Courseiva

DVA-C02 Development with AWS Services Practice Question

A company is using Amazon CloudFront to serve content from an Application Load Balancer (ALB) origin. The ALB is configured as an internal load balancer in a VPC. Users are getting HTTP 502 errors when accessing the CloudFront distribution. What is the MOST likely cause?

⚠ Common exam trap

Test-takers frequently assume CloudFront can reach any AWS resource within the same account, but they overlook that internal load balancers are not publicly accessible, and CloudFront requires a publicly routable endpoint or a VPC origin configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ALB is not internet-facing, so CloudFront cannot reach it.

The ALB is configured as an internal load balancer, meaning it only has private IP addresses and is accessible only within the VPC. CloudFront, being an AWS edge service outside the VPC, cannot route traffic to a private IP address without additional configuration such as a VPC origin or a public-facing ALB. This results in HTTP 502 errors because CloudFront cannot establish a connection to the origin.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ALB has AWS WAF enabled, blocking CloudFront IP addresses.

    Why it's wrong here

    A 502 Bad Gateway error from CloudFront indicates that the distribution received an invalid response from the origin or could not connect to it. If AWS WAF were blocking CloudFront IP addresses, it would typically respond with a 403 Forbidden status code, explicitly denying the request at the WAF level before it reaches the ALB's backend. Therefore, WAF blocking is not the direct cause of a 502 error, which implies a problem with the origin's response or reachability.

  • ✗

    The CloudFront distribution's cache behavior is set to cache all objects.

    Why it's wrong here

    Caching behavior in CloudFront determines how long content is stored at edge locations and how frequently it is revalidated with the origin. While misconfigured caching can lead to stale content or increased origin load, it does not cause a 502 Bad Gateway error. A 502 error signifies a fundamental issue with CloudFront's ability to establish a connection to or receive a valid response from the origin server, not a problem with content delivery or freshness.

  • ✓

    The ALB is not internet-facing, so CloudFront cannot reach it.

    Why this is correct

    CloudFront edge locations operate on the public internet and require public network connectivity to reach their configured origins. An Application Load Balancer (ALB) configured as 'internal' is only accessible via private IP addresses within its Virtual Private Cloud (VPC) and is not exposed to the public internet. Consequently, CloudFront would be unable to establish a network connection to an internal ALB, resulting in a 502 Bad Gateway error as it cannot retrieve content from the unreachable origin.

  • ✗

    The CloudFront distribution is not associated with a VPN connection to the VPC.

    Why it's wrong here

    CloudFront is a global content delivery network that serves content over the public internet. It is designed to connect to publicly accessible origins or origins secured via specific CloudFront mechanisms like Origin Access Control (OAC) for S3. CloudFront does not establish direct private network connections such as VPNs or AWS Direct Connect to a customer's VPC to reach origins. Therefore, the absence of a VPN connection is irrelevant to CloudFront's operation and would not cause a 502 error.

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.