DVA-C02 Troubleshooting and Optimization Practice Question
A developer is running a Docker container on Amazon ECS with Fargate. The container logs are not appearing in CloudWatch Logs even though the task definition has a logConfiguration specifying the awslogs driver and a log group. What is the MOST likely missing configuration?
⚠ Common exam trap
DVA-C02 often tests the confusion between the task execution role and the task role — candidates pick 'execution role lacks permissions' correctly only if they know the awslogs driver runs under the execution role, not the application task role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The task execution role lacks the necessary IAM permissions to write to CloudWatch Logs.
For Fargate tasks, the awslogs driver uses the task execution role (not the task role) to call logs:CreateLogStream and logs:PutLogEvents. If that role lacks these permissions, the container starts but log delivery silently fails, which is the most common cause of missing CloudWatch logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The container image does not have the awslogs log driver installed.
Why it's wrong here
The awslogs log driver is a feature configured at the Docker daemon level or within the ECS task definition, not a component installed *inside* the container image itself. Docker containers leverage log drivers provided by the Docker engine or orchestration platform (like ECS) to send their standard output and error streams to a specified destination. Therefore, the absence of an "installation" within the image is not a valid reason for logging failure.
- ✓
The task execution role lacks the necessary IAM permissions to write to CloudWatch Logs.
Why this is correct
For an Amazon ECS task to successfully send container logs to CloudWatch Logs, the assigned Task Execution IAM role must possess specific permissions. These include logs:CreateLogStream to create the necessary log stream within the specified log group and logs:PutLogEvents to write log data to that stream. Without these critical permissions, the ECS agent will be unable to interact with CloudWatch Logs, resulting in logging failures.
- ✗
The CloudWatch Logs log group does not exist.
Why it's wrong here
When an ECS task is configured to use the awslogs log driver and specifies a CloudWatch Logs log group, ECS (specifically the ECS agent or the underlying service) will attempt to create that log group automatically if it does not already exist. This automatic creation relies on the Task Execution Role having the logs:CreateLogGroup permission. Therefore, a non-existent log group is not inherently a problem, provided the necessary creation permissions are in place.
- ✗
The EC2 instance profile does not have CloudWatch Logs permissions.
Why it's wrong here
For tasks running on AWS Fargate, the primary IAM entity responsible for interacting with AWS services on behalf of the task, including sending logs to CloudWatch, is the Task Execution IAM Role. EC2 instance profiles are relevant for tasks running on EC2 launch types, where the underlying EC2 instance needs permissions. However, Fargate abstracts away the underlying infrastructure, making the instance profile irrelevant for Fargate-specific permission issues.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.