Courseiva
Monitoring and Logging →mediumMultiple Select

DOP-C02 Monitoring and Logging Practice Question

A DevOps engineer is designing a monitoring solution for a multi-tier web application hosted on AWS. The application consists of an Application Load Balancer (ALB), EC2 instances, and an RDS database. The engineer needs to capture and analyze HTTP request logs from the ALB to understand client behavior and troubleshoot errors. Which THREE steps are necessary to achieve this?

⚠ Common exam trap

DOP-C02 often tests the confusion between CloudTrail (API audit logs) and ALB access logs (HTTP request logs), and the misconception that the CloudWatch Agent can be installed on managed services like ALB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Amazon Athena to query the access logs in S3

Option D is correct because ALB access logs must be explicitly enabled on the load balancer, which captures detailed information about every HTTP/HTTPS request including client IP, request path, response codes, and latency. Option E is correct because ALB access logs are delivered to an Amazon S3 bucket, so a target S3 bucket (with the proper bucket policy allowing the ALB to write) must exist before enabling logging. Option C is correct because Amazon Athena can query the ALB access logs stored in S3 directly using SQL, enabling analysis of client behavior and troubleshooting of errors without loading data into a database. Option A is incorrect because the CloudWatch Agent runs on EC2 instances or on-premises servers, not on ALBs, which are managed services that cannot host agents. Option B is incorrect because AWS CloudTrail records API activity and management events, not HTTP request logs, so it does not capture ALB access log data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Install the CloudWatch Agent on the ALB

    Why it's wrong here

    The Application Load Balancer is a fully managed AWS service that operates at the network layer; there is no EC2 instance to install the CloudWatch Agent on, nor can the agent capture ALB-specific request logs. The CloudWatch Agent is designed to collect custom metrics and logs from EC2 instances or on-premises servers, not from managed services like ALB. ALB does publish CloudWatch metrics automatically, but access logs containing detailed HTTP request data are only delivered to Amazon S3 and require a different analysis path (e.g., Athena).

  • ✗

    Enable AWS CloudTrail for the ALB

    Why it's wrong here

    AWS CloudTrail records control-plane API calls made to the Elastic Load Balancing service via the management console, SDK, or CLI, such as CreateLoadBalancer or ModifyListener; it does not capture the data-plane HTTP requests that flow through the ALB itself. Even with data events enabled, CloudTrail would not log client requests to the load balancer because ALB does not integrate CloudTrail for data-plane traffic. The detailed per-request information needed for troubleshooting (client IP, URI, response codes) comes exclusively from ALB access logs stored in S3, not from CloudTrail.

  • ✓

    Use Amazon Athena to query the access logs in S3

    Why this is correct

    Amazon Athena is the correct service for interactively querying ALB access logs directly from S3 without loading data into a database. The logs are stored as gzipped text files in a partitionable layout (AWSLogs/account-id/elasticloadbalancing/region/yyyy/mm/dd), which can be registered as a table in Athena using JSON or CSV SerDe. With Athena's SQL, you can analyze request patterns, error rates, latency, and client behavior by writing queries against the log fields, and partitioning or partition projection keeps query costs low. This makes Athena the natural final step after enabling ALB access logs and storing them in S3.

  • ✓

    Enable access logs on the ALB

    Why this is correct

    Enabling access logs on the ALB is the critical step that causes the load balancer to capture detailed information about every HTTP/HTTPS request it processes, including the client IP address, user agent, request method, URI, response status codes, and latency metrics. Without this setting, the ALB only emits aggregated CloudWatch metrics and retains no raw request data. Once enabled, the ALB automatically writes log files in a structured format to the S3 bucket you specify, where they are delivered multiple times per hour as gzipped objects. This is a per-attribute toggle on the ALB and requires an IAM role or bucket policy to authorize the Elastic Load Balancing service to write.

  • ✓

    Create an Amazon S3 bucket to store the access logs

    Why this is correct

    Creating an Amazon S3 bucket is a prerequisite for ALB access logging because the ALB is hard-coded to deliver log files to S3 and offers no other storage destination for these logs. The bucket must have a policy that grants elasticloadbalancing.amazonaws.com permission to write objects into the bucket/prefix; otherwise the ALB will not be able to publish logs. Best practice is to place the bucket in the same AWS Region as the ALB to avoid data-transfer costs and latency, though the bucket can be in a different account when using a bucket-policy approach. Without this bucket, enabling access logs on the ALB would fail even though the feature is turned on.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.