Courseiva
Monitoring and Logging →mediumMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

A company is using Amazon CloudWatch Logs Insights to analyze application logs. The DevOps team needs to create a metric filter that counts occurrences of the word 'ERROR' in the log events. Which CloudWatch Logs Insights query should be used to test the metric filter?

⚠ Common exam trap

The trap is choosing a query that counts or sorts logs without filtering for the specific pattern. Candidates might think that any query that includes @message is sufficient, but the key is to filter for 'ERROR'. Also, some might forget that the filter must match the exact pattern used in the metric filter, which often includes a regex.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

fields @timestamp, @message | filter @message like /ERROR/

To test a metric filter that counts occurrences of the word 'ERROR' in log events, you need a CloudWatch Logs Insights query that filters log events containing 'ERROR'. The query `fields @timestamp, @message | filter @message like /ERROR/` does exactly that: it selects the timestamp and message fields and filters for messages that match the regular expression /ERROR/. This allows you to verify that the filter pattern will correctly identify the relevant log events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    fields @timestamp, @message | stats count() by bin(5m)

    Why it's wrong here

    fields @timestamp, @message | stats count() by bin(5m) groups matching events into 5-minute time buckets and returns a count per bucket. Because it never filters the @message field, it will count all ingested events, including non-ERROR entries, and it renders an aggregated time series rather than the individual log lines needed to validate a metric filter. This query could confirm event volume trends but cannot prove which specific events match the filter pattern.

  • ✓

    fields @timestamp, @message | filter @message like /ERROR/

    Why this is correct

    fields @timestamp, @message | filter @message like /ERROR/ applies a regular expression filter to the raw message text, returning only the individual log events that contain the substring 'ERROR'. This directly mirrors the behavior of the CloudWatch Logs metric filter pattern "ERROR", allowing you to see the exact events that would increment the metric. It is the appropriate query for testing whether the pattern matches the intended production logs before creating or updating the metric filter.

  • ✗

    fields @timestamp, @message | parse @message '[*] *' as @severity, @log

    Why it's wrong here

    fields @timestamp, @message | parse @message '[*] *' as @severity, @log extracts fields by splitting the message at the first space and capturing bracketed content as severity, but it does not apply any predicate to remove non-ERROR events. The parse operation changes the shape of the output and may produce null severity values for messages that do not follow the assumed format, yet it still returns every event. Without a filter step, this query cannot confirm which messages match an ERROR-based metric filter.

  • ✗

    fields @timestamp, @message | sort @timestamp desc

    Why it's wrong here

    fields @timestamp, @message | sort @timestamp desc simply reorders all log events by timestamp in descending order, showing the most recent events first. It does not filter @message for ERROR, so the result set can include a mix of INFO, WARN, and ERROR entries, drowning out the relevant matches. This is useful for browsing latest activity but cannot be used to validate that a metric filter will capture the intended error events.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.