CV0-004 Operations and Support Practice Question
A cloud operations team runs a three-tier web application on Amazon EC2 instances behind an Application Load Balancer. Users report intermittent 502 errors, and the operations team wants to identify whether the issue originates from unhealthy targets before the load balancer removes them. Which AWS feature should the team enable to actively probe target health at a configurable interval?
⚠ Common exam trap
The trap here is assuming that logging services like CloudTrail or Flow Logs perform active health probes, when only the load balancer's own health check mechanism evaluates target health.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application Load Balancer health checks with a shortened healthy and unhealthy threshold
Application Load Balancer health checks are the built-in mechanism that actively probes each registered target and removes unhealthy ones from rotation. Tuning the healthy and unhealthy thresholds lets the team detect failing targets faster and correlate the 502 errors with backend health. Logging and DNS-based services operate at different layers and cannot actively determine target health behind an ALB.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail data events on the target instances
Why it's wrong here
CloudTrail data events record API-level activity such as S3 object operations or Lambda invocations. They do not perform active network probes against EC2 targets behind an ALB and cannot determine whether a target is healthy from the load balancer's perspective. Enabling data events would only add logging cost and would not surface the 502 root cause in this scenario.
- ✗
VPC Flow Logs on the subnet hosting the targets
Why it's wrong here
VPC Flow Logs capture IP traffic metadata at the ENI level, showing accepted and rejected flows but not application-layer health. They cannot perform the active HTTP probe an ALB uses to decide target health, so they would not identify unhealthy targets before removal. Flow Logs are useful for connectivity troubleshooting, not for driving load balancer health decisions.
- ✓
Application Load Balancer health checks with a shortened healthy and unhealthy threshold
Why this is correct
ALB health checks periodically probe each registered target on a configured protocol, port, and path. Reducing healthy and unhealthy thresholds makes the load balancer react faster to failing targets, which directly addresses identifying unhealthy targets before they serve traffic. This is the native mechanism for detecting target health in an ALB and is the correct operational control in this scenario.
- ✗
Amazon Route 53 latency-based routing with failover records
Why it's wrong here
Route 53 routing policies direct DNS queries to endpoints based on latency or failover, operating at the DNS layer. They do not probe individual EC2 targets behind an ALB and cannot decide whether a specific target should receive traffic. Using latency records here would not detect the unhealthy backend causing the 502 responses.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.