Courseiva

ALB 503 Errors: Diagnose with Access Logs

An application running on EC2 instances behind an Application Load Balancer (ALB) occasionally returns HTTP 503 errors. The instances are in an Auto Scaling group. Which action should be taken to resolve this issue?

Quick Answer

The correct action is to review the ALB access logs to identify the target response codes. HTTP 503 errors from an Application Load Balancer mean the targets—your EC2 instances—are failing to respond successfully, often due to overload, application crashes, or health check failures. Access logs capture the exact response code returned by each target (e.g., a 503 from the instance itself versus a connection timeout), allowing you to distinguish between a saturated Auto Scaling group and a misconfigured application. On the AWS Certified Developer Associate DVA-C02 exam, this question tests your ability to diagnose load balancer issues systematically rather than jumping to scaling or health check tweaks. A common trap is assuming you should immediately increase instance count or modify health check thresholds, but the logs must be your first step to confirm the root cause. Memory tip: “503 from ALB? Log the target’s reply.”

⚠ Common exam trap

The trap here is that candidates often jump to scaling or instance size changes (Option D) without first using access logs to diagnose whether the 503s originate from the ALB or the targets, leading to ineffective fixes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the ALB access logs to identify the target response codes.

HTTP 503 errors from an ALB indicate that the targets (EC2 instances) are not responding successfully. Reviewing ALB access logs reveals the specific target response codes (e.g., 503 from the target itself or connection timeouts), which helps pinpoint whether the issue is due to overloaded instances, application errors, or health check failures. This diagnostic step is essential before making any configuration changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable cross-zone load balancing on the ALB.

    Why it's wrong here

    Cross-zone load balancing only redistributes traffic across Availability Zones; it cannot prevent 503s caused by targets failing health checks or capacity exhaustion. It is genuinely useful when nodes are unevenly distributed across zones, but here the Auto Scaling group's unhealthy or overloaded instances remain the actual source of errors.

  • ✓

    Review the ALB access logs to identify the target response codes.

    Why this is correct

    ALB access logs record target response codes and timing, revealing whether 503s originate from unhealthy targets, connection limits or application errors. Reviewing them identifies the actual failure source before remediation, satisfying the need to diagnose rather than guess at scaling or health-check changes.

  • ✗

    Increase the ALB idle timeout setting.

    Why it's wrong here

    The idle timeout governs how long an idle connection persists; 503s indicate no healthy target is available, not premature connection closure. Raising it is correct for long-running requests being cut off, but here it merely delays failure while unhealthy or overloaded instances remain unreplaced.

  • ✗

    Increase the size of the EC2 instances.

    Why it's wrong here

    Larger instances address sustained resource exhaustion, but 503s from an ALB mean no healthy target passed health checks, which instance size does not fix. Resizing is correct for consistently CPU- or memory-bound workloads, not for intermittent capacity shortfalls that scaling policy should handle.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A web application running on EC2 instances behind an Application Load Balancer (ALB) is experiencing intermittent 503 errors. The ALB target group health checks are succeeding. Which step should the developer take FIRST to diagnose the issue?

medium
  • A.Increase the number of EC2 instances in the target group.
  • ✓ B.Examine the ALB access logs for 503 responses.
  • C.Check the Route 53 record for the ALB.
  • D.Verify that the EC2 instances are in a running state.

Why B: The correct first step is to examine the ALB access logs for 503 responses. Since health checks are succeeding, the EC2 instances are considered healthy by the target group, but the ALB itself may be returning 503 errors due to issues like request rate limits, connection limits, or backend response timeouts. Access logs provide detailed HTTP response codes and timestamps, allowing you to identify the pattern and cause of the 503 errors without making assumptions about instance count or state.

Variation 2. An application uses an Application Load Balancer (ALB) with a target group of EC2 instances. Users report intermittent HTTP 503 errors. The ALB access logs show that the error occurs when the request rate exceeds 10,000 requests per second. What is the most likely cause?

hard
  • A.The EC2 instances are failing health checks.
  • B.The SSL certificate is expiring.
  • ✓ C.The ALB is exceeding its connection limit.
  • D.The target group's connection draining is too short.

Why C: The correct answer is C: the ALB is exceeding its connection limit, because an Application Load Balancer has a documented maximum of 10,000 new connections per second (and 100,000 concurrent connections) per load balancer node, and the access logs show the 503s begin exactly when the request rate crosses 10,000 requests per second, matching that limit. When this per-node connection limit is hit, the ALB cannot accept new connections and returns HTTP 503 errors to clients. Option A is unlikely because failing health checks would remove targets and typically produce 502/504 errors rather than a rate-dependent 503 pattern. Option B is wrong because an expiring SSL certificate causes TLS handshake failures or browser warnings, not intermittent 503s tied to request rate. Option D is wrong because connection draining only affects deregistering targets during scale-in or deployment, not steady-state 503s at high request rates.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.