Memory hook: Choose the geography first, separate failure domains next, and bring eligible content closer to users at the edge.
Must remember
Region, AZ and edge answer different questions
- A Region is a geographic deployment boundary containing multiple Availability Zones. Regions are designed for isolation; launching something in one does not automatically create a copy in another.
- An Availability Zone (AZ) is one or more data centers with independent infrastructure and low-latency connectivity to other AZs in that Region. Deploying working replicas across AZs addresses a local infrastructure failure.
- AZ names such as us-east-1a can map differently between accounts; AZ IDs identify the same physical AZ across accounts. Shared networking designs should not assume matching letters mean matching locations.
- A VPC is regional; each subnet belongs to one AZ. Instances inherit the AZ of their subnet. EBS volumes and ENIs also have AZ boundaries, so they cannot simply move with an application across AZs.
- Edge locations support delivery and DNS services such as CloudFront and Route 53. They are not ordinary AZs where you launch an RDS database.
- Local Zones extend selected regional services closer to users; AWS Wavelength addresses supported telecom/5G-edge workloads; AWS Outposts brings AWS infrastructure to customer premises. These are different deployment models, not alternate names for CloudFront caches. Details belong in migration and recovery.
Choose a Region using requirements, not habit
- Apply hard constraints first: data residency, legal requirements, required service/feature availability and organizational restrictions. Check replication, backups and cached copies too.
- Then compare measured end-to-end latency, regional prices, operational support and recovery needs. The closest city is not proof of the best actual application latency.
- Multi-AZ usually addresses availability within a Region. Multi-Region addresses geographic recovery or global serving, adding replication, consistency, failover and cost decisions.
- A second subnet or a standby deployment description does not itself provide active application capacity. Ask what is running, where data resides, and how clients reconnect when a component fails.
Scope and responsibility
- IAM and Route 53 have global control planes. EC2, VPC and RDS use regional resources. S3's shared bucket-name namespace does not make the bucket's data globally replicated.
- A provider or CLI default Region selects an API context; it does not migrate existing resources or change every global service.
- The AWS Management Console is a browser interface to services; console access does not bypass IAM or automatically select the correct account and Region.
- Under shared responsibility, AWS secures underlying cloud facilities, hardware and infrastructure. Customers remain responsible for identities, data classification, access permissions and their service configuration.
- For normal EC2, the customer patches the guest OS and application. With managed databases, AWS manages more of the underlying platform, but customers still design access, schemas, backup choices and recovery procedures. More managed does not mean responsibility-free.
Choose under exam pressure
| Requirement or clue | Decision and reason |
|---|---|
| Survive one AZ failing | Working capacity and data resilience across AZs |
| Recover after a regional disaster | Cross-Region recovery plan with explicit RPO/RTO |
| Worldwide users download public images | Edge caching, if global copies are permitted |
| Customer records must remain in a jurisdiction | Approved regional storage, backup and replication locations |
| Same AZ across accounts matters | Compare AZ IDs, not only AZ letters |
| AWS compute required on premises | Consider Outposts rather than a CDN edge |
Traps
- Availability is not geographic recovery. Multiple AZs remain inside one Region; an edge cache is not a complete database recovery plan.
- A global name is not a global copy. Know the data location separately from the resource's naming or control-plane scope.
- A managed service still needs a customer design. Wrong access policies or missing application recovery can undermine reliable infrastructure.
Active recall
1. A regulated database must stay in Germany, while product images need fast global delivery. Must every component stay in one location?
No. Keep regulated database data and its recovery copies in approved locations. Eligible images can use CloudFront globally if their own residency policy permits it. Requirements attach to the data and workload, not automatically to every component in the application.
2. An ALB spans two AZs but its ASG has one running instance. What availability claim is unsafe?
Claiming two active application replicas. The load balancer spans AZs, but backend capacity remains one instance. Replacement may restore service later; it does not provide immediate surviving application capacity during that instance's failure.
3. Two accounts select us-east-1a for a shared appliance design. What should be verified?
The AZ IDs. AZ letters can be mapped differently between accounts. A same-AZ networking requirement depends on physical placement, so matching account-local labels alone is insufficient.
4. Moving an application from EC2 to RDS removes which responsibility, and retains which?
For the managed database, AWS operates more of the database platform and underlying OS. The customer still controls application access, data, database users and recovery choices. This does not remove responsibility for securing the workload.
5. The cheapest Region lacks a required service feature. Is it still the cost-optimized answer?
Not if the feature is a hard requirement. Eliminate designs that fail requirements first, then optimize cost among viable alternatives. A lower unit price for an unusable architecture is not a solution.
Terraform anchor: Provider configuration selects API scope; data sources discover facts, while preconditions can reject an inconsistent regional design.
Sources
- AWS Regions and Zones — geography, placement and edge extensions.
- AWS shared responsibility — customer and AWS responsibilities.
- Availability Zone IDs — physical AZ alignment between accounts.
- SAA-C03 exam guide — secure, resilient, performant and cost-aware design objectives.