Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer is troubleshooting a failed AWS CloudFormation stack creation. The stack creates an EC2 instance with a user data script that runs a configuration management tool. The instance launches successfully, but the user data script fails. How can the engineer retrieve the user data execution logs to debug the issue?

⚠ Common exam trap

Candidates often assume CloudTrail or CloudWatch Logs automatically capture user data execution logs, but those services require explicit configuration and do not capture the script's output by default.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Access the instance via EC2 Instance Connect and check /var/log/cloud-init-output.log.

The user data script output is logged by cloud-init to /var/log/cloud-init-output.log on the EC2 instance. By using EC2 Instance Connect to access the instance, the engineer can directly read this log file to see the full execution output, including any error messages from the configuration management tool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudTrail to view the user data execution events.

    Why it's wrong here

    CloudTrail records AWS API activity such as RunInstances or DescribeInstances, but after the instance boots, the user-data script executes inside the guest OS as part of cloud-init. Those script commands and their stdout/stderr are not AWS API calls, so CloudTrail will not show the script's output or error. Therefore, CloudTrail cannot help diagnose a user-data execution failure.

  • ✗

    Use AWS Systems Manager Run Command to retrieve the logs remotely.

    Why it's wrong here

    Systems Manager Run Command is intended to run one-off commands on instances that already have the SSM Agent installed and are reachable via the SSM service. If the instance is booting or the user-data script failed in a way that left the system degraded, the instance may not be registered or reachable, so Run Command cannot reliably fetch logs. Even when reachable, Run Command itself does not collect logs; you would need to invoke a command to list them, making it an indirect workaround rather than a native log-retrieval mechanism.

  • ✗

    Check the CloudWatch Logs group for the instance.

    Why it's wrong here

    By default, Amazon EC2 does not send user-data output or cloud-init logs to any CloudWatch Logs group. Collecting those logs requires installing and configuring the unified CloudWatch agent with a log-stream definition for files such as /var/log/cloud-init-output.log. Unless that agent was pre-configured in the AMI or via user data, the specified CloudWatch Logs group will be empty or contain unrelated system logs, so checking it will not expose the user-data execution failure.

  • ✓

    Access the instance via EC2 Instance Connect and check /var/log/cloud-init-output.log.

    Why this is correct

    EC2 Instance Connect opens a temporary SSH session through the AWS Console, giving you direct interactive access to the running instance. Once connected, you can read /var/log/cloud-init-output.log, which captures the output of cloud-init including your user-data script, so any error or traceback from the script will be visible there. It is an effective diagnostic because it accesses the primary log source without requiring pre-installed agents or external log forwarding.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.