A CloudFront distribution uses an on-premises web server as a custom origin and requires TLS between CloudFront and that origin. The setup worked for months but users are now getting HTTP 502 (Bad Gateway) responses for pages that include CloudFront-delivered assets. What should a SysOps administrator check first to correct the issue?
Choose an answer
Tap an option to check your answer.
Correct answer: Check the origin server’s TLS certificate expiration date to confirm it hasn’t expired. Replace the certificate if it has..
Why this is the answer
The most common cause for 502 errors when CloudFront communicates with a custom origin over TLS, especially after a period of working correctly, is an expired TLS certificate on the origin server. CloudFront validates the origin's certificate, and an expired certificate will cause the connection to fail, resulting in a 502 error. While a hostname mismatch on the certificate would also cause issues, it's less likely to suddenly appear after months of working. Firewall or NACL issues blocking port 443 would prevent any connection, not just those after a period of successful operation, and CloudFront does not use NACLs for outbound connections to custom origins.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed