Courseiva
Monitoring and Logging →mediumMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

A company is running a production web application on Auto Scaling EC2 instances behind an ALB. They have enabled detailed CloudWatch metrics on the EC2 instances and enabled CloudTrail. Recently, users reported intermittent 503 errors. The operations team reviews CloudWatch dashboards but sees no spike in CPU or memory. What is the MOST likely cause of the 503 errors?

⚠ Common exam trap

DOP-C02 often tests the distinction between ALB 503 (no healthy targets) and 502 (bad gateway from a target) — candidates chase resource metrics or security group misconfigurations when the real signal is target health check failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The target group has an insufficient number of healthy instances due to health check failures

ALB returns HTTP 503 when no healthy targets are available in the target group to serve the request. If health checks are failing intermittently — due to application-level issues, misconfigured health check paths, or slow responses — targets are marked unhealthy and removed from rotation, leaving insufficient capacity and producing 503s. Because CPU and memory show no spike, the cause is not resource saturation but target availability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Insufficient CloudTrail logging trail configuration

    Why it's wrong here

    CloudTrail is an audit service that records API calls made to the AWS control plane, such as EC2 RunInstances or ALB CreateListener; it has no visibility into application payloads or HTTP responses. A misconfigured or insufficient CloudTrail trail might delay or prevent audit log delivery for forensic analysis, but it does not alter ALB routing behavior, target health evaluation, or capacity management. Therefore, it is irrelevant to the generation of 503 responses and is purely a compliance/observability concern, not an operational cause.

  • ✓

    The target group has an insufficient number of healthy instances due to health check failures

    Why this is correct

    The ALB routes requests only to targets that have successfully passed their configured health checks. If health check failures occur—due to an incorrect health check path, a timeout threshold being too low, or an application dependency failing—the corresponding instances are marked unhealthy and removed from the rotation. When the number of healthy targets drops below the minimum needed (typically zero healthy targets in a target group), the ALB returns HTTP 503 Service Unavailable. This can happen without CPU or memory utilization rising, because health checks validate application-level readiness, not just resource utilization.

  • ✗

    Detailed monitoring is disabled for the EC2 instances

    Why it's wrong here

    Detailed monitoring only changes the frequency of CloudWatch metric collection from 5 minutes to 1 minute; it does not affect the data plane behavior of the Application Load Balancer or the EC2 instances' ability to accept traffic. Even with detailed monitoring enabled, the ALB would still return 503 if its target group contains zero healthy instances. Thus, while disabling detailed monitoring reduces observability and delays detection of bottlenecks, it is not a cause of 503 Service Unavailable errors.

  • ✗

    The security group for the ALB is misconfigured

    Why it's wrong here

    A misconfigured security group on the ALB would block inbound traffic from clients or outbound traffic to the targets, leading to connection timeouts, connection resets, or HTTP 504 Gateway Timeout errors when the target fails to respond. It would not produce a 503, because a 503 specifically indicates that the ALB itself has accepted the connection and successfully routed to no target with healthy status. Since a security group misconfiguration prevents traffic from reaching the ALB or targets at the network layer, it manifests as a connectivity failure rather than a targeted HTTP status code.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.