DVA-C02 Security Practice Question
A company has a centralized logging solution where all EC2 instances send logs to a CloudWatch Logs group in a central account. The EC2 instances are in a different account (App Account). The developer configures the CloudWatch agent on the instances with the necessary IAM role. However, logs are not appearing in the central account's log group. The IAM role in the App Account has permissions to put logs to the central account's log group. What is the most likely missing configuration?
⚠ Common exam trap
DVA-C02 often tests cross-account access where both identity-based and resource-based policies are needed. Candidates may focus only on the IAM role permissions and forget the resource-based policy on the destination log group.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The central account's log group must have a resource-based policy that grants the App Account's IAM role permissions to put logs.
For cross-account CloudWatch Logs, the central account's log group must have a resource-based policy that grants the App Account's IAM role permission to put logs. Even if the IAM role in the App Account has permissions, the destination log group must also allow the source. This is a common missing configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CloudWatch Logs must be encrypted with the same KMS key in both accounts.
Why it's wrong here
CloudWatch Logs encryption with AWS Key Management Service (KMS) is an optional configuration, not a mandatory requirement for sending logs, even in a cross-account scenario. Logs can be stored unencrypted or utilize AWS-managed encryption keys by default. Furthermore, if KMS encryption is enabled for a log group, each account can independently manage and use its own distinct KMS key; there is no technical necessity or requirement for both the source and destination accounts to share or use the same KMS key for their respective log storage.
- ✓
The central account's log group must have a resource-based policy that grants the App Account's IAM role permissions to put logs.
Why this is correct
For successful cross-account logging, the destination CloudWatch Logs log group in the central account absolutely requires a resource-based policy. This policy must explicitly grant the `logs:PutLogEvents` permission to the specific IAM role or user from the application account that will be sending the logs. Without this explicit permission defined directly on the log group resource, the application account's IAM principal, even with local `logs:PutLogEvents` permissions, will be denied access to write to a log group owned by a different AWS account, establishing the necessary trust boundary.
- ✗
The log group must be in the same region as the EC2 instances.
Why it's wrong here
CloudWatch Logs fully supports cross-region logging, meaning EC2 instances can send their logs to a log group located in a different AWS region than the instances themselves. While configuring the CloudWatch agent to target a different region requires specifying the desired region in its configuration, this is a standard and supported capability. Therefore, stating that the log group *must* be in the same region as the EC2 instances is incorrect and imposes an unnecessary architectural constraint.
- ✗
The EC2 instances must be in a VPC with a VPC endpoint for CloudWatch Logs.
Why it's wrong here
EC2 instances can send logs to CloudWatch Logs over the public internet by default, provided they have outbound network connectivity and the necessary IAM permissions. A VPC endpoint for CloudWatch Logs is an optional feature that allows instances within a private VPC to communicate with the CloudWatch Logs service entirely within the AWS network, bypassing the internet gateway. While VPC endpoints offer benefits like enhanced security and reduced data transfer costs, they are not a mandatory requirement for logging functionality.
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.