certslothcertsloth
ANS-C01/Topic 04

AWS / Specialty

ELB & Auto Scaling

5 min read5 recall promptsReviewed 2026-10-10

Memory hook: A load balancer chooses a destination; an Auto Scaling group maintains capacity; application state must survive either decision.

Must remember

Pick the right traffic layer

  • Application Load Balancer (ALB) understands HTTP/HTTPS at layer 7. A listener receives traffic; ordered rules choose forward, redirect, authentication or fixed-response actions. Conditions can include host and path.
  • Target groups hold instances, IPs or supported Lambda destinations, with health checks/attributes. Path rules can select different groups.
  • Lower numbered listener priorities run first. A fixed response comes from the ALB and can succeed even when the application is unavailable.
  • Network Load Balancer (NLB) handles TCP/UDP/TLS at layer 4 and supplies static addresses per enabled AZ, with optional Elastic IPs for supported internet-facing deployments. It fits non-HTTP traffic and IP allowlist requirements.
  • NLB is not an HTTP path router. Modern NLBs support security groups in supported configurations; the old claim that NLBs never have security groups is unsafe.
  • Gateway Load Balancer (GWLB) steers traffic through network appliances using GENEVE/UDP 6081, rather than routing application URLs.
  • An internet-facing load balancer can forward to private backends; public users do not require public backend IPv4.

Connection behavior and health

  • Stickiness uses supported cookies/affinity mechanisms to favor a target. It does not replicate session memory or guarantee that target will survive.
  • Cross-zone load balancing allows a node to route across enabled AZs. ALB has it enabled at the load-balancer level, with target-group-level controls; NLB/GWLB default differently. Check transfer cost rules for the specific type.
  • Deregistration delay drains in-flight requests during removal. Too little can interrupt long work; excessive values can slow scale-in and deployments.
  • TLS termination uses listener certificates, often from ACM. SNI lets a compatible client indicate its hostname so a listener chooses the correct certificate. ALB certificates are regional; CloudFront ACM certificates use us-east-1.
  • Target health checks detect application reachability on the configured port/path. EC2 status health and application health answer different questions.
  • Health routing is not authorization: all-unhealthy/fail-open behavior can send traffic to unhealthy targets.

Scaling and replacement

  • Vertical scaling changes machine size and may require interruption; horizontal scaling changes the number of workers. Externalized state makes horizontal replacement safer.
  • AWS Auto Scaling plans coordinate resources. EC2 Auto Scaling manages instance groups; Application Auto Scaling handles supported dimensions such as ECS task counts. Plans can migrate to direct policies.
  • Launch templates describe AMIs, type, user data, interfaces and related launch settings. Updating a template does not automatically update every already-running instance.
  • An ASG maintains desired capacity between minimum and maximum bounds. Enable appropriate ELB health when application failures should cause replacement; EC2-only checks may miss a broken web process.
  • Instance refresh rolls out launch changes with health, warmup and capacity constraints.
  • Target tracking maintains a chosen metric target; step scaling changes capacity according to alarm severity; scheduled scaling anticipates known times; predictive scaling forecasts recurring demand.
  • Choose a demand-related metric: CPU can fit compute-bound servers, ALB request count per target can fit web workers, and queue backlog per worker can fit asynchronous processing.
  • Warmup/cooldown reduce unstable decisions during startup; grace periods do not prove readiness.
  • Multi-AZ subnets with desired capacity one do not provide two active replicas. Production resilience needs sufficient surviving capacity and dependencies.

Choose under exam pressure

Requirement Decision and reason
Several web apps under paths or hostnames ALB listener rules and target groups
Static addresses for TCP/UDP clients NLB
Third-party network inspection fleet GWLB
Scale before a known daily opening Scheduled scaling
Maintain utilization near a target Target tracking
Replace instances with a broken web process ASG using relevant ELB health
Roll out a new AMI to existing capacity Controlled instance refresh

Traps

  • Scaling and healing differ. Replacing an unhealthy instance can preserve the same desired capacity without adding demand capacity.
  • A cookie is not a session database. Target loss still destroys target-local state.
  • A successful listener test can bypass dependencies. Fixed responses do not prove backend, cache or database health.

Active recall

1. One HTTPS endpoint must route /images and /orders to separate services. Why is ALB a better fit than NLB?

ALB evaluates HTTP paths to select target groups. NLB selects network destinations, not URL routes; TLS termination alone does not add HTTP routing.

2. EC2 checks pass while the web process is dead. Why does the ASG keep the instance?

It may use EC2 status only. Enable relevant ELB health and meaningful target checks so application failures trigger replacement; increasing desired capacity solves a different problem.

3. A launch template now references a patched AMI. Why are current instances still unpatched?

Launch configuration controls future launches. Use instance refresh or appropriate patching with health/capacity safeguards; a template update alone does not establish a completed fleet rollout.

4. A shop loses carts during scale-in despite stickiness. What is the design fault?

Session state lives only on removable targets. Externalize required state to an appropriately resilient store. A longer deregistration delay may finish in-flight requests, but neither draining nor stickiness creates durable session storage.

5. An application has a precise daily traffic surge, then unpredictable variations. Must one scaling policy handle both?

No. Scheduled scaling prepares known surges; dynamic scaling handles variations. Coordinate bounds and warmup. Predictive scaling is another option when recurring patterns support useful forecasts.

Terraform anchor: An in-place listener change, a launch-template version and a fleet refresh have different operational effects even when each begins as a small code edit.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.