SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The SysOps administrator needs to monitor the application's HTTP 5xx error rate and set an alarm when the error rate exceeds 5% over a 5-minute period. The alarm must trigger an Amazon SNS notification. Which metric should be used for the alarm?
⚠ Common exam trap
Many candidates confuse HTTPCode_ELB_5XX_Count with HTTPCode_Target_5XX_Count, assuming all 5xx errors originate from the load balancer, when in fact the ALB separates its own errors from target-generated errors to provide precise fault isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTPCode_Target_5XX_Count
The alarm must monitor the error rate from the application targets (EC2 instances) behind the ALB. HTTPCode_Target_5XX_Count tracks HTTP 5xx responses generated by the targets themselves, which directly reflects application-level errors. To calculate the error rate, you would divide this metric by RequestCount, but the metric itself is the correct source for target-side 5xx errors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HTTPCode_ELB_5XX_Count
Why it's wrong here
The HTTPCode_ELB_5XX_Count metric tracks HTTP 5xx errors generated by the Application Load Balancer itself, not by the EC2 targets. For example, a 503 is returned when the ALB has no healthy targets to route to, or a 502 occurs from an invalid response from the target. This metric is therefore not suitable for detecting application-level HTTP 5xx failures; it only reveals infrastructure-level load balancer problems.
- ✓
HTTPCode_Target_5XX_Count
Why this is correct
The HTTPCode_Target_5XX_Count metric reports the number of HTTP 5xx responses returned directly by the registered EC2 instances, capturing errors such as 500 Internal Server Error from the application. Because these are the actual responses sent to clients from your web application, this metric is the correct measurement for an alarm that detects application-level failures. You can then create a CloudWatch alarm on this metric to trigger when the count exceeds a threshold, possibly combined with RequestCount to derive an error rate.
- ✗
RequestCount
Why it's wrong here
The `RequestCount` metric tracks the total number of requests processed by the ALB, not the proportion of failed responses. To calculate an HTTP 5xx error rate exceeding 5%, you need a ratio metric (e.g., `HTTPCode_Target_5XX_Count` divided by `RequestCount`), which `RequestCount` alone cannot provide. It is tempting because it is a fundamental ALB metric often used for traffic volume monitoring, and in scenarios where you only need to detect a raw spike in request volume (e.g., a DDoS attack), `RequestCount` would be the correct choice.
- ✗
TargetResponseTime
Why it's wrong here
TargetResponseTime measures the elapsed time from when the ALB sends the request to the target until it receives the complete response, or the time until the last byte received. It is a latency metric, not an error metric, so it cannot directly indicate HTTP 5xx responses from the application. While slow response times may correlate with errors or degraded performance, this metric does not provide the error count or rate required to alarm on HTTP 5xx failures.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.