Courseiva

SOA-C02 Networking and Content Delivery Practice Question

Network Topology
$ aws elbv2 describe-target-healthtarget-group-arn arn:aws:elasticloadbalancing:us-east-1:123456789012:targetgroup/my-tg/1234567890123456Refer to the exhibit."TargetHealthDescriptions": ["Target": {"Id": "i-0a1b2c3d4e5f6g7h8","Port": 80},"HealthCheckPort": "80","TargetHealth": {"State": "unhealthy","Reason": "Target.Timeout","Description": "Request timed out"

Refer to the exhibit. A SysOps administrator runs the describe-target-health command and sees that an EC2 instance in the target group is unhealthy with a timeout error. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The instance's security group does not allow traffic from the ALB on the health check port

The health check is timing out, which indicates that the instance is not responding to health check requests on port 80. The security group must allow inbound traffic from the ALB on the health check port. Option A is wrong because the target group is configured with port 80, which matches. Option C is wrong because the route table is less likely to cause a timeout; it would cause unreachability. Option D is wrong because the instance is in a public subnet? Not necessarily; but the health check timeout is most often a security group issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The target group is configured with an incorrect port

    Why it's wrong here

    The target group's configured traffic port is 80 and the health check port is set to the same port, so there is no mismatch that would prevent health checks. Even if it were incorrect, a port mismatch would produce a connection refused, not a timeout, because the network path would be open. Since the symptoms point to packets being dropped, the port configuration is not the cause.

  • ✓

    The instance's security group does not allow traffic from the ALB on the health check port

    Why this is correct

    The ALB health check requests are sent from the ALB nodes' private IP addresses to the target's health check port. If the instance's security group lacks an inbound rule that permits TCP on port 80 from the ALB's security group (or the VPC CIDR), the packets are silently dropped. This causes the health check to time out and the target to be marked unhealthy, which matches the observed symptom.

  • ✗

    The instance is in a private subnet without a NAT gateway

    Why it's wrong here

    A private subnet without a NAT gateway only means the instance cannot initiate outbound internet connections, but it can still receive inbound traffic from within the VPC. Since an ALB health check originates from the ALB's own interfaces in the same VPC, the target does not need any NAT or internet gateway to respond. The instance's lack of a NAT gateway is therefore irrelevant to the health check timeout.

  • ✗

    The instance does not have a route to the internet

    Why it's wrong here

    The instance does not need a route to the internet to receive ALB health checks because the health check traffic never leaves the VPC. Whether the load balancer is internet-facing or internal, the last hop is always the private network connection between the ALB and the target. A missing internet route would only matter if the ALB were trying to reach the instance via a public IP, which is not how ALB health checks work.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SysOps administrator notices that an EC2 instance is not receiving traffic from an Application Load Balancer (ALB). The ALB is healthy and the target group shows the instance as healthy. The exhibit shows the network interface attached to the instance. What is the likely cause of the issue?

hard
  • A.The source/destination check is enabled on the network interface
  • B.The network interface is in a private subnet
  • ✓ C.The instance's security group does not allow inbound traffic from the ALB
  • D.The network ACL of the subnet denies inbound traffic

Why C: The instance's security group must allow inbound traffic from the ALB. The exhibit shows the network interface attached to the instance, and the security group (sg-12345678) is likely the default security group, which typically does not allow HTTP/HTTPS traffic. Option C is correct because the security group acts as a virtual firewall for the instance. Options A, B, and D are incorrect: A) source/destination check is irrelevant for ALB traffic destined to the instance; B) the subnet type does not directly prevent ALB traffic as long as routing is correct; D) network ACLs are stateless and if inbound traffic is denied, outbound return traffic would also be affected, but the instance is not receiving traffic at all, indicating a security group issue.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.