SOA-C02 Networking and Content Delivery Practice Question
A SysOps administrator is troubleshooting DNS resolution issues for a custom domain used by an Application Load Balancer. Which TWO steps should the administrator take to diagnose the issue? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse DNS resolution issues with network connectivity or load balancer health, leading them to select security group or target group checks instead of focusing on the DNS configuration itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the Route 53 alias record points to the ALB's DNS name
A Route 53 alias record must point to the ALB's DNS name (e.g., my-alb-1234567890.us-east-1.elb.amazonaws.com) to properly route traffic to the load balancer. If the alias record is misconfigured or points to an incorrect resource, DNS resolution will fail or resolve to an unintended IP, causing the custom domain not to work.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure the VPC's CIDR block does not overlap with the ALB's IP range
Why it's wrong here
VPC CIDR blocks define the private IP address space for instances and subnets, but DNS resolution is handled at the application layer by Route 53 and the VPC resolver on UDP/TCP port 53. An overlap between your VPC CIDR and the ALB's assigned subnet IPs would only cause routing or peering conflicts, not name-to-IP translation failures. Therefore, checking CIDR overlap cannot diagnose a DNS resolution issue.
- ✓
Verify that the Route 53 alias record points to the ALB's DNS name
Why this is correct
The Route 53 alias record must reference the ALB's canonical DNS name (e.g., myapp-1234567890.us-east-1.elb.amazonaws.com) rather than a static IP address, because ALB IPs are ephemeral and can change during scale operations. If the alias target is misspelled, points to a deleted resource, or uses a non-alias type with an IP, Route 53 returns no valid answer or a stale address. Verifying this alias configuration directly corrects the misconfiguration that causes resolution failures.
- ✓
Run 'dig' or 'nslookup' from a client to verify the domain resolves to the correct IP
Why this is correct
Running dig or nslookup from the affected client queries the configured DNS resolver and returns the A/AAAA records for the domain, showing whether Route 53 is returning the expected ALB IP. This test distinguishes between DNS misconfiguration, such as missing records or wrong name servers, and other issues like network connectivity or application errors. You should also inspect the TTL to account for cached negative responses before making changes.
- ✗
Verify that the ALB's security group allows inbound traffic on port 443
Why it's wrong here
The ALB security group is a stateful network firewall that filters traffic at layer 3/4 after DNS resolution has already occurred. If inbound 443 is blocked, clients would see connection timeouts or TLS handshake failures, but the domain would still resolve to the ALB's IP address. Since the problem is explicitly DNS resolution, inspecting the security group cannot reveal why the name lookup fails.
- ✗
Check the health status of the ALB's target group
Why it's wrong here
An ALB target group's health status tracks the readiness of backend instances to receive requests; unhealthy targets cause the ALB to return HTTP 503 or drain connections. However, the DNS name of the ALB itself remains resolvable and the Route 53 record still maps to the load balancer regardless of backend health. Thus, target health checks address availability issues after DNS succeeds, not resolution failures.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.