Exchanges utilize synchronous replication across AZs to ensure strict ACID compliance, meaning trade data isn't "final" until all zones acknowledge the write. During a partial outage, a degraded AZ creates a "slowest-common-denominator" bottleneck where healthy nodes stall while waiting for the lagging zone to commit logs.
Failing over or operating in a single AZ would break the deterministic latency required for fair market execution and risk "split-brain" data corruption. Consequently, the system triggers a fail-closed state to preserve the integrity of the order book.