DOP-C02 Monitoring and Logging Practice Question
A company is using Amazon CloudWatch Logs to store application logs. The DevOps engineer needs to ensure that log data is encrypted at rest using a customer-managed KMS key. What step must be taken?
⚠ Common exam trap
Test-takers frequently confuse associating a KMS key with an IAM role (which controls access) with associating it directly with the log group (which controls encryption at rest), leading them to select Option B instead of C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new KMS customer-managed key and associate it with the CloudWatch Logs log group.
CloudWatch Logs supports encryption at rest using a customer-managed KMS key, which must be explicitly associated with the log group. When you create or update a log group, you can specify a KMS key ID (via the AWS CLI, SDK, or console) to encrypt all log data stored in that group. This ensures that the log data is encrypted using a key you control, not the default AWS-managed key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudTrail to encrypt the log data before it is sent to CloudWatch Logs.
Why it's wrong here
CloudTrail is an API audit service that records who made which call, but it has no role in encrypting payloads written to CloudWatch Logs. While CloudTrail can deliver events to a CloudWatch Logs log group, the encryption of that data is entirely governed by the log group's KMS configuration, not by CloudTrail. Invoking CloudTrail to encrypt log data would neither alter the log group's encryption settings nor add an extra encryption layer, so this approach fails to meet the compliance requirement.
- ✗
Create a KMS key and apply it to the IAM role used by the application.
Why it's wrong here
KMS keys are designed to be used for cryptographic operations by principals granted permission through key policies and IAM policies, but they are not 'applied to' an IAM role to encrypt data on that role's behalf. Attaching a KMS key to the application's IAM role would only authorize that role to call KMS operations such as Encrypt or Decrypt; it would not cause CloudWatch Logs to use that key for encrypting the log group. To achieve encryption at rest, the key must be explicitly associated with the log group itself, because CloudWatch Logs does not infer encryption keys from the identity of the writer.
- ✓
Create a new KMS customer-managed key and associate it with the CloudWatch Logs log group.
Why this is correct
This is the correct solution because CloudWatch Logs supports server-side encryption using a customer-managed KMS key that you can associate directly with the log group. When you create a log group or call the AssociateKmsKey API, you supply the key ARN, and CloudWatch Logs uses that key to encrypt all new incoming log events. This gives you full control over key rotation, access auditing, and lifecycle management, which is exactly what a requirement for customer-managed encryption requires. Note that the key must exist in the same AWS Region as the log group and its key policy must grant CloudWatch Logs permission to generate a data key for encryption.
- ✗
Enable server-side encryption on the log group using the default CloudWatch Logs key.
Why it's wrong here
CloudWatch Logs already encrypts data at rest by default using an AWS-managed key that is automatically assigned to the log group. Choosing the 'default CloudWatch Logs key' does not introduce a customer-managed key and therefore does not satisfy a requirement for customer-controlled encryption. Even if you toggle a setting labeled 'server-side encryption', the log group continues to use the system-managed key, which offers no customer visibility into key usage or the ability to rotate or disable the key independently of AWS.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.