DOP-C02 AWS X-Ray Practice Question
A company is deploying a new microservice on AWS Lambda. The DevOps team needs to monitor the function for errors and performance issues. Which TWO steps should the team take to set up effective monitoring?
⚠ Common exam trap
DOP-C02 often tests the misconception that agents (like CloudWatch Agent) can be installed on Lambda — candidates must remember Lambda is a managed runtime where you rely on native CloudWatch Logs and X-Ray integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable active tracing with AWS X-Ray to trace requests through the function
Option C is correct because enabling active tracing with AWS X-Ray on a Lambda function instruments the function and its downstream calls, letting the team trace requests end-to-end, identify latency bottlenecks, and pinpoint errors across the microservice. Option D is correct because Lambda automatically streams function output to CloudWatch Logs, which captures application logs, stack traces, and custom metrics needed to diagnose errors and performance issues. VPC Flow Logs (A) only record IP-level network traffic metadata for VPC resources and do not provide function-level error or performance insight. AWS Config rules (B) evaluate resource configuration compliance, not runtime errors or performance. The CloudWatch Agent (E) is installed on EC2 instances or on-premises servers and cannot be installed inside the managed Lambda execution environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable VPC Flow Logs to monitor network traffic to the function
Why it's wrong here
VPC Flow Logs capture IP traffic at the network interface level for resources in a VPC, such as ENIs attached to Lambda functions running in a VPC. However, they only record metadata like source/destination IP, ports, and packet counts; they do not trace individual requests within the function or capture application-level logs or error messages. Thus, while useful for network diagnostics, they cannot provide the request-level visibility needed to trace a request through the Lambda function.
- ✗
Enable AWS Config rules to evaluate the function configuration
Why it's wrong here
AWS Config rules evaluate the configuration settings of AWS resources for compliance, such as verifying that a Lambda function has the correct memory, timeout, or tagging. They run as periodic or change-triggered evaluations and report on compliance state, but they do not inspect runtime behavior, invocation traces, or application logs. Consequently, they are suited for auditing infrastructure, not for tracing requests through a live function.
- ✓
Enable active tracing with AWS X-Ray to trace requests through the function
Why this is correct
Enabling active tracing with AWS X-Ray gives you end-to-end visibility into requests as they pass through the Lambda function and any downstream AWS services or HTTP APIs. X-Ray automatically records a trace segment for each invocation, captures timing, errors, and subsegments for calls made with the AWS SDK, and supports sampling to control cost. It also propagates trace IDs across services, enabling you to follow a single user request through the entire distributed application.
- ✓
Enable CloudWatch Logs for the Lambda function to capture application logs
Why this is correct
Lambda automatically sends logs of every invocation to CloudWatch Logs, including stdout/stderr output from your code and any custom log statements you write. These logs capture application-level messages, stack traces, and debug information that are essential for diagnosing runtime behavior, but they are unstructured and do not correlate with distributed traces. They serve as the logging pillar of observability, complementing metrics and traces rather than replacing them.
- ✗
Install the CloudWatch Agent on the Lambda execution environment
Why it's wrong here
The CloudWatch Agent is a software package intended for EC2 instances and on-premises servers, where you have persistent OS access and need to collect additional system-level metrics or route logs to CloudWatch. Lambda execution environments are ephemeral, AWS-managed, and provide no way to install or run such an agent; instead, Lambda integrates directly with CloudWatch Logs and X-Ray. Attempting to use the agent is invalid because there is no persistent container or host to install it on.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.