DOP-C02 Monitoring and Logging Practice Question
A company wants to monitor network traffic to and from its VPC for security analysis. It needs to capture IP traffic information, including accepted and rejected connection attempts, and store the data in S3 for long-term analysis. Which AWS service should be used?
⚠ Common exam trap
Candidates often confuse GuardDuty (which analyzes traffic and produces findings) with VPC Flow Logs (which capture the raw traffic records), so candidates pick GuardDuty thinking it stores traffic in S3.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon VPC Flow Logs
Amazon VPC Flow Logs capture IP traffic metadata for ENIs, subnets, or VPCs, including ACCEPT and REJECT records, and can be published directly to Amazon S3 for long-term retention and Athena analysis. This matches the requirement to capture accepted and rejected connection attempts and store them in S3. Flow Logs are the standard DOP-C02 answer for VPC-level network traffic visibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a service for collecting, storing, and monitoring log files from resources like EC2 instances, Lambda functions, and other AWS services, as well as on-premises applications. While VPC Flow Logs can be delivered to CloudWatch Logs for real-time metric filters and alarms, CloudWatch Logs alone cannot capture or produce network flow data because it relies on other services to generate the logs. So it is a destination and monitoring platform, not the service that provides network traffic visibility.
- ✓
Amazon VPC Flow Logs
Why this is correct
Amazon VPC Flow Logs is the native service that captures IP traffic metadata for network interfaces in a VPC, including source and destination IPs, ports, protocol, and packet/byte counts for both accepted and rejected traffic. These logs can be published to Amazon S3 or CloudWatch Logs for long-term retention and analysis with services like Athena. As a result, VPC Flow Logs provides the flow-level visibility needed to monitor network traffic to and from a VPC.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a managed threat detection service that uses machine learning and anomaly detection to identify unauthorized behavior. It ingests and analyzes telemetry from sources such as VPC Flow Logs, DNS query logs, and CloudTrail events, but it does not generate or store raw network traffic data itself. Therefore, GuardDuty is a consumer of network logs, not the source you would enable to monitor traffic flows.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API calls and account activity across AWS, capturing governance, compliance, and operational audit information such as who made a request, which service was called, and what parameters were used. This data plane visibility is limited to control-plane API events and does not include the network-level 5-tuple information, byte counts, or packet metadata associated with traffic flowing through a VPC. Consequently, CloudTrail cannot be used to monitor raw network traffic.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.