DVA-C02 Deployment Practice Question
A company has a production environment running on AWS. The environment includes an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application is deployed using AWS CodeDeploy with a blue/green deployment strategy. Recently, the deployment started failing because the new instances do not pass the health checks configured on the ALB. The health check path is '/health'. The developer has verified that the application starts correctly and responds to the health check on the new instances when accessed directly via the instance's private IP. However, the health checks from the ALB are failing. The security group for the ALB allows inbound traffic on port 80 from 0.0.0.0/0, and the security group for the EC2 instances allows inbound traffic on port 80 from the ALB's security group. The VPC has both public and private subnets. The Auto Scaling group launches instances in private subnets. The ALB is in public subnets. What is the MOST likely cause of the health check failure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The network ACL on the private subnets is blocking inbound traffic from the ALB's subnets.
The correct answer is D: the network ACL on the private subnets is blocking inbound traffic from the ALB's subnets. Network ACLs are stateless and operate at the subnet level, so even though the EC2 security group allows port 80 from the ALB's security group, a NACL rule denying inbound traffic from the ALB's public subnet CIDR would silently drop the ALB health check packets before they reach the instances. This matches the symptom that the app responds on its private IP directly but ALB health checks to '/health' fail. Option A is wrong because the developer confirmed the application starts and responds on port 80 directly. Option B is wrong because the path '/health' was verified as working on the instances. Option C is wrong because an ALB can only target instances in the same VPC (or peered VPCs), and the scenario implies they are in the same VPC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application is not listening on port 80 on the new instances.
Why it's wrong here
If the application can be accessed directly on the new instances (e.g., via a bastion host or public IP), it confirms that the application process is running and successfully listening on the expected port, typically port 80 or 443. This direct access validates the application's operational status and its ability to bind to the specified port. Therefore, the problem is not with the application itself failing to start or listen, but rather with network traffic from the Application Load Balancer (ALB) failing to reach the instance.
- ✗
The health check path is configured incorrectly in the ALB target group.
Why it's wrong here
The existing note confirms that the health check path, '/health', is correctly configured within the ALB target group. This means the ALB is attempting to evaluate the instances' health using the designated endpoint. Since the path itself is correct, the issue is not a misconfiguration of the health check URL, but rather a deeper network problem preventing the ALB's health check requests from successfully reaching the instances and receiving a response.
- ✗
The ALB is not in the same VPC as the instances.
Why it's wrong here
The confirmation that the Application Load Balancer (ALB) and the EC2 instances reside within the same Virtual Private Cloud (VPC) eliminates a fundamental network isolation issue. For an ALB to successfully route traffic to its registered targets, they must share the same VPC. This ensures basic network reachability at the highest level of network segmentation, meaning the problem lies in a more granular network control.
- ✓
The network ACL on the private subnets is blocking inbound traffic from the ALB's subnets.
Why this is correct
Network ACLs (NACLs) operate at the subnet level and are stateless, meaning they evaluate every inbound and outbound packet independently. Even if the security groups on the EC2 instances permit inbound traffic from the ALB's subnets, a restrictive NACL on the private subnets hosting the instances could explicitly deny this traffic. This scenario is a common cause of connectivity failures, as NACLs can block traffic even when security groups are correctly configured to allow it, requiring explicit rules for both inbound and outbound traffic.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.