Courseiva
Monitoring and Logging →easyMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

A DevOps engineer is tasked with ensuring that all Amazon S3 buckets in the account have server access logging enabled. The engineer needs to be automatically notified when a new bucket is created without logging enabled. Which AWS service should they use?

⚠ Common exam trap

Candidates often confuse event-driven services like CloudTrail or S3 Event Notifications with configuration compliance services, mistakenly thinking they can directly detect and react to resource misconfigurations without the need for custom evaluation logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Config with a managed rule to check if S3 bucket logging is enabled, and configure an SNS topic for notifications.

AWS Config provides continuous monitoring and evaluation of your AWS resource configurations. By using the managed rule 's3-bucket-server-access-logging-enabled', AWS Config can automatically check all S3 buckets (including newly created ones) for server access logging. When a bucket is non-compliant, AWS Config can trigger an SNS notification to alert the DevOps engineer, meeting the requirement for automatic notification without custom code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudTrail to detect CreateBucket API calls and trigger a Lambda function to check logging.

    Why it's wrong here

    CloudTrail records API calls like CreateBucket for audit, but it does not evaluate the resulting configuration's compliance. While a Lambda could parse CloudTrail events and call GetBucketLogging, that requires custom code, and CloudTrail event delivery has latency, so it is not a near-real-time or managed compliance solution. The correct answer uses a purpose-built service like AWS Config.

  • ✗

    Use AWS Trusted Advisor to check S3 bucket logging and send notifications via Amazon SNS.

    Why it's wrong here

    Trusted Advisor performs periodic checks on a set refresh schedule, so it cannot detect a newly created S3 bucket immediately or send a timely SNS notification. Its S3 bucket logging check may also miss buckets that are created outside supported regions or only run every few hours. Thus, it offers only delayed, best-effort visibility, not the event-driven, real-time evaluation needed for this requirement.

  • ✗

    Use Amazon S3 Event Notifications to trigger a Lambda function when a new bucket is created.

    Why it's wrong here

    Amazon S3 Event Notifications are limited to object-level events, such as s3:ObjectCreated:* or s3:ObjectTagging:*; there is no bucket-level event like CreateBucket. Even if you tried to configure notifications on existing buckets, new buckets would need the configuration applied separately, so you cannot capture bucket creation events this way. This option misunderstands the scope of S3 event notifications, which focus on data-plane activity, not control-plane operations that require CloudTrail or AWS Config.

  • ✓

    Use AWS Config with a managed rule to check if S3 bucket logging is enabled, and configure an SNS topic for notifications.

    Why this is correct

    AWS Config continuously records configuration changes and evaluates them with managed rules, including s3-bucket-logging-enabled, which verifies server access logging is turned on for each bucket. When a bucket is created or its logging configuration changes, AWS Config re-evaluates in near real time and can publish compliance results to an SNS topic, triggering notifications. This provides a fully managed, automated, and near-real-time compliance check, making it the appropriate solution.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.