Courseiva
Monitoring and Logging →hardMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

A company uses AWS CloudTrail to monitor API activity. The DevOps team needs to ensure that any deletion of an S3 bucket is detected in real time and triggers an automated response. Which combination of AWS services should be used to meet these requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Send CloudTrail logs to CloudWatch Logs, create a CloudWatch Events rule matching the DeleteBucket event, and target a Lambda function.

CloudTrail logs can be sent to CloudWatch Logs, and a CloudWatch Events rule (now Amazon EventBridge) can be created to match the DeleteBucket event and trigger a Lambda function for automated response in real time. Option A is incorrect because CloudWatch Logs monitors log data, but a metric filter on DeleteBucket events in CloudTrail logs can trigger an alarm, but that is not as direct as EventBridge. More importantly, CloudWatch Logs metric filters have latency and are not the best for real-time response. Option B is incorrect because S3 event notifications are for operations on objects, not for bucket-level operations like deletion. Option C is incorrect because while CloudTrail can deliver logs to S3, S3 event notifications are not triggered by CloudTrail log file delivery; they are for object-level events. Using EventBridge directly with CloudTrail is the correct real-time approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use CloudWatch Logs to monitor the logs, and create a metric filter to trigger an alarm when the DeleteBucket event appears.

    Why it's wrong here

    A metric filter on the CloudWatch Logs log group can identify DeleteBucket entries, but CloudWatch alarms only change state and publish to an SNS topic; they do not directly execute an automated response. The alarm would require a human or a separate subscriber to act on the notification, and while you can configure an SNS subscription to invoke Lambda, that is an indirect pattern and not a native alarm-to-Lambda target. More importantly, the question asks for an automated response triggered by the event itself, so relying on a metric alarm adds latency and an unnecessary layer compared to an event-driven rule.

  • ✗

    Configure S3 event notifications to send to an SQS queue, and poll the queue with a Lambda function.

    Why it's wrong here

    S3 event notifications are limited to object-level events such as ObjectCreated and ObjectRemoved; they do not emit events for bucket management actions like DeleteBucket. Even if you set up an SQS queue as the destination and poll it with Lambda, the S3 service will never generate a notification for a bucket deletion, so the Lambda function will never be invoked. This option conflates S3's data-plane notifications with control-plane API activity, which CloudTrail (not S3 events) captures.

  • ✗

    Configure CloudTrail to deliver logs to an S3 bucket, and use S3 event notifications to invoke a Lambda function.

    Why it's wrong here

    While CloudTrail can deliver log files to S3, the delivery is batched and typically happens up to 5 minutes after the recorded activity, so it is not near real-time. S3 event notifications on the log bucket would fire when the new log file is written, but that still requires the Lambda function to load, parse, and extract the DeleteBucket event from a multi-event JSON file, adding complexity and latency. The correct architecture instead uses CloudTrail's native integration with CloudWatch Logs for immediate event delivery.

  • ✓

    Send CloudTrail logs to CloudWatch Logs, create a CloudWatch Events rule matching the DeleteBucket event, and target a Lambda function.

    Why this is correct

    Configuring CloudTrail to stream events to CloudWatch Logs provides near-real-time delivery of management events, including DeleteBucket. A CloudWatch Events (EventBridge) rule can use an event pattern to match the specific DeleteBucket API call and directly target a Lambda function as its target. This creates a low-latency, event-driven pipeline that automatically invokes the Lambda function without polling or human intervention, enabling immediate remediation or alerting.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.