Courseiva
Monitoring and Logging →mediumMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

A company is running a web application on Amazon EC2 instances behind an Application Load Balancer. The application is experiencing intermittent errors. The DevOps engineer needs to identify if the errors are caused by the application or the underlying infrastructure. Which solution provides the MOST detailed visibility into the application's behavior?

⚠ Common exam trap

DOP-C02 often tests whether candidates conflate infrastructure-level monitoring (CloudWatch, VPC Flow Logs, CloudTrail) with application-level tracing — the key discriminator is whether the tool can follow a single request through the application code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Instrument the application with AWS X-Ray SDK and analyze traces

AWS X-Ray traces individual requests as they travel through the application, showing latency, errors, and downstream calls at each segment. This provides the granular, request-level visibility needed to determine whether errors originate in application code or in dependencies like databases or external services. CloudWatch metrics and VPC Flow Logs operate at a coarser level and cannot pinpoint application logic failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable VPC Flow Logs and analyze traffic patterns

    Why it's wrong here

    VPC Flow Logs capture only network metadata at the ENI level—source/destination IP, ports, protocol, and packet/byte counts—and whether packets were accepted or rejected by security groups or NACLs. They do not inspect payload contents, so HTTP status codes, application exceptions, or business rule violations inside requests are invisible. Thus, while flow logs help diagnose connectivity issues, they cannot reveal why an application is returning errors in its business logic.

  • ✗

    Enable AWS CloudTrail and monitor for API errors

    Why it's wrong here

    AWS CloudTrail records management-plane API calls made by users, roles, or services within an AWS account, such as EC2 instance launches, ALB configuration changes, or IAM actions. Application-level errors raised in Java, Python, or Node.js code are not AWS API calls, so they never appear in CloudTrail event history. Monitoring CloudTrail would only expose control-plane misconfigurations or unauthorized API attempts, not the root cause of a web application failing during request processing.

  • ✓

    Instrument the application with AWS X-Ray SDK and analyze traces

    Why this is correct

    Instrumenting the application with the X-Ray SDK adds tracing headers to each incoming HTTP request and tracks the request as it flows through the EC2-hosted application and any downstream calls to databases or other services. X-Ray segments and subsegments capture the exact service, operation, and any exceptions or faults that occur, enabling a trace map that pinpoints the failing component or code path. This gives per-request context and error stack traces needed to resolve application-level errors definitively.

  • ✗

    Enable detailed CloudWatch metrics on the EC2 instances and ALB

    Why it's wrong here

    Detailed CloudWatch metrics provide time-series aggregates such as EC2 CPU utilization, disk I/O, and ALB RequestCount, TargetResponseTime, and HTTPCode_Target_5XX_Count. While these can alert when a spike of 5XX errors occurs, they do not link specific requests to the code path, query, or host that caused the failure. The aggregate nature of metrics means you see symptoms but lack trace-level granularity to identify the exact application error.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.