Question 1 · choose 2
An order service runs on Amazon EC2 instances in an Auto Scaling group that spans three Availability Zones behind an Application Load Balancer. It uses a single-AZ Amazon RDS for PostgreSQL DB instance, and all private subnets send traffic to a payment provider through one zonal NAT gateway in the first Availability Zone. The service must keep working if any one Availability Zone fails, with the least ongoing operational effort. Which changes should the DevOps engineer make? (Choose TWO.)
- AConvert the DB instance to a Multi-AZ DB instance deployment
- BCreate a read replica in a second Availability Zone and promote it by hand if the primary DB instance becomes unavailable
- CReplace the zonal NAT gateway with a regional NAT gateway and route the private subnets in every Availability Zone to it
- DAdd a second zonal NAT gateway in another Availability Zone and keep all private route tables pointed at the first NAT gateway
- EMove the DB instance to a larger instance class with Provisioned IOPS storage to absorb the extra load after a zone failure
Show the answer and why
AConvert the DB instance to a Multi-AZ DB instance deployment
Correct
RDS then keeps a synchronous standby in a different Availability Zone and fails over to it automatically when the primary or its Availability Zone fails.
BCreate a read replica in a second Availability Zone and promote it by hand if the primary DB instance becomes unavailable
Incorrect
Promotion is a manual step that turns the replica into a standalone instance, so it adds operational work during the outage.
CReplace the zonal NAT gateway with a regional NAT gateway and route the private subnets in every Availability Zone to it
Correct
A regional NAT gateway expands across the Availability Zones where the workload runs, so outbound traffic no longer depends on one zone.
DAdd a second zonal NAT gateway in another Availability Zone and keep all private route tables pointed at the first NAT gateway
Incorrect
Traffic still goes only through the first NAT gateway, so losing its Availability Zone still cuts off the other zones.
EMove the DB instance to a larger instance class with Provisioned IOPS storage to absorb the extra load after a zone failure
Incorrect
More capacity in one Availability Zone does not help when that zone is the one that fails.
The two single points of failure are the single-AZ database and the NAT gateway in one zone. Multi-AZ gives the database automatic failover, and a regional NAT gateway removes the shared dependency on one Availability Zone.
AWS documentation