cluster placement group
  3. CRaise the group's desired capacity from four to eight instances in the same subnet
  4. DTurn on sticky sessions for the target group
  5. EEnable Availability Zone C for the load balancer
Show the answer and why
  • AAdd subnets in Availability Zones B and C to the Auto Scaling group

    Correct

    The group keeps an equal number of instances across its enabled zones and launches in another healthy zone when launches in one zone fail.

  • BLaunch the instances in a cluster placement group

    Incorrect

    A cluster placement group sits in a single Availability Zone, which is the opposite of zone redundancy.

  • CRaise the group's desired capacity from four to eight instances in the same subnet

    Incorrect

    More instances in one subnet still sit in one zone, so a zone failure still takes down the whole tier.

  • DTurn on sticky sessions for the target group

    Incorrect

    Stickiness sends a client's later requests to the same target. It does not place targets in more zones.

  • EEnable Availability Zone C for the load balancer

    Correct

    The load balancer does not route requests to registered targets in a zone that is not enabled for it, so the new instances in Zone C would receive no traffic.

Zone redundancy needs both halves: instances in several zones, and a load balancer enabled in each of those zones.

Practise domain 2 →Practise all domains →