DOP-C02 Incident and Event Response Practice Question
A company runs a critical application on a fleet of EC2 instances managed by an Auto Scaling group. The application generates logs that are sent to CloudWatch Logs using the CloudWatch agent. Recently, the operations team noticed that some instances are missing logs for certain periods. The CloudWatch agent is configured to batch log events and send them every 5 seconds. The instances have high CPU utilization (90%+) during the missing periods. The DevOps engineer suspects that the agent is being throttled or failing. Which of the following is the MOST likely cause and the BEST course of action?
⚠ Common exam trap
DOP-C02 often tests resource contention — candidates blame network or disk because logs are I/O, but the question explicitly states high CPU, pointing to agent starvation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The CloudWatch agent is being starved of CPU resources, causing it to drop logs. Increase the CPU credits or instance size.
When CPU utilization is sustained at 90%+, the CloudWatch agent competes for CPU and can be starved, causing it to drop or delay log batches. The agent buffers events in memory and on disk; under CPU starvation, the buffer may overflow or the agent may fail to flush within the 5-second interval. Increasing CPU credits (for burstable instances) or moving to a larger instance size gives the agent the resources it needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The network bandwidth is saturated, causing log delivery to fail. Increase instance network performance.
Why it's wrong here
Network saturation would typically manifest as CloudWatch Logs API call failures, connection timeouts, or a backlog of unsent log batches with corresponding `ClientError` or `Throttling` entries in the agent logs, not as clean, silently missing log periods. The provided evidence points to sustained high EC2 CPU utilization as the root cause, and upgrading network performance would not address CPU contention that prevents the agent from collecting and forwarding its buffers. A missing period in CloudWatch Logs alongside high CPU is far more consistent with the agent being unable to schedule its collection loop than with a network bottleneck.
- ✗
The CloudWatch Logs retention policy is set to 1 day, so older logs are deleted. Increase retention.
Why it's wrong here
CloudWatch Logs retention policy controls how long ingested log events are retained before deletion; it has no effect on whether new log events are delivered or appear in near real-time. A 1-day retention would simply cause logs older than one day to be expunged, but you would still see a continuous stream of recent events unless delivery itself stopped. Since the problem is missing periods of logs while high CPU is observed, retention is a red herring — it does not cause gaps in the current data stream.
- ✓
The CloudWatch agent is being starved of CPU resources, causing it to drop logs. Increase the CPU credits or instance size.
Why this is correct
The CloudWatch agent runs as a separate user-space daemon that periodically reads log files and sends them to the CloudWatch Logs API. When the host's CPU is saturated — especially on T-series instances with exhausted CPU credits — the agent's log collection and flush loop can be delayed or preempted for long enough that it begins dropping buffered events to avoid creating an ever-growing backlog. Increasing instance size or CPU credits gives the agent the scheduling time it needs to reliably process and upload log batches, directly resolving the observed missing periods.
- ✗
The instances are running out of disk space, preventing log buffering. Add more EBS volume space.
Why it's wrong here
Disk exhaustion on the instance would typically produce `No space left on device` errors when the agent attempts to write its state file or when the application itself cannot append to the monitored log file, often accompanied by the log file size remaining static and a flooded agent log with I/O errors. The agent does not rely on free EBS space to buffer logs for delivery — it uses in-memory batching with an optional local queue that is much smaller and not the likely failure point here. Adding EBS volume space would address capacity concerns but would do nothing to fix the CPU starvation that prevents the agent from running its collection thread.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.