Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A SysOps administrator is troubleshooting DNS resolution issues for a custom domain used by an Application Load Balancer. Which TWO steps should the administrator take to diagnose the issue? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse DNS resolution issues with network connectivity or load balancer health, leading them to select security group or target group checks instead of focusing on the DNS configuration itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the Route 53 alias record points to the ALB's DNS name

A Route 53 alias record must point to the ALB's DNS name (e.g., my-alb-1234567890.us-east-1.elb.amazonaws.com) to properly route traffic to the load balancer. If the alias record is misconfigured or points to an incorrect resource, DNS resolution will fail or resolve to an unintended IP, causing the custom domain not to work.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensure the VPC's CIDR block does not overlap with the ALB's IP range

    Why it's wrong here

    VPC CIDR blocks define the private IP address space for instances and subnets, but DNS resolution is handled at the application layer by Route 53 and the VPC resolver on UDP/TCP port 53. An overlap between your VPC CIDR and the ALB's assigned subnet IPs would only cause routing or peering conflicts, not name-to-IP translation failures. Therefore, checking CIDR overlap cannot diagnose a DNS resolution issue.

  • ✓

    Verify that the Route 53 alias record points to the ALB's DNS name

    Why this is correct

    The Route 53 alias record must reference the ALB's canonical DNS name (e.g., myapp-1234567890.us-east-1.elb.amazonaws.com) rather than a static IP address, because ALB IPs are ephemeral and can change during scale operations. If the alias target is misspelled, points to a deleted resource, or uses a non-alias type with an IP, Route 53 returns no valid answer or a stale address. Verifying this alias configuration directly corrects the misconfiguration that causes resolution failures.

  • ✓

    Run 'dig' or 'nslookup' from a client to verify the domain resolves to the correct IP

    Why this is correct

    Running dig or nslookup from the affected client queries the configured DNS resolver and returns the A/AAAA records for the domain, showing whether Route 53 is returning the expected ALB IP. This test distinguishes between DNS misconfiguration, such as missing records or wrong name servers, and other issues like network connectivity or application errors. You should also inspect the TTL to account for cached negative responses before making changes.

  • ✗

    Verify that the ALB's security group allows inbound traffic on port 443

    Why it's wrong here

    The ALB security group is a stateful network firewall that filters traffic at layer 3/4 after DNS resolution has already occurred. If inbound 443 is blocked, clients would see connection timeouts or TLS handshake failures, but the domain would still resolve to the ALB's IP address. Since the problem is explicitly DNS resolution, inspecting the security group cannot reveal why the name lookup fails.

  • ✗

    Check the health status of the ALB's target group

    Why it's wrong here

    An ALB target group's health status tracks the readiness of backend instances to receive requests; unhealthy targets cause the ALB to return HTTP 503 or drain connections. However, the DNS name of the ALB itself remains resolvable and the Route 53 record still maps to the load balancer regardless of backend health. Thus, target health checks address availability issues after DNS succeeds, not resolution failures.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.