Courseiva
Monitoring and Logging →mediumMultiple Select

DOP-C02 Monitoring and Logging Practice Question

A company is using Amazon CloudWatch Logs to store application logs. The DevOps team wants to set up real-time monitoring for specific error patterns and trigger remediation actions. Which TWO services can process the log events in real time and invoke an AWS Lambda function for remediation? (Choose two.)

⚠ Common exam trap

The trap is assuming CloudWatch Logs can natively target SQS or SNS (options D and E); in reality only subscription filters and Kinesis streaming are supported real-time paths to Lambda.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stream log events to Amazon Kinesis Data Streams and configure a Lambda function to process the stream.

Option A is correct because CloudWatch Logs subscription filters can stream log events in real time to Amazon Kinesis Data Streams, and a Lambda function can be configured with the Kinesis stream as an event source to process records and invoke remediation logic. Option B is correct because a CloudWatch Logs subscription filter can deliver matching log events directly to AWS Lambda in real time, which is the native pattern for real-time log processing and automated remediation. Option C is not correct because EventBridge rules match on CloudWatch Logs API events such as CreateLogGroup or PutRetentionPolicy, not on the contents of individual log events, so it cannot process error patterns in real time. Option D is not correct because CloudWatch Logs does not natively send log events to Amazon SQS, and polling SQS is not a real-time push-based processing pattern. Option E is not correct because CloudWatch Logs does not publish log events directly to Amazon SNS, and even if it did, SNS-to-Lambda is not a supported real-time log event processing path for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Stream log events to Amazon Kinesis Data Streams and configure a Lambda function to process the stream.

    Why this is correct

    Amazon CloudWatch Logs subscription filters can deliver log events in real time to a Kinesis data stream, which then uses a Lambda event source mapping to process each record. The stream acts as a durably buffered, highly scalable ingestion layer that decouples producers from consumers and preserves event ordering per shard. This is a fully supported path for real-time log processing and allows multiple Lambda functions or other consumers to read the same stream independently.

  • ✓

    Create a CloudWatch Logs subscription filter that delivers log events to a Lambda function.

    Why this is correct

    A CloudWatch Logs subscription filter can directly invoke an AWS Lambda function, passing a compressed batch of log events as the invocation payload. Because the filter pushes events to Lambda as soon as they are received, the function is triggered with minimal latency, making this an natively supported real-time option. Unlike the Kinesis route, no intermediate streaming service is involved, but the function may be subject to invocation throttling under very high log volumes.

  • ✗

    Create an Amazon EventBridge rule that matches on CloudWatch Logs log group events.

    Why it's wrong here

    Amazon EventBridge rules operate on structured service events rather than raw log data, and CloudWatch Logs does not have a built-in EventBridge target for subscription filters. While you could use a custom Lambda or Kinesis consumer to transform log events and republish them to EventBridge, that requires an intermediary and is not a native capability. Therefore, this option fails because EventBridge cannot directly subscribe to CloudWatch Logs stream events or log groups.

  • ✗

    Configure the log group to send log events to an Amazon SQS queue, and have the Lambda function poll the queue.

    Why it's wrong here

    CloudWatch Logs subscription filters do not support Amazon SQS as a destination, so you cannot directly configure a log group to push events to a queue. Even if you inserted a Lambda function between CloudWatch Logs and SQS, the Lambda function would poll the queue in batch intervals rather than receive real-time pushes, adding unnecessary latency. The polling model of SQS also makes it ill-suited as a primary real-time processing mechanism for log events.

  • ✗

    Publish log events to an Amazon SNS topic and subscribe the Lambda function.

    Why it's wrong here

    Amazon SNS is not a valid destination for CloudWatch Logs subscription filters; the only supported push targets are Lambda, Kinesis Data Streams, and Kinesis Data Firehose. Even if you were to create an intermediate Lambda function to forward log events to SNS, the direct path from CloudWatch Logs to SNS does not exist, and doing so would add an unnecessary hop without improving real-time processing. Thus, this option cannot achieve direct real-time delivery of log events to Lambda.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.