Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company has deployed a global web application using AWS CloudFront with an Application Load Balancer (ALB) as the origin. The ALB is in a single AWS region. Users in different geographic regions report high latency, and some users are unable to access the application. The SysOps administrator verifies that the CloudFront distribution is configured correctly and that the ALB is healthy. The administrator also confirms that the ALB's security group allows traffic from the CloudFront IP ranges. What is the most likely cause of the issue?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ALB is overwhelmed by the number of concurrent connections from CloudFront

The ALB in a single region can become overwhelmed by the high volume of concurrent connections from CloudFront's global edge locations, even though the security group allows traffic from CloudFront IP ranges. This can cause high latency and access failures for users in different regions. Option B is incorrect because CloudFront caching typically reduces the load on the origin by serving cached content at edge locations. Option C is incorrect because CloudFront distributions support HTTP and HTTPS protocols, not TCP/UDP, and the protocol used does not explain the regional latency issue. Option D is incorrect because the SSL/TLS certificate on the ALB must be trusted by CloudFront for HTTPS connections, but this would not cause intermittent access issues across regions if the distribution is configured correctly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The ALB is overwhelmed by the number of concurrent connections from CloudFront

    Why this is correct

    CloudFront's global network of edge locations each establishes a pool of persistent (keep-alive) TCP connections to the ALB origin. In a busy distribution, the aggregate of these connections across all edges can exceed the ALB's concurrent connection capacity (MaxConnectionIdleTime, target group limits, or instance/scale limits), causing SYN queue saturation, latency, and timeouts. The fix is to scale the ALB and adjust keep-alive timeouts, not to assume caching or TLS errors.

  • ✗

    CloudFront is not caching content, causing all requests to go to the origin

    Why it's wrong here

    If CloudFront were misconfigured to not cache, every request would reach the ALB, increasing request throughput and origin load. However, that would manifest as high request counts, CPU utilization, and possibly 5xx errors from the origin, not specifically as an overwhelming number of concurrent *connections* caused by CloudFront's edge aggregation. Caching behavior is controlled per-cache behavior, and a lack of caching is usually intentional or a configuration error, but it does not explain the connection saturation scenario described.

  • ✗

    The CloudFront distribution is using TCP instead of HTTP, causing higher latency

    Why it's wrong here

    CloudFront works over HTTP/HTTPS (application layer) and uses TCP only as the underlying transport protocol; you cannot choose 'TCP instead of HTTP' as a distribution setting. While TCP-level protocols like WebSockets exist, CloudFront's standard behavior is HTTP/HTTPS, and latency issues are more typically tied to TLS handshake overhead, cache hit ratio, or origin response time—not a naive TCP/HTTP choice. This option fundamentally misunderstands the OSI model.

  • ✗

    The SSL/TLS certificate on the ALB is not trusted by CloudFront

    Why it's wrong here

    If the ALB's SSL/TLS certificate were not trusted by CloudFront, CloudFront would reject the origin connection and return a 502 (Bad Gateway) error because it validates that the certificate is publicly trusted and matches the origin domain name. The described problem of high latency or overwhelmed connections would not result from a certificate trust failure. Also, ALB certificates issued by ACM are automatically trusted, and a mismatch causes immediate handshake failure, not performance degradation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.