SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator is troubleshooting an application that runs on EC2 instances behind an ALB. Users report intermittent 503 errors. The administrator checks the ALB access logs and finds entries with 'elb_status_code' 503 and 'target_status_code' '-'. What is the most likely cause?
⚠ Common exam trap
Many candidates confuse a 503 error with target-side issues (like high CPU or application errors), but the dash in the target_status_code is the key indicator that the ALB itself is rejecting the request due to no healthy targets, not that the request reached a target and failed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The target instances are unhealthy, causing the ALB to return 503.
The ALB access log entry with `elb_status_code` 503 and `target_status_code` '-' indicates that the load balancer itself generated the 503 error because it could not establish a connection to any healthy target. The dash for the target status code means the request never reached a target instance, which occurs when all targets in the target group are marked unhealthy by the health checks. This is the most common cause of intermittent 503 errors with an ALB.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The target instances are unhealthy, causing the ALB to return 503.
Why this is correct
When every instance in a target group fails consecutive health checks, the ALB marks them unhealthy and has no target to forward client traffic to. Instead of proxying a 5xx error from an overloaded backend, the load balancer itself responds with 503 Service Unavailable because the service is deemed unreachable. The health check interval and threshold settings determine how quickly an unhealthy target is removed from rotation, but the client sees 503 until at least one target passes.
- ✗
The SSL certificate on the ALB has expired.
Why it's wrong here
An expired SSL certificate on the ALB's HTTPS listener prevents the TLS handshake from completing when a client connects to the load balancer. The client would encounter a certificate validation error, and the ALB would close the connection or return a 502 Bad Gateway during renegotiation, not a 503 Service Unavailable. Furthermore, a 503 is generated at the HTTP application layer after a request is accepted, whereas TLS failure occurs before any HTTP request reaches the load balancer. Thus, an expired certificate cannot produce the observed 503.
- ✗
The target instances have high CPU utilization.
Why it's wrong here
High CPU utilization on the target instances may slow application responses and cause increased latency, but it does not inherently make an instance unhealthy for the ALB unless the health check endpoint becomes unresponsive or returns an error. Even a severely overloaded instance can continue to pass TCP or HTTP health checks, allowing the ALB to route traffic to it and return status codes like 200 or 500 from the application. The ALB only returns its own 503 when zero healthy targets exist in the target group, not simply because backend resources are under stress. In fact, sustained high CPU could eventually lead to health check failures, but that indirect effect is not what the question describes.
- ✗
The security group on the ALB is blocking traffic.
Why it's wrong here
A security group attached to the ALB controls inbound traffic from clients to the load balancer's listeners. If that security group blocks clients, the requests never reach the ALB infrastructure, so clients would experience timeouts or connection failures rather than receiving an HTTP 503 response. Moreover, because no request reaches the load balancer, no corresponding entry is written to the ALB access logs, whereas a 503 response always indicates the ALB accepted and processed the request. The symptom described points to a lack of healthy targets downstream, not an upstream access control blockage.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.