SAP-C02 Continuous Improvement for Existing Solutions Practice Question
A company runs a containerized application on Amazon ECS with Fargate launch type. The application is deployed across multiple Availability Zones. Recently, deployments have been failing because new tasks cannot register with the Application Load Balancer (ALB) target group. The health checks are failing. What is the MOST likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The security group for the tasks does not allow inbound traffic from the ALB on the health check port.
If the security group for the tasks does not allow inbound traffic from the ALB on the health check port, health checks fail and tasks cannot register. Option B is incorrect because a desired count of zero would prevent new tasks from running, but the scenario describes deployments failing due to health check failures on new tasks. Option C is incorrect: an invalid container image would cause the task to fail to start, not cause health check failures after the task is running. Option D is incorrect because Fargate manages capacity; insufficient capacity would cause a different error (e.g., unable to provision tasks), not health check failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The security group for the tasks does not allow inbound traffic from the ALB on the health check port.
Why this is correct
Fargate tasks and the ALB communicate over the network, so the task security group must permit inbound traffic from the ALB security group on the health check port. Without that rule, health checks fail and tasks never register.
- ✗
The ECS service is configured with a desired count of zero.
Why it's wrong here
A desired count of zero stops tasks entirely, so none would exist to fail health checks or register; the service would simply report no running tasks. Failing registration with failing health checks points to security group or port misconfiguration between tasks and the ALB. Zero desired count suits intentionally scaled-down services, not active multi-AZ deployments.
- ✗
The task definition specifies an invalid container image.
Why it's wrong here
An invalid container image causes the task to fail at image pull, so the container never starts and cannot serve ALB health checks; the task stops rather than registering unhealthy. It is tempting because image errors do break deployments, but they manifest as task launch failures, not ALB health-check failures on running tasks.
- ✗
The ECS cluster has insufficient capacity.
Why it's wrong here
Fargate provisions capacity on demand, so cluster capacity is never a constraint; tasks launch and then fail health checks for networking or port reasons. It is tempting because insufficient capacity is a classic EC2-launch-type failure, but that mechanism does not apply to Fargate, which has no cluster capacity pool to exhaust.
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.