Courseiva

DVA-C02 Troubleshooting and Optimization Practice Question

A company runs a production web application on EC2 instances behind an Application Load Balancer. Users report intermittent 502 errors. The developers find that the ALB access logs show 'target_response_code' of 502 for some requests. What is the MOST likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The EC2 instances are closing idle connections prematurely due to a short keep-alive timeout.

The 502 Bad Gateway error from an Application Load Balancer indicates that the target (EC2 instance) closed the connection before the ALB could finish writing the request or reading the response. This commonly occurs when the keep-alive timeout on the EC2 instance is set too low, causing idle connections to be closed prematurely. Option A is incorrect because DNS resolution issues would not cause a 502; they would cause a 503 or connection failure. Option B is incorrect because a security group blocking traffic would result in health check failures and a 503, not a 502. Option D is incorrect because unhealthy instances would cause a 503, not a 502.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The EC2 instances are unable to resolve DNS for the ALB.

    Why it's wrong here

    EC2 instances function as targets for the Application Load Balancer (ALB), meaning the ALB initiates connections to them to forward client requests. The ALB resolves the DNS names or IP addresses of the registered EC2 instances within its target group. Conversely, the EC2 instances themselves do not need to resolve the ALB's DNS name to receive incoming traffic, as they are passive recipients of connections initiated by the ALB. Therefore, an inability for EC2 instances to resolve the ALB's DNS would not cause a 502 Bad Gateway error, which indicates an issue with the response from the target.

  • ✗

    The security group for the EC2 instances is blocking traffic from the ALB.

    Why it's wrong here

    If the security group associated with the EC2 instances were blocking incoming traffic from the Application Load Balancer (ALB), the ALB would be unable to establish a connection with the target instances. In such a scenario, the ALB would typically mark the instances as unhealthy and return an HTTP 503 Service Unavailable error to the client, indicating that no healthy targets are available to process the request. A 502 Bad Gateway error, however, implies that the ALB *did* establish a connection but received an invalid, incomplete, or unexpected response from the backend server.

  • ✓

    The EC2 instances are closing idle connections prematurely due to a short keep-alive timeout.

    Why this is correct

    When an Application Load Balancer (ALB) forwards a request to a target EC2 instance, it maintains a persistent connection using HTTP keep-alive. If the EC2 instance's web server (e.g., Apache, Nginx, or application server) has a `keep-alive_timeout` configured to be shorter than the ALB's idle timeout (default 60 seconds) or the time it takes for the ALB to send the full request or receive the full response, the instance might prematurely close the TCP connection. This abrupt closure, while the ALB is still expecting a response or attempting to send data, results in the ALB receiving an unexpected connection termination, which it translates into an HTTP 502 Bad Gateway error for the client.

  • ✗

    The ALB health checks are failing and the target group has unhealthy instances.

    Why it's wrong here

    If the Application Load Balancer's (ALB) health checks are consistently failing for the EC2 instances in a target group, the ALB will mark those instances as unhealthy and stop routing new requests to them. When all instances in a target group are unhealthy, or if there are no healthy instances available to handle a request, the ALB will respond to the client with an HTTP 503 Service Unavailable error. A 502 Bad Gateway error, in contrast, indicates an issue with the communication *between* the ALB and a *reachable* target, specifically concerning an invalid or unexpected response from the backend, not that the target is entirely unavailable or unhealthy.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.