DOP-C02 Monitoring and Logging Practice Question
A company uses Amazon CloudWatch Logs to centralize logs from multiple EC2 instances running a web application. The DevOps team needs to create a metric filter that parses logs for HTTP status codes (e.g., 4xx and 5xx) and increment a metric. Additionally, they need to create a CloudWatch alarm on the error count. Which of the following are required to achieve this? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define the metric filter pattern to match HTTP status codes in the log entries.
The correct answers are B and C. A metric filter must be defined on a log group (option C) to extract metrics, and the filter pattern must match the HTTP status codes in the log entries (option B). Option A is not required because CloudWatch Logs can publish metrics without an additional IAM role; the log group already has sufficient permissions. Option D is incorrect because subscription filters are for streaming logs to other destinations, not for creating metrics. Option E is not required because the CloudWatch Logs agent or the unified CloudWatch agent can send logs, but the question does not specify which agent; the default agent suffices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM role that allows CloudWatch Logs to read the log data and publish metrics.
Why it's wrong here
No additional IAM role is needed for CloudWatch Logs to perform metric extraction; the EC2 instance profile or IAM role used by the CloudWatch agent already provides permissions like logs:PutLogEvents and logs:CreateLogStream. Metric filters are evaluated by the CloudWatch Logs service during log ingestion, so the service itself does not require a separate IAM role to read your log data or publish the extracted metrics. If a subscription were used, the Lambda function would need an execution role, but for a native metric filter, the role you are describing is irrelevant.
- ✓
Define the metric filter pattern to match HTTP status codes in the log entries.
Why this is correct
The metric filter pattern is the core of the extraction process: it defines exactly which log events should be matched and how the metric value is derived, such as counting occurrences of a 4xx or 5xx status code. For example, a pattern like "[*, _, _, status_code]" or a JSON pattern like "{ $.status_code = 4* }" is needed to parse the relevant field correctly from the log entry. If the pattern is not defined, CloudWatch Logs has no way to know which log lines correspond to an HTTP status code or what value to emit for the CloudWatch metric.
- ✓
Create a metric filter in CloudWatch Logs on the log group that contains the application logs.
Why this is correct
A metric filter must be attached to the specific log group that retains the application logs, because the filter is evaluated on every log event delivered to that group. Once you create the metric filter on the correct log group, CloudWatch Logs automatically applies the filter pattern to incoming log data and continuously updates the associated CloudWatch metric. Without this step, no metric data is generated, even though the application logs themselves are present.
- ✗
Configure a subscription filter to forward the logs to a Lambda function that creates the metric.
Why it's wrong here
A subscription filter streams matching log events to a destination such as AWS Lambda, Amazon Kinesis, or Amazon OpenSearch Service; it does not directly create CloudWatch metrics. While you could write a Lambda function that parses the stream and calls PutMetricData, this approach adds unnecessary compute, complexity, and cost when a metric filter can natively extract the same metric without any code. For the stated goal of creating a metric from logs, a metric filter is the correct, built-in mechanism; a subscription filter is not a step in that process.
- ✗
Install the CloudWatch Agent on the EC2 instances to send the logs.
Why it's wrong here
Installing the CloudWatch Agent is about log collection and delivery to CloudWatch Logs, not about metric extraction. The agent runs on EC2 instances to send log data, but the question already states that logs are centralized in CloudWatch Logs; at that point, the metric filter performs the extraction, not the agent. Choosing this option conflates ingestion with metric creation, and it is not a required step if logs are already being sent to CloudWatch Logs.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is using Amazon CloudWatch Logs to collect logs from multiple applications. The DevOps team wants to create a metric filter to count the number of ERROR log entries and trigger an alarm when the count exceeds 10 in 5 minutes. Which TWO steps must the team take? (Choose TWO.)
medium- A.Create a subscription filter to stream logs to Amazon Kinesis Data Firehose.
- ✓ B.Create a metric filter on the log group that extracts ERROR count.
- ✓ C.Create a CloudWatch alarm on the metric with the threshold of 10.
- D.Set a log group retention policy to retain logs indefinitely.
- E.Create a CloudWatch dashboard to visualize the ERROR count.
Why B: Option B is correct because a CloudWatch Logs metric filter must be defined on the log group to parse log events and publish a custom metric that counts occurrences of the ERROR pattern; this is the mechanism that turns raw log data into a numeric CloudWatch metric. Option C is correct because once the metric exists, a CloudWatch alarm is created against that metric with a threshold of 10 and an evaluation period of 5 minutes so it can trigger when the count exceeds the limit. Option A is not needed because subscription filters stream logs to destinations like Kinesis Data Firehose for processing, not for creating metrics or alarms. Option D is irrelevant because retention policy only controls how long log events are stored and does not affect metric filtering or alarming. Option E is unnecessary because a dashboard only visualizes metrics and does not create the metric or trigger the alarm.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.