Courseiva
Incident and Event Response →mediumMultiple Select

DOP-C02 CloudWatch Alarm Practice Question

A company uses Amazon CloudWatch for monitoring. The operations team wants to receive an alert when an EC2 instance's status check fails for 2 consecutive minutes. Which THREE resources should the team configure? (Choose three.)

⚠ Common exam trap

A common trap is confusing CloudWatch Events with CloudWatch Alarms. CloudWatch Events are for event-driven actions based on state changes or schedules, not for monitoring metric thresholds over time. Metric alarms require the CloudWatch Alarm resource.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudWatch alarm

To alert when an EC2 instance's status check fails for 2 consecutive minutes, you need to create a CloudWatch alarm on the StatusCheckFailed metric (options C and D). The alarm needs to send notifications via an SNS topic (option E). Option A (CloudWatch Events rule) is not used for metric-based alerts; CloudWatch Events triggers on events or schedules, not metric thresholds. Option B (CloudWatch Logs) is for log data, not metrics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CloudWatch Events rule

    Why it's wrong here

    Amazon CloudWatch Events (now Amazon EventBridge) is designed for event-driven architectures: it matches patterns in AWS service events, API calls, or scheduled cron expressions, not for evaluating a numeric metric over a time window. An Events rule can react to an alarm's state change by invoking a Lambda or sending to an SNS topic, but it does not itself perform the threshold comparison. Therefore, it cannot replace a CloudWatch alarm for monitoring a metric like StatusCheckFailed.

  • ✗

    CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a service for ingesting, storing, and querying log data from EC2 instances and other resources. Log groups and log streams are not metric monitors; a metric filter can extract a custom metric from log events, but subsequent alerting still requires a CloudWatch alarm on that extracted metric. For the monitoring scenario described, the relevant metric (StatusCheckFailed) already exists as a standard CloudWatch metric, so CloudWatch Logs would never be consulted.

  • ✓

    CloudWatch alarm

    Why this is correct

    A CloudWatch alarm is the correct monitoring construct to watch a metric such as StatusCheckFailed or CPUUtilization. It evaluates the metric against a threshold over a specified number of evaluation periods and transitions to ALARM, OK, or INSUFFICIENT_DATA, then triggers a configured SNS action. The alarm is the central component that converts raw metric data into an operational notification, making it the appropriate mechanism for alerting on the instance's status check result.

  • ✓

    EC2 StatusCheckFailed metric

    Why this is correct

    The EC2 StatusCheckFailed metric (with SystemStatusCheckFailed and InstanceStatusCheckFailed variants) is the right metric to monitor because it reflects both underlying hardware/network failures and guest OS/application problems. EC2 publishes this metric to CloudWatch every minute, and by itself it offers visibility into instance health. It is correct as the data source for the monitoring pipeline, but only an alarm on this metric will produce a notification when a check fails, so it is a necessary but not sufficient part of the solution.

  • ✓

    Amazon SNS topic

    Why this is correct

    An Amazon SNS topic is the recommended notification endpoint for CloudWatch alarms: when the alarm enters ALARM state, it publishes a message to the topic, which then fans out via email, SMS, HTTP(S) endpoints, or Lambda. The correct design uses an SNS topic as the delivery mechanism in the monitoring pipeline, but the topic itself does not evaluate any metrics. Without a CloudWatch alarm publishing to it, the topic would never receive an operational alert.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.