DOP-C02 Incident and Event Response Practice Question
A DevOps team is debugging a production incident where an Application Load Balancer (ALB) is returning 503 errors for some requests. The target group instances are healthy. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The deregistration delay setting on the target group is too long
The deregistration delay setting controls how long the ALB continues to send requests to an instance that is being deregistered. If this delay is too long, the ALB may route traffic to an instance that has already stopped accepting connections, resulting in 503 errors even though the health checks pass. Option A is incorrect because a missing security group rule would prevent any traffic from reaching the ALB, causing connection timeouts rather than 503 errors. Option B is incorrect because the instance health checks are passing (as stated), so the health check path must be correct. Option D is incorrect because disabling cross-zone load balancing affects traffic distribution but does not cause 503 errors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The security group for the ALB does not allow inbound traffic on port 443
Why it's wrong here
If the ALB's security group blocks inbound traffic on port 443, clients cannot establish a TCP or TLS connection, so the ALB never receives the request and cannot return an HTTP 503. The client would observe connection timeouts or connection refused instead, depending on whether the security group drops or rejects packets. A 503 specifically means the ALB is reachable and is responding because it lacks a healthy target in the target group, so this option cannot produce the reported error.
- ✗
Health checks are misconfigured to use an incorrect path
Why it's wrong here
A health check configured with an incorrect path would cause the ALB to receive non-200 responses from targets, marking them unhealthy and eventually returning 503. However, in this incident the instances are reported as healthy, which indicates the health check is succeeding against the configured path. If the path were incorrect, the instances would be deregistered from rotation and would not show as healthy, so this option is inconsistent with the observed health status.
- ✓
The deregistration delay setting on the target group is too long
Why this is correct
An excessively long deregistration delay prolongs the draining period in which a target is excluded from new request routing but still waits for in-flight requests to complete. For example, if the delay is set to 3,600 seconds (the maximum) and a rolling deployment drains instances, replacement targets may not become healthy quickly enough, leaving zero targets in rotation. With no healthy targets, the ALB returns HTTP 503 to new requests even though the underlying instances might function correctly—the bottleneck is the delayed deregistration.
- ✗
Cross-zone load balancing is disabled
Why it's wrong here
Disabling cross-zone load balancing restricts the ALB to routing traffic only to targets within the same Availability Zone as the node that received the client's connection. This can cause uneven load distribution or reduced fault tolerance if an AZ has fewer capacity, but it does not globally produce HTTP 503 errors. Cross-zone balancing being off would not create a condition where all healthy targets are absent; it simply degrades performance or availability in a single AZ, making it an implausible root cause for a service-wide 503 incident.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.