Courseiva

DOP-C02 Incident and Event Response Practice Question

A company stores application logs in Amazon CloudWatch Logs. During an incident, an engineer needs to search across multiple log groups for a specific request ID from the last hour and then preserve the findings for a post-incident review. Which approach meets both needs with the least operational effort?

⚠ Common exam trap

The trap here is reaching for S3 export and Athena for a quick, time-bounded log search, when CloudWatch Logs Insights already queries multiple log groups directly and can retain the results.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use CloudWatch Logs Insights to query the log groups for the request ID and save the query results for the post-incident review.

CloudWatch Logs Insights is designed to run interactive queries across one or more log groups over a specified time range, which fits searching the last hour of logs for a request ID. Because it also lets you save or export query results, it satisfies the need to preserve findings for a post-incident review with minimal setup and no additional infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a CloudWatch Logs subscription filter that streams matching events to AWS Lambda for processing.

    Why it's wrong here

    A subscription filter processes new events as they arrive and does not search historical data from the last hour. Building a Lambda consumer to capture and store matches adds moving parts and latency, which does not meet the immediate search need or the simple preservation requirement.

  • ✗

    Enable CloudTrail logging for the log groups and search the trail for the request ID.

    Why it's wrong here

    CloudTrail records API activity, not application log content, so a request ID written by the application will not appear there. Enabling it adds audit logging cost and still leaves the engineer unable to find the request ID or preserve relevant application log findings for review.

  • ✓

    Use CloudWatch Logs Insights to query the log groups for the request ID and save the query results for the post-incident review.

    Why this is correct

    CloudWatch Logs Insights queries multiple log groups at once with a time range and supports saving or exporting results, directly matching the search and preservation requirements. It requires no infrastructure, so it is the lowest-effort option for finding the request ID and retaining the findings for review.

  • ✗

    Export all log groups to Amazon S3 and use Amazon Athena to search for the request ID.

    Why it's wrong here

    Exporting logs to S3 and querying with Athena can search the data, but it introduces export tasks, a table schema, and storage management, which is far more operational effort than needed for a one-hour search. It is better suited to long-term, large-scale analytics than a rapid incident lookup.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.