Courseiva

DOP-C02 Resilient Cloud Solutions Practice Question

A company runs a critical application on Amazon EC2 instances in an Auto Scaling group. The application generates logs that are sent to Amazon CloudWatch Logs. The DevOps team needs to configure a metric filter to monitor for error patterns and trigger an alarm when the error rate exceeds 5% of total requests over a 5-minute period. Which TWO steps should the team take? (Choose TWO.)

⚠ Common exam trap

DOP-C02 often tests the difference between metric filters (which auto-publish metrics from log patterns) and manually created metrics or subscription filters, catching candidates who think they must create the metric separately or route logs through Lambda.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a metric filter on the log group to count occurrences of the error pattern.

Option B is correct because a CloudWatch Logs metric filter is the mechanism that scans log events in a log group for a specified pattern (for example, "ERROR") and increments a custom metric each time the pattern matches, which is exactly how the error count is derived from the application logs. Option E is correct because the requirement is an error rate (a percentage), not a raw count, so the alarm must use a CloudWatch metric math expression that divides the error-count metric by the total-request-count metric and compares the result against the 5% threshold over the 5-minute evaluation period. Option A is not needed because metric filters are applied to an existing log group that already receives the application logs; you do not create a separate log group for the metric. Option C is wrong because subscription filters stream log data to destinations such as Lambda or Kinesis for real-time processing, which is unnecessary when CloudWatch metric filters and metric math can compute the rate natively. Option D is wrong because the metric is created automatically by the metric filter defined in Option B, so a separate manual metric creation step is redundant.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a CloudWatch Logs log group for the error metric.

    Why it's wrong here

    A log group is the container that already holds the application's log streams; metric filters are attached to an existing log group and cannot be created as a separate group. It is tempting because organising logs into groups is normal CloudWatch practise, and creating a dedicated group would be right when isolating a new application's logs from others.

  • ✓

    Create a metric filter on the log group to count occurrences of the error pattern.

    Why this is correct

    CloudWatch metric filters scan log events for a pattern and publish a numeric metric each time it matches. Counting error-pattern occurrences produces the error count metric that the subsequent math expression and alarm consume to compute the error rate.

  • ✗

    Create a CloudWatch Logs subscription filter to stream errors to a Lambda function that calculates the error rate.

    Why it's wrong here

    A CloudWatch Logs subscription filter streams log data in real time to a Lambda function, but it does not provide the metric filter needed to continuously evaluate the error rate against a threshold over a 5-minute window. The requirement is for a metric filter that emits a metric to CloudWatch Metrics, enabling a CloudWatch Alarm to compare the error proportion against total requests. This option is tempting because subscription filters are commonly used for real-time log processing and alerting, and would be correct if the team needed to perform custom, stateless transformations on each log event rather than aggregate a rolling error-rate metric.

  • ✗

    Create a CloudWatch metric for the error count.

    Why it's wrong here

    Metric filters publish data into a metric namespace automatically; manually creating a metric for error count produces no data because nothing writes to it. It is tempting because alarms must reference a metric, and defining a custom metric is correct when an application publishes its own values via the PutMetricData API.

  • ✓

    Create a CloudWatch alarm that uses a math expression to calculate the error rate (error count / total request count) and compare it to the threshold of 5%.

    Why this is correct

    A metric filter alone counts raw occurrences; converting counts into a percentage requires a metric math expression. The alarm evaluates error count divided by total request count against the 5% threshold over the 5-minute window, satisfying the error-rate condition.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.