DOP-C02 Monitoring and Logging Practice Question
A DevOps engineer is designing a centralized logging solution for a multi-account AWS environment. The solution must be cost-effective and provide real-time log analysis. Which THREE services should they consider?
⚠ Common exam trap
The trap is selecting S3 as an analysis service or CloudTrail as a general log source — candidates must distinguish storage vs. analysis and audit logs vs. application logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon OpenSearch Service (Elasticsearch)
Amazon CloudWatch Logs (D) is correct because it is the native AWS service for collecting, storing, and monitoring log data from EC2 instances, Lambda functions, and other AWS resources, and it supports real-time metric filters and subscription filters for analysis. Amazon Kinesis Data Firehose (B) is correct because it reliably streams log data in near real-time to destinations such as Amazon S3, Amazon OpenSearch Service, or Splunk, and it can transform and batch records cost-effectively. Amazon OpenSearch Service (A) is correct because it provides real-time search, analytics, and visualization of log data via Kibana, making it ideal for interactive log analysis in a centralized multi-account setup. Amazon S3 (C) is not marked correct because, while it is a cost-effective storage destination for logs, it is not a real-time analysis service on its own. AWS CloudTrail (E) is not marked correct because it records API activity and account events for auditing, not application or system log aggregation and real-time analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon OpenSearch Service (Elasticsearch)
Why this is correct
Amazon OpenSearch Service provides the interactive search and visualization layer for a centralized logging solution. Logs ingested from Firehose, CloudWatch Logs subscriptions, or Logstash are indexed and available for real-time queries, aggregations, and Kibana dashboards, making it the correct target for log analytics. Unlike object storage or API audit trails, OpenSearch supports full-text search, ad hoc filtering, and anomaly detection across massive log volumes.
- ✓
Amazon Kinesis Data Firehose
Why this is correct
Amazon Kinesis Data Firehose is a fully managed streaming ingestion service that reliably buffers, transforms (e.g., via Lambda), compresses, and encrypts log records before delivering them to destinations such as Amazon OpenSearch Service, S3, or Redshift. It is correct because it decouples log producers from the analytics backend and scales automatically to handle traffic spikes, enabling near-real-time delivery into OpenSearch for analysis. However, Firehose itself does not store or query logs; it is the pipeline, not the analytics engine.
- ✗
Amazon S3
Why it's wrong here
Amazon S3 is an object storage service suited for durable, cost-effective log archival and long-term retention, not for interactive or real-time log analysis. While you can use S3 Select or Athena to run occasional SQL queries, S3 lacks built-in indexing, continuous query capability, and low-latency dashboards, so relying solely on S3 does not satisfy a centralized logging solution requiring search and analysis. Therefore, S3 is wrong in this context because it addresses storage, not analysis.
- ✓
Amazon CloudWatch Logs
Why this is correct
Amazon CloudWatch Logs can centralize logs from multiple AWS accounts and regions by using cross-account log subscriptions, log destinations, and Organizations log aggregation, giving operations teams a single place for monitoring, alarms, and basic metric filters. It is a correct component because it collects and retains application and system logs natively without deploying agents, and it can stream those logs to Kinesis Data Firehose or OpenSearch for deeper analysis. However, its query language and performance are optimized for operational monitoring rather than full-text log analytics.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records only API activity and account-level actions, such as who called which AWS API, from which IP address, and when, for governance and security auditing. It does not capture application stdout, web server access logs, OS syslogs, or database logs, so it cannot serve as a general-purpose centralized logging solution. While CloudTrail logs are valuable for security and compliance, they address audit trails rather than operational log aggregation and analysis.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A DevOps team is setting up centralized logging for a multi-account AWS environment. They want to aggregate logs from all accounts into a single S3 bucket. Which services should be used to achieve this? (Choose TWO.)
medium- ✓ A.AWS CloudTrail
- B.AWS Config
- ✓ C.Amazon CloudWatch Logs
- D.Amazon Kinesis Data Firehose
- E.Amazon S3 replication
Why A: AWS CloudTrail is correct because it can be configured to deliver log files from multiple accounts to a single S3 bucket by setting up a trail in the management account and using the 'Enable for all accounts in my organization' option, which automatically applies the trail to all member accounts in AWS Organizations. This centralizes CloudTrail logs without requiring per-account configuration.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.