What the exam asks
- Choose the routing policy for the requirement: active-passive failover, percentage split, lowest latency, country-based compliance, ISP-based routing, or several healthy IPs.
- Configure health checks that actually detect the failure: endpoint, string match, calculated, or CloudWatch alarm-based for private resources.
- Use alias records for the zone apex and AWS targets instead of CNAMEs or hard-coded IPs.
- Build hybrid DNS with Route 53 Resolver inbound and outbound endpoints, forwarding rules and AWS RAM sharing.
- Explain why failover was slow: the health check detected nothing, or DNS caching (TTL) kept clients on the old answer.
Core ideas
Routing policies
| Policy | What it does | Exam keywords |
|---|---|---|
| Simple | One record, one or more values returned in random order; no health checks | Single resource, no failover |
| Failover | Primary answer while healthy, secondary when the primary is unhealthy | Active-passive, maintenance page, DR site |
| Weighted | Splits answers by relative weight (0–255) | Canary, blue/green, “send 5% to v2” |
| Latency | Answers with the Region that has the lowest measured latency for the user | “Lowest latency”, global users, multi-Region active-active |
| Geolocation | Answers by the user’s continent, country or US state; add a Default record | Compliance, data residency, localised content, licensing |
| Geoproximity | Answers by distance to resources, with a bias to grow or shrink an area | “Shift more traffic to a Region” by geography |