DOP-C02 Monitoring and Logging Practice Question
A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The operations team wants to analyze application access logs and error rates. They need to identify the top IP addresses making requests, as well as the distribution of HTTP status codes over time. Which THREE steps should the team take to achieve this? (Select THREE.)
⚠ Common exam trap
A common mix-up: candidates confuse AWS CloudTrail (management plane logging) with application-level access logging, leading candidates to select CloudTrail instead of ALB access logs for HTTP request analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable access logs on the Application Load Balancer and store them in an Amazon S3 bucket.
Enabling access logs on the Application Load Balancer and storing them in an S3 bucket captures detailed HTTP request data, including client IPs, request paths, and HTTP status codes. This raw log data is essential for analyzing top IP addresses and status code distributions over time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable access logs on the Application Load Balancer and store them in an Amazon S3 bucket.
Why this is correct
Enabling access logs on the Application Load Balancer is the foundational step; it delivers a raw, per-request log file containing the client IP, request URI, User-Agent, and HTTP status code for every request handled by the ALB. These logs are written in gzip-compressed files to an S3 bucket you specify, and S3 provides durable, queryable storage. Without this first step, no HTTP-level transaction data exists in S3, making any subsequent log analysis or querying impossible. This is why enabling ALB access logs is the correct primary action.
- ✓
Use Amazon CloudWatch Logs Insights to run queries on the access logs.
Why this is correct
Amazon CloudWatch Logs Insights is a query engine that lets you run SQL-like queries against log data that has been ingested into CloudWatch Logs. Once ALB access logs are sent to S3, you can use a subscription or Lambda function to stream them into CloudWatch Logs, and then Logs Insights can parse the access log fields to aggregate top IPs by request count or calculate the distribution of HTTP status codes. It provides interactive, fast querying without the need to manage your own log analytics infrastructure. This is a valid analysis technique for the log data, distinct from Contributor Insights which focuses on identifying top contributors.
- ✗
Enable AWS CloudTrail to log all API calls.
Why it's wrong here
AWS CloudTrail is designed to record and monitor API activity within your AWS account, such as calls made to EC2, IAM, or S3 APIs by users, roles, or services. It captures the identity, API call parameters, and response elements for control-plane and selected data-plane operations, but it does not capture the HTTP requests or responses received by your Application Load Balancer. Therefore, CloudTrail cannot provide the client IP addresses accessing your web application or the HTTP status codes returned by the application, making it an incorrect choice for this analysis. It is a governance and auditing tool, not a web traffic logging service.
- ✗
Enable VPC Flow Logs to capture IP traffic data.
Why it's wrong here
VPC Flow Logs capture information about IP traffic that passes through your VPC, specifically at the network interface level, including source/destination IP, source/destination port, protocol, and the number of packets and bytes transferred. While this can show which IPs are sending traffic to the load balancer, it does not include the application-layer details such as the HTTP status code returned, the request URI, or the actual HTTP method. Without status code information, you cannot analyze response code distributions to identify client or server errors. Flow Logs are useful for network diagnostics and security analysis but are insufficient for HTTP-level application analysis.
- ✓
Use Amazon CloudWatch Contributor Insights to analyze the top IP addresses.
Why this is correct
Amazon CloudWatch Contributor Insights is a service that automatically analyzes log data to identify the top contributors to a particular metric, such as the top IP addresses generating requests. You create a rule that defines the fields to analyze (e.g., client IP from ALB access logs) and a time period, and Contributor Insights maintains high-cardinality top contributors in memory, giving you charts of the most active IPs. It is a purpose-built tool for answering 'who is the top talker' questions and works well with ALB access logs that have been sent to CloudWatch Logs. While it can identify top IPs, it is not designed to compute full status-code distribution, making it complementary but not the sole correct answer.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.