Improving Application Reliability with Auto Scaling and Aurora
A company runs an application in the cloud that consists of a database and a website. Users can post data to the website, have the data processed, and have the data sent back to them in an email. Data is stored in a MySQL database running on an Amazon EC2 instance. The database is running in a VPC with two private subnets. The website is running on Apache Tomcat in a single EC2 instance in a different VPC with one public subnet. There is a single VPC peering connection between the database and website VPC. The website has suffered several outages during the last month due to high traffic. Which actions should a solutions architect take to increase the reliability of the application? (Choose three.)
Community Insight
The exam tests your ability to identify Single Points of Failure (SPOFs) in a VPC-peered architecture and apply AWS best practices like Auto Scaling Groups, Load Balancers, and Multi-AZ database replicas to ensure reliability.
This question addresses designing a reliable architecture for a web application by eliminating single points of failure in both the compute layer (Tomcat) and the data layer (MySQL). The correct solution involves implementing high availability through redundancy and managed services.
Many candidates choose AC but miss F because they overlook that a single public subnet is not highly available. Others incorrectly select B or D, failing to realize that additional peering connections or NAT gateways do not address the core availability issues of the EC2 instances.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To increase reliability, you must remove single points of failure. Option A creates redundancy for the web tier by using an Auto Scaling Group behind an Application Load Balancer, ensuring the site stays up during traffic spikes or instance failures. Option C migrates the database to Amazon Aurora, which provides built-in multi-AZ replication and self-healing storage, significantly improving data availability compared to a single EC2-hosted MySQL instance. Although Option F is not listed in the provided options text, community comments and the standard pattern for this specific exam question confirm that 'Create an additional public subnet in a different Availability Zone' is the third required action to ensure the website tier has cross-AZ resilience.Why the Other Options Are Wrong
Option B is incorrect because adding another VPC peering connection does not increase availability; it only adds routing paths, and peering connections are not inherently redundant across AZs unless configured specifically, which isn't stated. Option D is incorrect because NAT gateways handle outbound internet access for private subnets; adding more does not help the reliability of the inbound web traffic or the database availability. Option E is incorrect and technically flawed because you cannot simply move an EC2 instance to another VPC without re-creating it, and moving the web server into the database VPC (which has no public subnets) would make it inaccessible without complex NAT configurations.Community Comment Notes
Community consensus strongly supports ACF as the correct combination. As user kejam noted, 'These increase reliability of the app,' highlighting that A, C, and F directly address SPOFs. User HunkyBunky correctly identified that moving the Tomcat server to the database VPC (Option E) is invalid because that VPC lacks public subnets. Multiple users confirmed that B and D provide no benefit to the reliability of the application stack itself.Exam Strategy
When asked about reliability, always look for 'redundancy' and 'multiple Availability Zones'. If you see a single EC2 instance handling web traffic, think Auto Scaling + Load Balancer. If you see a database on EC2, think RDS/Aurora with Multi-AZ. Avoid options that just add capacity (like more NAT gateways) unless specifically needed for throughput, not availability.
Frequently Asked Questions
Why is adding a second VPC peering connection (B) wrong for reliability?
VPC peering is not a high-availability mechanism. It connects two VPCs but does not provide redundancy against AZ failures or instance crashes within those VPCs.
Can I move an existing EC2 instance to another VPC easily?
No. You cannot directly move a running EC2 instance to a different VPC. You must create a new instance in the target VPC from a snapshot or AMI, which disrupts service.
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →