Courseiva
Monitoring and Logging →mediumMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

A company uses AWS CloudFormation to deploy infrastructure. The DevOps team needs to receive notifications when stack creation fails. Which approach should be used to automate this monitoring?

⚠ Common exam trap

DOP-C02 often tests the misconception that CloudTrail or CloudWatch Logs can directly filter CloudFormation failure statuses; candidates must recognize EventBridge as the native event source for stack status changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CloudWatch Events rule that matches CloudFormation 'CREATE_FAILED' stack events and targets an SNS topic.

CloudWatch Events (now Amazon EventBridge) can match CloudFormation stack events with the detail-type 'CloudFormation Stack Status Change' and filter for CREATE_FAILED, then target an SNS topic for notification. This is the native, event-driven approach for automating failure alerts without polling or log parsing. It provides near-real-time notification with minimal configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a CloudWatch Events rule that matches CloudFormation 'CREATE_FAILED' stack events and targets an SNS topic.

    Why this is correct

    CloudFormation emits stack status change events to CloudWatch Events (Amazon EventBridge) whenever a stack transitions to a terminal state. A rule can filter for detail-type 'CloudFormation Stack Status Change' and the 'status-detail' of 'CREATE_FAILED', then route the event to an SNS topic. This is the native, event-driven mechanism for receiving notifications about stack creation failures, and it includes the stack name and status in the event payload.

  • ✗

    Use AWS Config rules to detect failed stack creations.

    Why it's wrong here

    AWS Config is a service for assessing resource configuration compliance against rules, not for observing CloudFormation operation lifecycle. It can detect that a provisioned resource violates a rule, but it has no visibility into the outcome of a stack creation or the CREATE_FAILED status emitted by CloudFormation. Moreover, a failed stack may never produce all resources or may leave partial resources, so Config cannot reliably signal the failure event itself. For real-time notification of a stack failure, you need an event-driven integration.

  • ✗

    Enable CloudTrail and create a metric filter for 'CreateStack' API calls.

    Why it's wrong here

    CloudTrail records the 'CreateStack' API call at the moment a user requests stack creation, which only indicates that the request was accepted, not whether the stack subsequently reached 'CREATE_COMPLETE' or 'CREATE_FAILED'. The failure status is an asynchronous stack event that occurs later, so a metric filter on the CreateStack API call would over-report creations and miss the actual failure signal. CloudTrail alone cannot be used to trigger on the final stack status; you need CloudWatch Events for the status change.

  • ✗

    Stream CloudFormation logs to CloudWatch Logs and create a metric filter for 'CREATE_FAILED'.

    Why it's wrong here

    CloudFormation does not automatically stream its stack events or logs to CloudWatch Logs; stack events are published to CloudWatch Events/EventBridge, not to a log group. Without a log stream containing 'CREATE_FAILED' entries, a metric filter has nothing to match. While you could technically create a custom mechanism to forward CloudFormation events to logs, the native and simpler integration is an EventBridge rule targeting SNS. This option is incorrect because it relies on a non-existent default logging behavior.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.