DOP-C02 Incident and Event Response Practice Question
A company uses AWS Lambda functions behind an Amazon API Gateway REST API. During an incident, the API returns 502 Bad Gateway errors. The Lambda function logs show no errors. What is the most likely cause?
⚠ Common exam trap
AWS often tests the distinction between different HTTP status codes (502 vs 504 vs 429) and the specific conditions under which each is returned, leading candidates to incorrectly attribute 502 errors to Lambda timeouts or API Gateway throttling instead of payload size limits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Lambda function is returning a response that exceeds the API Gateway payload size limit
When an API Gateway REST API returns 502 Bad Gateway errors but the Lambda function logs show no errors, the most likely cause is that the Lambda function is returning a response that exceeds the API Gateway payload size limit. API Gateway has a maximum payload size of 10 MB for REST APIs, and if the Lambda function returns a response larger than this, API Gateway will reject it and return a 502 error without the Lambda function itself throwing an exception or logging an error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Lambda function is throwing an unhandled exception
Why it's wrong here
An unhandled exception in the Lambda function would typically cause API Gateway to return a 502 Bad Gateway, but it would also generate an error log entry in CloudWatch Logs. Since the logs show no errors, this can be eliminated as a cause. A 502 from an unhandled exception is also accompanied by a response body containing 'Internal server error' or similar, which is not observed here.
- ✓
The Lambda function is returning a response that exceeds the API Gateway payload size limit
Why this is correct
API Gateway imposes a hard 10 MB payload size limit for REST API responses (and 4 MB for HTTP APIs). When a Lambda function returns a response exceeding this threshold, API Gateway cannot process it and returns a 502 Bad Gateway error to the client, with no error logged from the Lambda side because the function already completed successfully. This is the classic 'silent' 502 cause and matches the symptoms in the question.
- ✗
The API Gateway has reached its maximum concurrency limit
Why it's wrong here
API Gateway concurrency limits, such as throughput throttling or burst limits, are enforced as rate limits and produce HTTP 429 Too Many Requests responses when exceeded. Neither account-level nor usage-plan concurrency constraints cause a 502 Bad Gateway, which indicates a proxy or integration-level failure. Additionally, Lambda function concurrency limits would yield 429 or 503 errors, not 502, so this is not the correct cause.
- ✗
The Lambda function is timing out and API Gateway is not handling the timeout correctly
Why it's wrong here
When a Lambda function times out, API Gateway returns a 504 Gateway Timeout because the backend did not respond within the configured timeout, typically 29 seconds for synchronous invocation. This is fundamentally different from a 502, which indicates a malformed or oversized response after the backend has already finished processing. API Gateway does not 'mis-handle' a timeout into a 502; the status code is deterministic, so this option is incorrect.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.