DOP-C02 Monitoring and Logging Practice Question
A company is using a centralized logging solution with Amazon OpenSearch Service. The DevOps team notices that logs from some EC2 instances are missing. The CloudWatch agent is installed and configured on all instances. What should the team do to troubleshoot the issue?
⚠ Common exam trap
Many exam-takers assume a 'status' command exists for the CloudWatch agent (Option A) because many other AWS services have such commands, but the agent uses a control script instead, and the real diagnostic starting point is the agent's own log file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the CloudWatch agent log file located at /var/log/amazon/amazon-cloudwatch-agent/amazon-cloudwatch-agent.log.
The CloudWatch agent writes detailed operational logs to /var/log/amazon/amazon-cloudwatch-agent/amazon-cloudwatch-agent.log. This file contains errors, warnings, and debug messages that can reveal why logs from specific EC2 instances are not being delivered to Amazon OpenSearch Service. Checking this log is the first and most direct troubleshooting step because it captures agent-level issues such as configuration errors, network connectivity failures, or permission problems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the CloudWatch agent status using the CloudWatch agent status command.
Why it's wrong here
The `amazon-cloudwatch-agent-status` command only reports whether the agent process is running and its basic operational state (e.g., version, config path). It does not surface detailed transport or delivery errors, IAM permission failures, or malformed log config entries. In a pure troubleshooting scenario where logs are not appearing, this command provides no diagnostic path to identify why a log stream is missing or why the agent cannot reach CloudWatch Logs.
- ✗
Configure a Lambda function to poll the CloudWatch agent for logs.
Why it's wrong here
A Lambda function cannot 'poll' the CloudWatch agent itself because the agent is a local service and has no API endpoint for remote queries. The agent actively pushes log events to CloudWatch Logs via the PutLogEvents API; it does not expose a pull mechanism. While Lambda could be used to inspect CloudWatch Logs API metrics or query already-delivered log streams, that would only confirm the absence of logs after the fact and does not diagnose an agent-side problem such as a bad config or connectivity issue. This approach adds complexity without addressing the agent's failure mode.
- ✗
Verify that the EC2 instances have an SQS queue configured for log delivery.
Why it's wrong here
The CloudWatch agent does not use Amazon SQS at any point in its log delivery flow. Logs are gathered from local files/streams and sent directly to the CloudWatch Logs service using the AWS SDK (PutLogEvents). Requiring an SQS queue on the EC2 instances implies a queue-based pipeline that does not exist in this architecture. Misdiagnosing the problem as a missing SQS queue would lead you away from the agent's actual log file and error messages, which are the correct sources of truth for delivery failures.
- ✓
Check the CloudWatch agent log file located at /var/log/amazon/amazon-cloudwatch-agent/amazon-cloudwatch-agent.log.
Why this is correct
The CloudWatch agent logs its own operational activity—including configuration errors, permission issues, network timeouts, and partial failures—to `/var/log/amazon/amazon-cloudwatch-agent/amazon-cloudwatch-agent.log`. When log events are not appearing in CloudWatch Logs, this file is the authoritative source for finding the root cause. It records detailed error messages and stack traces that are not available in the agent status output or anywhere else, making it the first place to look when troubleshooting a missing log delivery.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A DevOps team is using Amazon CloudWatch Logs to centralize logs from multiple EC2 instances running a custom application. The team notices that logs are missing from some instances intermittently. The CloudWatch agent configuration is identical across all instances. What is the MOST likely cause of the missing logs?
hard- ✓ A.The CloudWatch Logs agent's state file has become corrupted due to disk full condition
- B.The VPC Flow Logs are consuming all available network bandwidth
- C.The EC2 instances are running out of CPU credits, causing the agent to skip log batches
- D.The IAM role attached to the instances has been rotated incorrectly
Why A: The CloudWatch agent maintains a persistent state file (typically at /opt/aws/amazon-cloudwatch-agent/etc/ or /var/lib/amazon/amazon-cloudwatch-agent/) that tracks which log lines have already been published to CloudWatch Logs. If the disk fills up, this state file can become corrupted or truncated, causing the agent to lose track of its position and silently drop log batches. Since the configuration is identical across instances, a per-instance environmental issue like disk exhaustion is the most plausible cause of intermittent, instance-specific log loss.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.