DVA-C02 Development with AWS Services Practice Question
A developer is building a serverless application that uses Amazon S3 for static website hosting and AWS Lambda for dynamic API calls. The developer wants to enable logging of all API requests. Which TWO services can be used to log API requests? (Choose TWO.)
⚠ Common exam trap
Watch out — candidates often confuse S3 server access logs (which log S3 bucket operations) with API request logging, or mistakenly think VPC Flow Logs can capture HTTP-level API calls when they only capture network-layer traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs
Amazon CloudWatch Logs is correct because it can capture and store logs from AWS Lambda function executions. When a Lambda function is invoked via an API request (e.g., through Amazon API Gateway), the function's execution details, including request IDs, timestamps, and error messages, are automatically sent to CloudWatch Logs. This enables developers to monitor and troubleshoot API-driven serverless applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudWatch Logs
Why this is correct
Amazon CloudWatch Logs is the primary service for collecting and monitoring logs from various AWS services and custom applications. For a serverless application utilizing API Gateway, CloudWatch Logs captures detailed execution logs, including request/response payloads, latency, and error messages. These logs are essential for real-time monitoring, debugging, and troubleshooting the runtime behavior of the API Gateway and integrated backend Lambda functions. Configuring API Gateway to send its access and execution logs to CloudWatch Logs provides granular insights into every API call.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail provides a comprehensive record of actions taken by a user, role, or an AWS service within your AWS account. It logs API calls made to AWS services (management events) and can optionally log data plane operations (data events) for specific resources. For a serverless application, CloudTrail logs actions like deploying an API Gateway, updating a Lambda function, or modifying DynamoDB tables, offering an audit trail for security analysis, compliance, and operational troubleshooting of control plane activities.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture detailed information about the IP traffic going to and from network interfaces in your Amazon Virtual Private Cloud (VPC). These logs record metadata such as source/destination IP addresses, ports, protocol, and the action (ACCEPT/REJECT) for network packets. While crucial for network security and troubleshooting within a VPC, they do not directly log API calls made to services like API Gateway or the execution of serverless functions, which operate at a higher application layer.
- ✗
Amazon S3 server access logs
Why it's wrong here
Amazon S3 server access logs provide detailed records for requests made to an S3 bucket, capturing information such as the requester, bucket name, request time, request action, and response status. These logs are invaluable for auditing access to S3 objects, understanding data usage patterns, and ensuring compliance for data stored in S3. However, they specifically track interactions with S3 storage and do not provide insights into the API calls or execution flow of a serverless application's core logic, such as API Gateway invocations or Lambda function executions.
- ✗
Amazon Route 53 logs
Why it's wrong here
Amazon Route 53 logs, specifically DNS query logs, record information about the DNS queries that Route 53 receives for your hosted zones. These logs include details like the domain name queried, the query type, and the Route 53 edge location that served the request. While useful for analyzing DNS traffic patterns and troubleshooting domain resolution issues, they do not provide any visibility into the actual execution of a serverless application or the API calls processed by services like API Gateway after DNS resolution has occurred.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.