DOP-C02 Monitoring and Logging Practice Question
A company is using Amazon CloudWatch Logs to collect application logs. They need to search and analyze the logs in near real-time. Which TWO AWS services can be used to achieve this?
⚠ Common exam trap
DOP-C02 often tests whether candidates confuse log analysis (Logs Insights, OpenSearch) with log-generating or monitoring services (Synthetics) or assume Athena can query CloudWatch Logs directly without an S3 export.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs Insights
Amazon CloudWatch Logs Insights (option A) is correct because it is a purpose-built, interactive query engine within CloudWatch Logs that lets you search, filter, and analyze log data in near real-time using a specialized query syntax, with results returned in seconds. Amazon OpenSearch Service (option E) is also correct because it can ingest CloudWatch Logs (typically via a subscription filter to Lambda or Kinesis) and provides near real-time search, dashboards, and analytics on that log data. Option B, Amazon CloudWatch Synthetics, is wrong because it creates canaries to monitor endpoints and availability, not to search or analyze log content. Option C, Amazon Kinesis Data Analytics, is wrong because it is for running SQL/Flink stream processing over streaming data, not for ad-hoc log search and analysis. Option D, Amazon Athena, is wrong because it queries data in S3 with SQL on a batch/interactive basis and does not natively search CloudWatch Logs in near real-time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudWatch Logs Insights
Why this is correct
Amazon CloudWatch Logs Insights is a native query engine that runs SQL-like queries directly against log data already ingested into CloudWatch Logs, without requiring any data movement or additional infrastructure. It automatically parses structured JSON log events, discovers fields, and lets you use commands such as filter, stats, sort, and time-based aggregation for interactive troubleshooting and pattern analysis. As the logs are already collected in CloudWatch, this is the most immediate and cost-effective way to analyze application log data.
- ✗
Amazon CloudWatch Synthetics
Why it's wrong here
Amazon CloudWatch Synthetics is designed for active monitoring by running lightweight Node.js or Python canaries that execute scripted HTTP requests and browser interactions against your API endpoints or web applications, checking availability, latency, and visual regression. It does not provide a query language or any ability to interrogate historical log data stored in CloudWatch Logs, because its core purpose is to generate synthetic traffic and alert on failures rather than analyze existing logs. Therefore, it cannot fulfill the requirement to analyze application logs.
- ✗
Amazon Kinesis Data Analytics
Why it's wrong here
Amazon Kinesis Data Analytics (now Amazon Managed Service for Apache Flink) is a real-time stream processing engine that consumes data exclusively from Amazon Kinesis Data Streams, Amazon Kinesis Data Firehose, or custom sources via the Kinesis Client Library; it cannot directly read from CloudWatch Logs. To get log data into it, you would first need to configure a CloudWatch Logs subscription to stream logs to a Kinesis Data Stream, which adds pipeline complexity and latency, and even then it would provide streaming analytics rather than interactive ad-hoc querying of the current log set. For the stated goal of analyzing logs already in CloudWatch, this is neither purpose-built nor the simplest path.
- ✗
Amazon Athena
Why it's wrong here
Amazon Athena is an interactive SQL query engine that runs directly on objects stored in Amazon Simple Storage Service (S3), meaning it cannot query CloudWatch Logs in place. Before Athena can be used, you must export the log groups to S3 either by creating a manual export task for historic logs or by setting up a Kinesis Data Firehose subscription to continuously deliver log data, after which you also need to define a table schema using an Athena DDL statement or a crawler. This detour introduces setup overhead and a time delay, making it less direct than using CloudWatch Logs Insights on the already-collected logs.
- ✓
Amazon OpenSearch Service
Why this is correct
Amazon OpenSearch Service is a legitimate choice for log analytics because CloudWatch Logs can stream log events to an OpenSearch cluster in near real time by way of a subscription filter backed by a Lambda function or by using Amazon Data Firehose to push the data into an OpenSearch index. Once the logs are indexed, you can run sophisticated aggregations, create dashboards in OpenSearch Dashboards, and set up alerting, making it a powerful solution for exploring logs at scale. However, unlike CloudWatch Logs Insights, it requires provisioning and managing an OpenSearch domain and configuring the ingest pipeline, so it is a heavier operational lift if you only need straightforward query of logs that are already in CloudWatch Logs.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is using Amazon CloudWatch Logs to store application logs. The DevOps team needs to search and analyze logs from multiple EC2 instances in real time. Which TWO services can be used to achieve this? (Choose TWO.)
medium- ✓ A.Amazon OpenSearch Service.
- B.Amazon Athena.
- C.Amazon QuickSight.
- D.Amazon Kinesis Data Analytics.
- ✓ E.CloudWatch Logs Insights.
Why A: CloudWatch Logs can stream logs to Amazon OpenSearch Service for real-time search and analytics. Option E is correct because CloudWatch Logs Insights allows real-time querying of log groups directly within CloudWatch. Option B is incorrect: Amazon Athena is designed for querying data in S3, not for real-time log search from EC2 instances. Option C is incorrect: Amazon QuickSight is a business intelligence service for visualization, not real-time log search. Option D is incorrect: Amazon Kinesis Data Analytics is for analyzing streaming data, not directly searching CloudWatch Logs.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.