AWS Certified DevOps Engineer – ProfessionalResilient Cloud SolutionsHard

A global SaaS company provides a critical API service to its customers. The API uses an Amazon Aurora PostgreSQL database as its backend. To meet a Recovery Point Objective (RPO) of near-zero and a Recovery Time Objective (RTO) of less than 5 minutes during a regional disaster, the company has implemented an Aurora Global Database. In the event of a primary region failure, what is the most appropriate and fastest way to promote a secondary region to become the new primary?

  1. AManually create a new Aurora database in the secondary region from the latest snapshot and then update application endpoints.
  2. BPerform an unplanned failover (managed planned failover) of the Aurora Global Database, promoting a secondary cluster.
  3. CInitiate a planned failover operation from the primary region to the secondary region using the Aurora console or API.
  4. DUse AWS Backup to restore the primary database to the secondary region and update DNS records.
Show answer & explanation

Correct answer: B. Perform an unplanned failover (managed planned failover) of the Aurora Global Database, promoting a secondary cluster.

For an Aurora Global Database, an unplanned failover (which AWS now refers to as 'managed planned failover' in the context of Global Database promotion) is the fastest way to promote a secondary cluster to primary during a regional disaster, meeting the RTO of less than 5 minutes and near-zero RPO by using the continuously replicated data.

Why the other options are wrong

  • A. Creating from a snapshot is a slow process and would not meet the RTO of less than 5 minutes, nor the near-zero RPO.
  • C. A 'planned failover' is typically used for maintenance or testing, where the primary is still available. In a disaster scenario (primary region failure), an unplanned failover (promotion of a secondary) is required.
  • D. Restoring from AWS Backup is a much slower process than promoting a Global Database secondary and would not meet the stringent RTO.

Aurora Global Database Unplanned Failover

An unplanned failover for an Aurora Global Database involves promoting a secondary cluster in a different region to become the new primary, typically in less than a minute, to recover from a primary region outage with near-zero data loss (near-zero RPO).

  • Used for disaster recovery when the primary region is unavailable.
  • Promotes a secondary cluster to primary role.
  • Achieves very low RTO (often <1 minute) and RPO (near-zero).
  • Requires updating application endpoints to point to the new primary.

Memory trick: When the primary region burns, Global DB's unplanned promotion quickly makes a new leader.

More Resilient Cloud Solutions questions