SOA-C02 Networking and Content Delivery Practice Question
A company is using Amazon CloudFront with an Application Load Balancer (ALB) as the origin. The ALB is configured with HTTPS listeners. Users report that some requests are failing with a 502 error. Which THREE steps should the SysOps administrator take to troubleshoot the issue? (Choose three.)
⚠ Common exam trap
Candidates often think a custom error response (Option C) resolves the root cause, when in fact it only masks the symptom, or they may confuse the X-Forwarded-For header (Option E) with routing logic, which is unrelated to 502 errors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check that the ALB's security group allows inbound traffic from the CloudFront IP ranges.
The ALB's security group must allow inbound traffic from CloudFront's IP ranges, because CloudFront forwards requests to the ALB using its own IP addresses. Without this rule, the ALB will reject the connection, resulting in a 502 error (Bad Gateway) as CloudFront cannot reach the origin. You can obtain the current CloudFront IP ranges from the AWS IP Address Ranges list and update the security group accordingly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check that the ALB's security group allows inbound traffic from the CloudFront IP ranges.
Why this is correct
CloudFront reaches your ALB from AWS's CloudFront edge and regional IP ranges, which are published in ip-ranges.json and are not the same as the source IPs of your viewers. If the ALB security group does not contain an inbound HTTPS/HTTP allow rule for those CIDR blocks (or an AWS-managed prefix list), the SYN packets from CloudFront are dropped, the origin never responds, and CloudFront returns a 502 Bad Gateway to users. This is the most direct cause of the failure and must be validated first.
- ✓
Verify that the ALB's health check is configured correctly and that the targets are healthy.
Why this is correct
A correctly configured ALB health check marks each registered target as healthy or unhealthy based on the response to periodic HTTP/TCP probes sent from the VPC. If the health check path returns a non-2xx/3xx status, or if the interval and thresholds are too aggressive, the ALB can consider all targets unhealthy and refuses to forward incoming requests (often returning a 503 to CloudFront, which surfaces as a 502 after the origin response is received). Even when your application is fine, a broken health check or a target group that contains no healthy instances will reproduce the 502, so check the target group's Health Checks tab and the CloudWatch target-health metrics.
- ✗
Configure the CloudFront distribution to use a custom error response for 502 errors.
Why it's wrong here
Configuring a CloudFront custom error response for 502 errors only changes what the viewer receives, such as returning a generic 200 with a static page when CloudFront sees a 502 from the origin. It does nothing to alter how or whether CloudFront successfully fetches from the ALB, so the underlying issue (security group, health check, or certificate) remains and your custom error page is served whenever the origin fails. This is a stopgap, not a fix, and can even mask persistent availability problems.
- ✓
Ensure that the SSL certificate on the ALB is valid and trusted by CloudFront.
Why this is correct
When CloudFront is configured with an origin that uses HTTPS, it performs a TLS handshake with the ALB and validates that the ALB's certificate covers the domain name used as the origin Domain Name in the CloudFront origin settings. If that certificate is expired, self-signed, doesn't include the origin domain, or is not signed by a trusted CA, CloudFront aborts the handshake and emits a 502 Bad Gateway instead of forwarding the request. For an ALB, the certificate must be stored in or trusted by ACM and be associated with the HTTPS listener on the exact port CloudFront uses.
- ✗
Verify that the ALB is configured to use the X-Forwarded-For header to route requests.
Why it's wrong here
The X-Forwarded-For header is inserted by the ALB to preserve the originating client's IP address in a comma-separated list, and it is used by your application for logging, rate-limiting, or geo-personalization. It is not a routing hint: ALB listener rules route requests based on the incoming listener host/path conditions, and the target group determines which instances receive traffic. Enabling or disabling X-Forwarded-For has no effect on CloudFront's ability to reach the ALB, so it cannot be used to resolve a 502 error.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.