SOA-C02 Networking and Content Delivery Practice Question
Network Topology
Refer to the exhibit. The output shows the health status of two targets in a target group. One target is unhealthy with a 502 error. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The web server on the target instance is returning HTTP 502 status codes.
A 502 Bad Gateway error from the target indicates that the web server on the instance is returning an invalid response, often due to an application error or misconfiguration. Option A is incorrect because a security group blocking health check traffic would result in a connection timeout or refusal, not a 502. Option B is incorrect because the health check is initiated by the ALB to the target instance, so outbound traffic from the instance is not relevant. Option D is incorrect because a misconfigured health check path would typically result in a 404 or other error, but not necessarily a 502. The 502 error is directly caused by the target's web server returning an HTTP 502 status code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The target instance’s security group is blocking the health check traffic.
Why it's wrong here
If the target instance's security group blocks the ALB's health check traffic, the connection attempt from the ALB would either time out (if the packet is silently dropped) or receive a TCP RST (if a deny rule sends a reset). This would appear as a connection failure or 'health check failed with timeout' in the ALB's CloudWatch logs, not as an HTTP 502 response. Since a 502 is an actual HTTP status code sent by the target, a network-layer block cannot produce that code. Therefore, this option does not explain the observed 502 status.
- ✗
The target instance is not allowing outbound traffic to the ALB.
Why it's wrong here
Application Load Balancer health checks are inbound requests initiated from the ALB's node to the target instance's health check port. Once the TCP connection is established, the target sends its HTTP response over that same connection; it never needs to open a new outbound connection toward the ALB. Even if the target's outbound rules are restrictive, security groups are stateful, so the response traffic for an allowed inbound health check is automatically permitted to flow back out. Thus, a lack of outbound connectivity would not cause the target to return an HTTP 502 status, making this explanation incorrect.
- ✓
The web server on the target instance is returning HTTP 502 status codes.
Why this is correct
An HTTP 502 Bad Gateway response is produced by a web server acting as a reverse proxy or gateway when it receives an invalid response from an upstream server, such as an application server or backend service that the target depends on. In the context of an ALB health check, the load balancer considers any non-2xx HTTP response (including 502) as a health check failure, and the target is marked unhealthy. The fact that the ALB received a 502 proves that the target was reachable and successfully responded at the HTTP layer, so the issue is not network-level but application-layer, specifically that the target's own upstream dependencies are failing.
- ✗
The ALB health check is misconfigured with an incorrect path.
Why it's wrong here
A health check misconfiguration with an incorrect path would cause the target's web server to return a 404 Not Found, or sometimes a 403 if directory listing is forbidden, because the default object at that path does not exist. The ALB would then log the health check failure as a 404, not a 502. A 503 Service Unavailable could appear if the path exists but the server is overloaded, but a 502 specifically means the server received a bad response from an upstream component, which is not the result of a wrong health check path. Thus, while a wrong path would make the target unhealthy, it would not produce the observed 502 status.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.