DOP-C02 Monitoring and Logging Practice Question
A company is using Amazon CloudWatch Logs to store application logs. The DevOps team wants to set up real-time monitoring for specific error patterns and trigger remediation actions. Which TWO services can process the log events in real time and invoke an AWS Lambda function for remediation? (Choose two.)
⚠ Common exam trap
The trap is assuming CloudWatch Logs can natively target SQS or SNS (options D and E); in reality only subscription filters and Kinesis streaming are supported real-time paths to Lambda.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stream log events to Amazon Kinesis Data Streams and configure a Lambda function to process the stream.
Option A is correct because CloudWatch Logs subscription filters can stream log events in real time to Amazon Kinesis Data Streams, and a Lambda function can be configured with the Kinesis stream as an event source to process records and invoke remediation logic. Option B is correct because a CloudWatch Logs subscription filter can deliver matching log events directly to AWS Lambda in real time, which is the native pattern for real-time log processing and automated remediation. Option C is not correct because EventBridge rules match on CloudWatch Logs API events such as CreateLogGroup or PutRetentionPolicy, not on the contents of individual log events, so it cannot process error patterns in real time. Option D is not correct because CloudWatch Logs does not natively send log events to Amazon SQS, and polling SQS is not a real-time push-based processing pattern. Option E is not correct because CloudWatch Logs does not publish log events directly to Amazon SNS, and even if it did, SNS-to-Lambda is not a supported real-time log event processing path for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Stream log events to Amazon Kinesis Data Streams and configure a Lambda function to process the stream.
Why this is correct
Amazon CloudWatch Logs subscription filters can deliver log events in real time to a Kinesis data stream, which then uses a Lambda event source mapping to process each record. The stream acts as a durably buffered, highly scalable ingestion layer that decouples producers from consumers and preserves event ordering per shard. This is a fully supported path for real-time log processing and allows multiple Lambda functions or other consumers to read the same stream independently.
- ✓
Create a CloudWatch Logs subscription filter that delivers log events to a Lambda function.
Why this is correct
A CloudWatch Logs subscription filter can directly invoke an AWS Lambda function, passing a compressed batch of log events as the invocation payload. Because the filter pushes events to Lambda as soon as they are received, the function is triggered with minimal latency, making this an natively supported real-time option. Unlike the Kinesis route, no intermediate streaming service is involved, but the function may be subject to invocation throttling under very high log volumes.
- ✗
Create an Amazon EventBridge rule that matches on CloudWatch Logs log group events.
Why it's wrong here
Amazon EventBridge rules operate on structured service events rather than raw log data, and CloudWatch Logs does not have a built-in EventBridge target for subscription filters. While you could use a custom Lambda or Kinesis consumer to transform log events and republish them to EventBridge, that requires an intermediary and is not a native capability. Therefore, this option fails because EventBridge cannot directly subscribe to CloudWatch Logs stream events or log groups.
- ✗
Configure the log group to send log events to an Amazon SQS queue, and have the Lambda function poll the queue.
Why it's wrong here
CloudWatch Logs subscription filters do not support Amazon SQS as a destination, so you cannot directly configure a log group to push events to a queue. Even if you inserted a Lambda function between CloudWatch Logs and SQS, the Lambda function would poll the queue in batch intervals rather than receive real-time pushes, adding unnecessary latency. The polling model of SQS also makes it ill-suited as a primary real-time processing mechanism for log events.
- ✗
Publish log events to an Amazon SNS topic and subscribe the Lambda function.
Why it's wrong here
Amazon SNS is not a valid destination for CloudWatch Logs subscription filters; the only supported push targets are Lambda, Kinesis Data Streams, and Kinesis Data Firehose. Even if you were to create an intermediate Lambda function to forward log events to SNS, the direct path from CloudWatch Logs to SNS does not exist, and doing so would add an unnecessary hop without improving real-time processing. Thus, this option cannot achieve direct real-time delivery of log events to Lambda.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.