DOP-C02 Monitoring and Logging Practice Question
A DevOps engineer is configuring CloudWatch Logs for a Lambda function that processes streaming data from Kinesis. The function sometimes fails due to memory exhaustion. The engineer wants to ensure that logs from the function are shipped to CloudWatch Logs even when the function fails. Which configuration should be used?
⚠ Common exam trap
The trap here is that candidates may overthink the solution and assume a separate agent or service is required for log shipping in failure scenarios, when in fact Lambda’s native stdout/stderr capture works automatically and reliably even on invocation failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the Lambda function writes logs to stdout or stderr; CloudWatch Logs will automatically capture them
Lambda functions automatically send all output written to stdout (via print or console.log) and stderr to CloudWatch Logs, regardless of whether the function succeeds or fails. This is a built-in behavior of the Lambda runtime, so no additional agents or configuration are needed to capture logs from a failed invocation due to memory exhaustion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Kinesis Agent on the Lambda execution environment to stream logs to CloudWatch Logs
Why it's wrong here
Incorrect. The Lambda execution environment is a managed, immutable runtime sandbox that only includes the Lambda runtime, your function code, and its declared dependencies. A Kinesis Agent is a standalone Amazon-provided daemon designed to run on EC2 or on-premises hosts, not something you can install or configure inside an ephemeral Lambda container. Moreover, the Lambda service itself already integrates with CloudWatch Logs via the runtime's logging mechanism, so adding an extra streaming layer is both impossible and unnecessary.
- ✗
Install the CloudWatch Logs agent on the Lambda function to continuously send logs
Why it's wrong here
Incorrect. AWS Lambda functions run in stateless, short-lived execution environments that are provisioned and destroyed by the Lambda service; you have no SSH access and no ability to install, start, or manage system services like the CloudWatch Logs agent. The agent is meant for persistent EC2 instances or on-premises servers, not for Lambda's event-driven, container-based model. Lambda's native runtime automatically forwards logs written to stdout/stderr to CloudWatch Logs, so agent installation would be redundant even if it were technically feasible.
- ✗
Enable detailed CloudWatch metrics for the Lambda function
Why it's wrong here
Incorrect. Enabling detailed CloudWatch metrics for a Lambda function (e.g., Provisioned Concurrency metrics or enhanced built-in metrics) provides operational telemetry like duration, invocations, errors, throttles, and iterator age, but it does not capture log data. Metrics are numerical time-series data, not log events, and they cannot surface function print statements, stack traces, or custom log messages. To get logs, you must rely on Lambda's built-in logging integration, not on enabling additional metric granularity.
- ✓
Ensure the Lambda function writes logs to stdout or stderr; CloudWatch Logs will automatically capture them
Why this is correct
Correct. The Lambda runtime (for both the AWS-provided runtimes and custom runtimes that use the Runtime API) intercepts all output written to stdout and stderr and automatically streams it to CloudWatch Logs under the log group /aws/lambda/<function-name>. This happens regardless of whether the function completes successfully or crashes, so logging to stdout/stderr is the standard, documented way to generate logs. Each invocation gets a unique log stream, and the exact log line format can include request IDs if you also log the Lambda context object, but the capture itself requires no extra configuration beyond the Lambda service execution role's CloudWatch Logs permissions.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.