SOA-C02 Networking and Content Delivery Practice Question
Network Topology
Refer to the exhibit. A SysOps administrator runs the describe-target-health command and sees that an EC2 instance in the target group is unhealthy with a timeout error. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The instance's security group does not allow traffic from the ALB on the health check port
The health check is timing out, which indicates that the instance is not responding to health check requests on port 80. The security group must allow inbound traffic from the ALB on the health check port. Option A is wrong because the target group is configured with port 80, which matches. Option C is wrong because the route table is less likely to cause a timeout; it would cause unreachability. Option D is wrong because the instance is in a public subnet? Not necessarily; but the health check timeout is most often a security group issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The target group is configured with an incorrect port
Why it's wrong here
The target group's configured traffic port is 80 and the health check port is set to the same port, so there is no mismatch that would prevent health checks. Even if it were incorrect, a port mismatch would produce a connection refused, not a timeout, because the network path would be open. Since the symptoms point to packets being dropped, the port configuration is not the cause.
- ✓
The instance's security group does not allow traffic from the ALB on the health check port
Why this is correct
The ALB health check requests are sent from the ALB nodes' private IP addresses to the target's health check port. If the instance's security group lacks an inbound rule that permits TCP on port 80 from the ALB's security group (or the VPC CIDR), the packets are silently dropped. This causes the health check to time out and the target to be marked unhealthy, which matches the observed symptom.
- ✗
The instance is in a private subnet without a NAT gateway
Why it's wrong here
A private subnet without a NAT gateway only means the instance cannot initiate outbound internet connections, but it can still receive inbound traffic from within the VPC. Since an ALB health check originates from the ALB's own interfaces in the same VPC, the target does not need any NAT or internet gateway to respond. The instance's lack of a NAT gateway is therefore irrelevant to the health check timeout.
- ✗
The instance does not have a route to the internet
Why it's wrong here
The instance does not need a route to the internet to receive ALB health checks because the health check traffic never leaves the VPC. Whether the load balancer is internet-facing or internal, the last hop is always the private network connection between the ALB and the target. A missing internet route would only matter if the ALB were trying to reach the instance via a public IP, which is not how ALB health checks work.
Visual reference
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A SysOps administrator notices that an EC2 instance is not receiving traffic from an Application Load Balancer (ALB). The ALB is healthy and the target group shows the instance as healthy. The exhibit shows the network interface attached to the instance. What is the likely cause of the issue?
hard- A.The source/destination check is enabled on the network interface
- B.The network interface is in a private subnet
- ✓ C.The instance's security group does not allow inbound traffic from the ALB
- D.The network ACL of the subnet denies inbound traffic
Why C: The instance's security group must allow inbound traffic from the ALB. The exhibit shows the network interface attached to the instance, and the security group (sg-12345678) is likely the default security group, which typically does not allow HTTP/HTTPS traffic. Option C is correct because the security group acts as a virtual firewall for the instance. Options A, B, and D are incorrect: A) source/destination check is irrelevant for ALB traffic destined to the instance; B) the subnet type does not directly prevent ALB traffic as long as routing is correct; D) network ACLs are stateless and if inbound traffic is denied, outbound return traffic would also be affected, but the instance is not receiving traffic at all, indicating a security group issue.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.