Courseiva

DVA-C02 Development with AWS Services Practice Question

A developer is building a serverless application that uses Amazon S3 for static website hosting and AWS Lambda for dynamic API calls. The developer wants to enable logging of all API requests. Which TWO services can be used to log API requests? (Choose TWO.)

⚠ Common exam trap

Watch out — candidates often confuse S3 server access logs (which log S3 bucket operations) with API request logging, or mistakenly think VPC Flow Logs can capture HTTP-level API calls when they only capture network-layer traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs

Amazon CloudWatch Logs is correct because it can capture and store logs from AWS Lambda function executions. When a Lambda function is invoked via an API request (e.g., through Amazon API Gateway), the function's execution details, including request IDs, timestamps, and error messages, are automatically sent to CloudWatch Logs. This enables developers to monitor and troubleshoot API-driven serverless applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    Amazon CloudWatch Logs is the primary service for collecting and monitoring logs from various AWS services and custom applications. For a serverless application utilizing API Gateway, CloudWatch Logs captures detailed execution logs, including request/response payloads, latency, and error messages. These logs are essential for real-time monitoring, debugging, and troubleshooting the runtime behavior of the API Gateway and integrated backend Lambda functions. Configuring API Gateway to send its access and execution logs to CloudWatch Logs provides granular insights into every API call.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail provides a comprehensive record of actions taken by a user, role, or an AWS service within your AWS account. It logs API calls made to AWS services (management events) and can optionally log data plane operations (data events) for specific resources. For a serverless application, CloudTrail logs actions like deploying an API Gateway, updating a Lambda function, or modifying DynamoDB tables, offering an audit trail for security analysis, compliance, and operational troubleshooting of control plane activities.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture detailed information about the IP traffic going to and from network interfaces in your Amazon Virtual Private Cloud (VPC). These logs record metadata such as source/destination IP addresses, ports, protocol, and the action (ACCEPT/REJECT) for network packets. While crucial for network security and troubleshooting within a VPC, they do not directly log API calls made to services like API Gateway or the execution of serverless functions, which operate at a higher application layer.

  • ✗

    Amazon S3 server access logs

    Why it's wrong here

    Amazon S3 server access logs provide detailed records for requests made to an S3 bucket, capturing information such as the requester, bucket name, request time, request action, and response status. These logs are invaluable for auditing access to S3 objects, understanding data usage patterns, and ensuring compliance for data stored in S3. However, they specifically track interactions with S3 storage and do not provide insights into the API calls or execution flow of a serverless application's core logic, such as API Gateway invocations or Lambda function executions.

  • ✗

    Amazon Route 53 logs

    Why it's wrong here

    Amazon Route 53 logs, specifically DNS query logs, record information about the DNS queries that Route 53 receives for your hosted zones. These logs include details like the domain name queried, the query type, and the Route 53 edge location that served the request. While useful for analyzing DNS traffic patterns and troubleshooting domain resolution issues, they do not provide any visibility into the actual execution of a serverless application or the API calls processed by services like API Gateway after DNS resolution has occurred.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.