Courseiva
Monitoring and Logging →easyMultiple Select

DOP-C02 Monitoring and Logging Practice Question

A company is using Amazon CloudWatch Logs to collect application logs. They need to search and analyze the logs in near real-time. Which TWO AWS services can be used to achieve this?

⚠ Common exam trap

DOP-C02 often tests whether candidates confuse log analysis (Logs Insights, OpenSearch) with log-generating or monitoring services (Synthetics) or assume Athena can query CloudWatch Logs directly without an S3 export.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs Insights

Amazon CloudWatch Logs Insights (option A) is correct because it is a purpose-built, interactive query engine within CloudWatch Logs that lets you search, filter, and analyze log data in near real-time using a specialized query syntax, with results returned in seconds. Amazon OpenSearch Service (option E) is also correct because it can ingest CloudWatch Logs (typically via a subscription filter to Lambda or Kinesis) and provides near real-time search, dashboards, and analytics on that log data. Option B, Amazon CloudWatch Synthetics, is wrong because it creates canaries to monitor endpoints and availability, not to search or analyze log content. Option C, Amazon Kinesis Data Analytics, is wrong because it is for running SQL/Flink stream processing over streaming data, not for ad-hoc log search and analysis. Option D, Amazon Athena, is wrong because it queries data in S3 with SQL on a batch/interactive basis and does not natively search CloudWatch Logs in near real-time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudWatch Logs Insights

    Why this is correct

    Amazon CloudWatch Logs Insights is a native query engine that runs SQL-like queries directly against log data already ingested into CloudWatch Logs, without requiring any data movement or additional infrastructure. It automatically parses structured JSON log events, discovers fields, and lets you use commands such as filter, stats, sort, and time-based aggregation for interactive troubleshooting and pattern analysis. As the logs are already collected in CloudWatch, this is the most immediate and cost-effective way to analyze application log data.

  • ✗

    Amazon CloudWatch Synthetics

    Why it's wrong here

    Amazon CloudWatch Synthetics is designed for active monitoring by running lightweight Node.js or Python canaries that execute scripted HTTP requests and browser interactions against your API endpoints or web applications, checking availability, latency, and visual regression. It does not provide a query language or any ability to interrogate historical log data stored in CloudWatch Logs, because its core purpose is to generate synthetic traffic and alert on failures rather than analyze existing logs. Therefore, it cannot fulfill the requirement to analyze application logs.

  • ✗

    Amazon Kinesis Data Analytics

    Why it's wrong here

    Amazon Kinesis Data Analytics (now Amazon Managed Service for Apache Flink) is a real-time stream processing engine that consumes data exclusively from Amazon Kinesis Data Streams, Amazon Kinesis Data Firehose, or custom sources via the Kinesis Client Library; it cannot directly read from CloudWatch Logs. To get log data into it, you would first need to configure a CloudWatch Logs subscription to stream logs to a Kinesis Data Stream, which adds pipeline complexity and latency, and even then it would provide streaming analytics rather than interactive ad-hoc querying of the current log set. For the stated goal of analyzing logs already in CloudWatch, this is neither purpose-built nor the simplest path.

  • ✗

    Amazon Athena

    Why it's wrong here

    Amazon Athena is an interactive SQL query engine that runs directly on objects stored in Amazon Simple Storage Service (S3), meaning it cannot query CloudWatch Logs in place. Before Athena can be used, you must export the log groups to S3 either by creating a manual export task for historic logs or by setting up a Kinesis Data Firehose subscription to continuously deliver log data, after which you also need to define a table schema using an Athena DDL statement or a crawler. This detour introduces setup overhead and a time delay, making it less direct than using CloudWatch Logs Insights on the already-collected logs.

  • ✓

    Amazon OpenSearch Service

    Why this is correct

    Amazon OpenSearch Service is a legitimate choice for log analytics because CloudWatch Logs can stream log events to an OpenSearch cluster in near real time by way of a subscription filter backed by a Lambda function or by using Amazon Data Firehose to push the data into an OpenSearch index. Once the logs are indexed, you can run sophisticated aggregations, create dashboards in OpenSearch Dashboards, and set up alerting, making it a powerful solution for exploring logs at scale. However, unlike CloudWatch Logs Insights, it requires provisioning and managing an OpenSearch domain and configuring the ingest pipeline, so it is a heavier operational lift if you only need straightforward query of logs that are already in CloudWatch Logs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is using Amazon CloudWatch Logs to store application logs. The DevOps team needs to search and analyze logs from multiple EC2 instances in real time. Which TWO services can be used to achieve this? (Choose TWO.)

medium
  • ✓ A.Amazon OpenSearch Service.
  • B.Amazon Athena.
  • C.Amazon QuickSight.
  • D.Amazon Kinesis Data Analytics.
  • ✓ E.CloudWatch Logs Insights.

Why A: CloudWatch Logs can stream logs to Amazon OpenSearch Service for real-time search and analytics. Option E is correct because CloudWatch Logs Insights allows real-time querying of log groups directly within CloudWatch. Option B is incorrect: Amazon Athena is designed for querying data in S3, not for real-time log search from EC2 instances. Option C is incorrect: Amazon QuickSight is a business intelligence service for visualization, not real-time log search. Option D is incorrect: Amazon Kinesis Data Analytics is for analyzing streaming data, not directly searching CloudWatch Logs.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.