DVA-C02 Development with AWS Services Practice Question
A company has a legacy application that generates log files on an EC2 instance. The developer needs to stream these log files to Amazon CloudWatch Logs in real time. The developer installed the CloudWatch agent on the EC2 instance and configured it to monitor the log files. However, the logs are not appearing in CloudWatch Logs. The developer checks the agent status and sees that the agent is running. What is the most likely cause of this issue?
⚠ Common exam trap
DVA-C02 often tests the assumption that a 'running' agent means it is functioning — candidates overlook that the agent can run while lacking IAM permissions, and they pick network or configuration answers instead of checking the instance role's CloudWatch Logs policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The EC2 instance does not have an IAM role with the necessary CloudWatch Logs permissions.
The CloudWatch agent uses the EC2 instance's IAM role credentials to call the CloudWatch Logs API (logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents). If the instance profile lacks these permissions, the agent process runs but every API call is rejected with AccessDenied, so logs never appear. This is the most common cause when the agent status shows running but no data arrives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The log file format is not compatible with the CloudWatch agent.
Why it's wrong here
The CloudWatch agent is highly versatile and designed to ingest log data from various text-based formats, including custom application logs, system logs, and web server logs. It does not impose strict format requirements, as its primary function is to collect and stream raw log events. Therefore, an incompatible log file format is generally not a reason for the agent to fail in sending logs to CloudWatch Logs.
- ✗
The EC2 instance is in a private subnet without internet access.
Why it's wrong here
While an EC2 instance in a private subnet typically lacks direct internet access, the CloudWatch agent can still successfully send logs to CloudWatch Logs by utilizing VPC interface endpoints. These endpoints provide private connectivity from your VPC to AWS services like CloudWatch Logs, ensuring secure and direct communication without requiring an Internet Gateway or NAT Gateway. Therefore, the absence of internet access does not inherently prevent log ingestion.
- ✓
The EC2 instance does not have an IAM role with the necessary CloudWatch Logs permissions.
Why this is correct
For the CloudWatch agent to successfully publish log data, the EC2 instance profile must be associated with an IAM role that grants specific permissions to CloudWatch Logs. Essential permissions include logs:PutLogEvents to send log data, logs:CreateLogStream to create new log streams, and logs:DescribeLogStreams to check existing streams. Without these explicit permissions, the agent will be unauthorized to interact with the CloudWatch Logs service, leading to log ingestion failures.
- ✗
The CloudWatch agent configuration file does not specify an existing log group.
Why it's wrong here
The CloudWatch agent is designed with convenience features, including the ability to automatically create a log group if the one specified in its configuration file does not already exist. As long as the associated IAM role has the logs:CreateLogGroup permission, the agent will provision the log group upon its first attempt to send logs. Therefore, the non-existence of a pre-configured log group is not a blocker for log ingestion.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.