Courseiva
Monitoring and Logging →hardMultiple Select

DOP-C02 Monitoring and Logging Practice Question

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application logs show that some requests are timing out. The team needs to identify the source of the issue. Which TWO steps should they take?

⚠ Common exam trap

DOP-C02 often tests the distinction between logging services: candidates may confuse VPC Flow Logs (network-level) with ALB access logs (application-level) or assume CloudTrail captures performance data, leading to wrong selections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable ALB access logs and analyze them.

Option A is correct because ALB access logs capture detailed per-request information such as request processing time, target response time, and the specific error codes (e.g., 504 Gateway Timeout) returned by the load balancer, which directly helps pinpoint whether timeouts originate at the ALB or the backend targets. Option D is correct because CloudWatch metrics for the ALB, particularly 'TargetResponseTime' and 'RequestCount', reveal latency trends and traffic patterns that indicate whether targets are slow or overloaded, helping isolate the source of the timeouts. Option B is not appropriate because VPC Flow Logs only capture IP-level metadata (source/destination, ports, accept/reject) and cannot show HTTP-layer timing or application-level errors. Option C is not appropriate because AWS WAF logs only record requests that match or are blocked by WAF rules, and the scenario does not indicate WAF is in use or that requests are being blocked. Option E is not appropriate because CloudTrail records AWS API calls for auditing, not application request behavior or latency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable ALB access logs and analyze them.

    Why this is correct

    ALB access logs are the authoritative source for request-level diagnostics because they capture every HTTP request processed by the load balancer, including the target processing time, request processing time, HTTP status, and client/user-agent data. Analyzing these logs lets you identify exactly which requests experienced slow responses or timeouts, isolate problematic targets by IP or URL pattern, and correlate with backend health. Unlike aggregated metrics, access logs provide per-request granularity that is essential for root-causing intermittent timeout issues.

  • ✗

    Enable VPC Flow Logs to capture network traffic.

    Why it's wrong here

    VPC Flow Logs only capture network flow metadata, such as source/destination IP addresses, ports, protocols, and aggregated packet/byte counts over sampled intervals. They do not include HTTP request lines, status codes, or application-layer response timing, so they cannot distinguish a request that timed out from one that completed quickly. While flow logs can show whether traffic reached a target, they cannot expose the application latency or timeout behavior that this question is investigating.

  • ✗

    Enable AWS WAF logs to inspect HTTP requests.

    Why it's wrong here

    AWS WAF logs are generated when an HTTP request is inspected by WAF rules, and they mainly record whether a request was allowed or blocked, the rule matched, and the originating IP. Requests that do not trigger a WAF rule may not appear in WAF logs, and WAF logs do not contain target response time, backend processing time, or final status codes. Thus, they provide security control visibility but are not a general-purpose logging sink for application performance and timeout analysis.

  • ✓

    Review CloudWatch metrics for the ALB, such as 'RequestCount' and 'TargetResponseTime'.

    Why this is correct

    CloudWatch ALB metrics such as RequestCount and TargetResponseTime provide aggregated time-series data that can reveal broad patterns like increasing average or p99 latency across the fleet. However, these metrics are statistical summaries that do not include individual request URLs, client identities, or a breakdown of which specific target is slow for a given request. You can use them for alarms and trend analysis, but you need access logs to drill down into the exact root cause of a timeout.

  • ✗

    Enable AWS CloudTrail to log all API calls.

    Why it's wrong here

    AWS CloudTrail records management-plane (control plane) API calls made through the AWS console, SDK, or CLI—for example, CreateLoadBalancer, ModifyLoadBalancerAttributes, or AttachInstances. It does not intercept or record data-plane HTTP traffic that flows through the ALB to backend EC2 instances, nor does it capture request/response payloads or application-level timing. Therefore, CloudTrail is useful for auditing configuration changes, but it cannot help diagnose application timeouts or performance issues.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.