DOP-C02 Monitoring and Logging Practice Question
A company is running a critical application on Amazon ECS with Fargate launch type. The application writes logs to Amazon CloudWatch Logs. The DevOps team needs to set up an alert when the application generates more than 100 error logs in any 5-minute window. Which configuration should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudWatch Logs metric filter for 'ERROR' and a CloudWatch alarm on the resulting metric with a period of 5 minutes
A CloudWatch Logs metric filter can be configured to count occurrences of the word 'ERROR' in log streams. This filter creates a custom metric that can be monitored by a CloudWatch alarm with a period of 5 minutes. When the metric exceeds the threshold of 100, the alarm triggers an action such as an SNS notification. Option A is incorrect because CloudWatch Logs Insights is a query tool for interactive analysis, not for continuous real-time alerting. Option B is incorrect because EventBridge events are not generated from log content directly; you would need a metric filter or subscription filter to turn log data into events. Option D is incorrect because AWS CloudTrail logs API activities, not application error logs written to CloudWatch Logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a CloudWatch Logs Insights query that runs every 5 minutes and triggers an SNS notification
Why it's wrong here
Logs Insights queries are designed for interactive, ad-hoc log analysis and troubleshooting, not for continuous, automated metric extraction and alerting. While a query could identify error counts, it does not natively publish a custom metric that a CloudWatch Alarm can monitor for threshold breaches. This option is tempting because Insights can process and summarise log data effectively. However, it is suitable for manual investigation, debugging, or generating one-off reports, not for establishing a persistent, real-time alerting mechanism based on log patterns.
- ✗
Create an Amazon EventBridge rule that matches CloudWatch Logs events for the word 'ERROR' and triggers an alarm
Why it's wrong here
EventBridge rules operate on structured AWS service events, not on raw log content from CloudWatch Logs. To route log data into EventBridge, a CloudWatch Logs subscription filter would first have to stream the logs to a downstream consumer such as Lambda, which could then generate a custom event—EventBridge itself cannot parse the word 'ERROR' from a log stream. Moreover, CloudWatch Alarms are not an EventBridge target; alarms are triggered by CloudWatch metrics, not by EventBridge rules, so this approach cannot directly create or trigger an alarm.
- ✓
Create a CloudWatch Logs metric filter for 'ERROR' and a CloudWatch alarm on the resulting metric with a period of 5 minutes
Why this is correct
A CloudWatch Logs metric filter is applied to a log group in near-real time as log events are ingested, and it uses pattern syntax to count occurrences of the string 'ERROR' and emit a custom metric (e.g., ErrorCount) for that log group. The CloudWatch alarm is then configured on that custom metric with an evaluation period of 5 minutes, so if the number of ERROR log lines within a 5-minute interval exceeds the configured threshold, the alarm state changes to ALARM and can trigger an SNS notification. This is the standard, fully managed mechanism for log-pattern-based alerting because it does not require any custom code or additional infrastructure, and it integrates directly with CloudWatch alarm actions.
- ✗
Enable AWS CloudTrail logging for the ECS task and create a metric filter on CloudTrail logs
Why it's wrong here
CloudTrail records API calls made to AWS services (such as RunTask, DescribeTasks, or other ECS control-plane operations) but it does not capture the stdout/stderr output of the application running inside an ECS task. The application's error logs are sent to CloudWatch Logs through the awslogs log driver configured in the task definition, not to CloudTrail. Even if a metric filter were applied to a CloudTrail log group, it would only match error messages from the API calls themselves—not the application-level 'ERROR' strings—so this option would fail to monitor the critical application's runtime errors.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company runs a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application processes financial transactions. The DevOps team needs to monitor for duplicate transactions that could occur due to retries. The team wants to set up an alert when the number of duplicate transaction attempts exceeds 10 in a 5-minute window. The application logs each transaction attempt with a unique transaction ID to CloudWatch Logs. What is the most efficient way to achieve this?
medium- ✓ A.Create a CloudWatch Logs metric filter that counts log events containing 'DuplicateTransaction' and set an alarm on the metric with a threshold of 10.
- B.Use DynamoDB Streams to trigger a Lambda function that counts duplicates and publishes metrics.
- C.Stream the CloudWatch Logs to Amazon Kinesis Data Analytics and use SQL queries to detect duplicates.
- D.Modify the Lambda function to publish a custom metric to CloudWatch for each duplicate transaction, then set an alarm.
Why A: CloudWatch Logs metric filters can scan log events for specific terms like 'DuplicateTransaction' and convert matches into a custom metric. You can then create a CloudWatch alarm on that metric with a threshold of 10 over a 5-minute period. This requires no code changes, no additional services, and is the most efficient and native solution for monitoring log-based patterns.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.