Courseiva

ALB Health Check Failure Due to Network ACL or Security Group

A SysOps administrator notices that traffic to an Application Load Balancer (ALB) is being rejected. The ALB has a security group that allows inbound HTTP (80) and HTTPS (443) from 0.0.0.0/0. The target group health checks are failing. What could be the issue?

⚠ Common exam trap

The trap is assuming that if the ALB's security group allows inbound traffic, the targets will automatically accept it; candidates forget that the targets have their own security groups that must also allow traffic from the ALB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The target instances' security group does not allow inbound traffic from the ALB security group.

For an ALB to route traffic to targets, the targets' security group must allow inbound traffic from the ALB's security group on the target port. Even if the ALB's security group allows inbound HTTP/HTTPS from the internet, the targets will reject traffic if their security group does not permit it. This is a common misconfiguration that causes health checks to fail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The target instances' security group does not allow inbound traffic from the ALB security group.

    Why this is correct

    For an ALB health check to succeed, the target instance's security group must explicitly allow inbound traffic on the health check port from the ALB's security group as the source. This rule permits the ALB to establish the health check connection and receive the response. Without it, the target rejects the health check packets, causing the instance to be marked unhealthy even though the application itself may be running.

  • ✗

    The ALB security group does not allow outbound traffic to the targets.

    Why it's wrong here

    The ALB's security group does not need a special outbound rule to send health checks to targets because the default outbound security group rule allows all traffic, and security groups are stateful so responses automatically return. Moreover, even if an explicit outbound rule were required, the primary cause of health check failure in this architecture is the target security group's missing inbound allowance from the ALB security group. Thus, this option incorrectly attributes the problem to the wrong security group.

  • ✗

    The ALB’s security group is blocking health check traffic from the targets.

    Why it's wrong here

    Health checks are initiated by the ALB toward the target instances, not by the targets toward the ALB. The ALB's security group governs inbound traffic from clients and outbound traffic from the ALB itself; it does not need a specific rule to accept inbound health check responses because security groups are stateful. Therefore, the ALB's security group blocking inbound traffic from the targets is not the reason health checks would fail; the failure would instead occur on the target's inbound rules.

  • ✗

    The target instances' security group does not allow inbound HTTP/HTTPS from the internet.

    Why it's wrong here

    Target instances behind an Application Load Balancer do not receive direct traffic from the internet; the ALB terminates the client connection and forwards requests to the targets using its own security group as the source. Therefore, the target security group need not allow inbound HTTP/HTTPS from the public internet (0.0.0.0/0). The missing rule is the inbound allowance from the ALB security group, not from the internet.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.