DOP-C02 Monitoring and Logging Practice Question
A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses a custom health check endpoint '/health'. The DevOps team notices that the ALB is marking some instances as unhealthy even though the application is running fine. The team checks the security groups and network ACLs and confirms they allow traffic. What should the team check next?
⚠ Common exam trap
DOP-C02 often tests whether candidates jump to tuning health check timing parameters when the actual root cause is a simple configuration mismatch like the wrong path or success code, so candidates pick interval/timeout adjustments instead of verifying the path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confirm that the health check path is correctly configured to '/health' on the target group.
If security groups and NACLs are confirmed correct, the next most likely cause is a misconfigured health check path on the target group — for example, the path is set to '/' or '/healthz' instead of '/health', so the ALB receives a 404 and marks the instance unhealthy. Verifying the exact path string in the target group's health check settings is the correct next diagnostic step. The other options either do not apply or are premature tuning steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure the health check path is case-insensitive.
Why it's wrong here
HTTP paths are case-sensitive, and AWS Elastic Load Balancing health checks strictly match the configured path character-for-character. The target group health check does not offer a case-insensitive toggle, so attempting to make it case-insensitive would require changing the application to treat paths case-insensitively, which is out of scope for the load balancer configuration. If the path is correct, case sensitivity is not the cause of intermittent failures.
- ✗
Increase the health check interval and timeout values.
Why it's wrong here
Increasing the health check interval or timeout only changes how frequently probes are sent and how long the load balancer waits for a response, which can mask transient failures by reducing the chance of catching them, but it does not address why the application occasionally returns a non-200 status. This approach can also delay the detection of real outages, making it a harmful mitigation rather than a fix. Intermittent failures typically stem from the application's response behavior, not from the probe frequency.
- ✓
Confirm that the health check path is correctly configured to '/health' on the target group.
Why this is correct
The target group health check path must exactly match the application endpoint that is designed to return an HTTP 200 OK when healthy. If the path is incorrectly set to something like '/' instead of '/health', the application may return a different status code, such as a redirect or a default page, which can cause intermittent health check failures as the application's behavior changes under load. Confirming the path resolves the root cause because the health check will then probe a purpose-built endpoint that consistently returns 200.
- ✗
Verify that the health check port matches the application port.
Why it's wrong here
A mismatch between the health check port and the application port would cause every health check request to fail consistently, typically with a connection refused or timeout error, rather than intermittent failures. Since the symptoms are intermittent, a port mismatch is unlikely; the health check is reaching the instance sometimes, and the path or response code is the variable factor. Ports are a binary, deterministic configuration, so they cannot produce an intermittent success/failure pattern.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.