Courseiva
Monitoring and Logging →hardMultiple Select

DOP-C02 Monitoring and Logging Practice Question

A company runs a critical application on Amazon EKS. The operations team needs to monitor the health of the Kubernetes cluster and the applications running on it. Which THREE services can be used together to achieve comprehensive monitoring? (Choose THREE.)

⚠ Common exam trap

DOP-C02 often tests whether candidates confuse network/audit logging services (VPC Flow Logs, CloudTrail) with observability services that actually surface application and container health, causing them to pick the wrong 'monitoring' trio.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS X-Ray

AWS X-Ray (A) is correct because it provides distributed tracing for applications running on EKS, letting the team follow requests across microservices and pinpoint latency or errors in the application layer. Amazon CloudWatch Container Insights (D) is correct because it collects and aggregates container-level metrics and logs (CPU, memory, disk, network) from EKS nodes and pods, giving cluster and workload health visibility. Amazon Managed Service for Prometheus (E) is correct because it is a Prometheus-compatible managed service that scrapes and stores Kubernetes metrics and supports alerting, complementing Container Insights for deeper, PromQL-based monitoring. Amazon VPC Flow Logs (B) only captures IP traffic metadata at the network interface level and does not provide application or Kubernetes-level health insight. AWS CloudTrail (C) records AWS API activity for auditing and governance, not runtime health or performance monitoring of the cluster or its applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS X-Ray

    Why this is correct

    AWS X-Ray traces requests as they flow through a distributed application, providing end-to-end visibility into latencies, errors, and dependencies across microservices running on Amazon EKS. By instrumenting the application with the X-Ray SDK, you can identify the specific service or database call causing performance degradation. X-Ray's service graph and trace timelines reveal exactly where requests are spending time, making it the correct choice for troubleshooting application-level performance issues.

  • ✗

    Amazon VPC Flow Logs

    Why it's wrong here

    Amazon VPC Flow Logs capture metadata about IP traffic - source and destination addresses, ports, protocol, and whether packets were accepted or rejected - but they reveal nothing about the health or behavior of applications running on those network paths. While they can help diagnose connectivity problems like security group denial or misconfigured routes, they cannot tell you if an application is returning errors or experiencing high latency. Therefore, VPC Flow Logs are not a suitable tool for monitoring application health on EKS.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records a history of API calls made to AWS services, such as EKS control plane actions, for auditing and compliance purposes. It can show who made which API calls and when, but it provides no insight into the runtime performance, metrics, or resource utilization of containers or pods. Consequently, CloudTrail is irrelevant for monitoring application health and cannot detect issues like pod crashes or request failures.

  • ✓

    Amazon CloudWatch Container Insights

    Why this is correct

    Amazon CloudWatch Container Insights collects, aggregates, and summarizes metrics and logs from Amazon EKS, including resource utilization data at the cluster, node, pod, and container levels. It automatically detects EKS clusters and provides prebuilt dashboards for CPU, memory, disk, and network performance, integrating with CloudWatch alarms to signal resource saturation. This infrastructure and container-level telemetry is essential for monitoring the health and capacity of the platform, though it does not trace individual requests like X-Ray.

  • ✓

    Amazon Managed Service for Prometheus

    Why this is correct

    Amazon Managed Service for Prometheus is a fully managed, Prometheus-compatible monitoring solution designed for Kubernetes workloads, enabling you to scrape metrics from EKS using the Prometheus server's pull model. With PromQL, you can query application-level custom metrics by deploying Prometheus client libraries and exporters, and you can create alerting rules for anomaly detection. This gives you a scalable, reliable monitoring stack without managing the underlying Prometheus infrastructure, making it a powerful tool for application and infrastructure monitoring on EKS.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.