Courseiva
Monitoring and Logging →mediumMultiple Select

DOP-C02 Monitoring and Logging Practice Question

A company is using Amazon CloudWatch Logs to collect logs from multiple EC2 instances. They need to filter logs in real time and send specific log events to a custom application for processing. Which TWO services can they use to achieve this?

⚠ Common exam trap

DOP-C02 often tests the difference between CloudWatch Logs subscription filters and CloudWatch Events; candidates may confuse the two and select CloudWatch Events for log processing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a CloudWatch Logs subscription filter that invokes an AWS Lambda function.

Option B is correct because a CloudWatch Logs subscription filter performs real-time filtering of log events and can deliver matching events directly to AWS Lambda, which then runs the custom application logic for processing. Option D is correct because a subscription filter can also stream filtered log events to Amazon Kinesis Data Firehose, which reliably delivers them to a custom destination for processing. Option A is incorrect because Kinesis Data Analytics analyzes streaming data but is not a CloudWatch Logs subscription destination for real-time log filtering. Option C is incorrect because CloudWatch Events (EventBridge) rules react to AWS service events, not individual CloudWatch Logs log events, and cannot filter log events to SQS. Option E is incorrect because S3 event notifications only trigger on object creation in S3 and do not provide real-time filtering of CloudWatch Logs streams.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon Kinesis Data Analytics to process the log stream.

    Why it's wrong here

    Amazon Kinesis Data Analytics is designed for running SQL queries or Apache Flink applications on data streams, not for forwarding log events. CloudWatch Logs does not have a direct integration that sends log events to Kinesis Data Analytics without first delivering them to a Kinesis Data Stream via a subscription filter. Even if you set that up, Kinesis Data Analytics would transform or analyze the data, not act as a real-time forwarding mechanism to a custom application, making it an incorrect choice for this requirement.

  • ✓

    Configure a CloudWatch Logs subscription filter that invokes an AWS Lambda function.

    Why this is correct

    A CloudWatch Logs subscription filter can be configured with a Lambda function as its destination, enabling real-time processing of log events as they arrive. When a log event matches the filter pattern, CloudWatch Logs invokes the Lambda function asynchronously, passing the event payload (base64-encoded and gzipped) for your custom logic to parse and forward. This is a native, low-latency pattern that satisfies the requirement to filter and stream logs in real time, and it is a widely recommended approach for building log-processing pipelines.

  • ✗

    Create a CloudWatch Events rule to capture log events and send them to Amazon SQS.

    Why it's wrong here

    CloudWatch Events (now part of Amazon EventBridge) is an event bus that matches events from AWS services, such as CloudTrail API calls, EC2 state changes, or scheduled cron jobs, and routes them to targets like Amazon SQS. It does not integrate directly with CloudWatch Logs to read or filter log data; log events published to a log group are not automatically emitted as CloudWatch Events. Therefore, a CloudWatch Events rule cannot capture CloudWatch Logs content, so this option fails to meet the real-time log-filtering requirement.

  • ✓

    Configure a CloudWatch Logs subscription filter that sends data to Amazon Kinesis Data Firehose.

    Why this is correct

    A CloudWatch Logs subscription filter can send log events to Amazon Kinesis Data Firehose as a delivery stream destination. Firehose then buffers, compresses, and can transform the data (e.g., via Lambda) before delivering it to custom HTTP endpoints, Amazon S3, Redshift, or other services. This is a fully managed, real-time approach that directly supports forwarding filtered log events to a custom application, making it a valid alternative to the Lambda-based solution.

  • ✗

    Use Amazon S3 event notifications to trigger a Lambda function on new log files.

    Why it's wrong here

    Amazon S3 event notifications are triggered by object-level operations (e.g., PutObject, DeleteObject) on an S3 bucket, not by CloudWatch Logs events. For this to work, logs would first need to be exported to S3 as files, but CloudWatch Logs export to S3 is a batch operation performed on an hourly or on-demand basis, not a real-time streaming mechanism. Thus, using S3 event notifications to trigger a Lambda function adds unnecessary latency and does not satisfy the real-time filtering and forwarding requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.