Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team requires that all traffic to the ALB must be encrypted (HTTPS) and that the ALB must only accept traffic from CloudFront. The DevOps engineer has configured CloudFront with an origin pointing to the ALB, and the ALB has a listener on port 443 with a valid SSL certificate. The engineer also added a security group rule to the ALB that allows HTTPS traffic only from CloudFront's IP ranges. However, users are reporting intermittent 503 errors. The engineer checks CloudFront logs and sees that some requests are failing with 'Origin Connect Error'. What is the most likely cause?

⚠ Common exam trap

DOP-C02 often tests the misconception that a static snapshot of CloudFront IP ranges is sufficient for origin lockdown, when in fact AWS updates these ranges continuously and only the managed prefix list stays current.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The security group rule is using an outdated list of CloudFront IP ranges, and CloudFront has added new IP ranges that are being blocked.

CloudFront publishes its origin-facing IP ranges in the managed prefix list (com.amazonaws.global.cloudfront.origin-facing) and updates it periodically. If the ALB security group was configured with a static, manually copied list of CloudFront IPs, newly added edge locations will connect from IPs not in the allow list, and the ALB will drop the TCP handshake — producing 'Origin Connect Error' in CloudFront logs and 503s to users. The correct fix is to reference the AWS-managed prefix list rather than hardcoded CIDRs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ALB has a Web Application Firewall (WAF) that is blocking requests from CloudFront.

    Why it's wrong here

    A WAF blocking requests returns HTTP 403 responses at the ALB, not CloudFront 'Origin Connect Error', which indicates a TCP or TLS connection failure before any HTTP response. It is tempting because WAF rules do reject traffic, and would be correct if logs showed 403s rather than connection errors.

  • ✓

    The security group rule is using an outdated list of CloudFront IP ranges, and CloudFront has added new IP ranges that are being blocked.

    Why this is correct

    CloudFront's origin-facing IP ranges change periodically, so a static security group rule based on a previously captured list will block newer edge locations. Those blocked connections surface as 'Origin Connect Error' and intermittent 503s, matching the stem's requirement that the ALB accept traffic only from CloudFront.

  • ✗

    The SSL certificate on the ALB is not trusted by CloudFront, causing handshake failures.

    Why it's wrong here

    CloudFront validates origin certificates against public CAs, and a valid ALB certificate chains correctly, so handshakes succeed. It is tempting because certificate mismatches do cause origin connect errors, but that would affect all requests consistently, not intermittently as the stem describes.

  • ✗

    The ALB idle timeout is set too low, causing CloudFront to close connections prematurely.

    Why it's wrong here

    Idle timeout mismatches cause 504 gateway timeouts after connections establish, not 'Origin Connect Error', which occurs before a connection completes. It is tempting because timeout tuning is a common CloudFront-ALB issue, and would be correct if the symptom were slow responses rather than failed connects.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.