Courseiva

DOP-C02 Incident and Event Response Practice Question

A DevOps engineer is troubleshooting an AWS CodeDeploy deployment that failed. Which TWO resources should the engineer examine to identify the cause of the failure? (Choose two.)

⚠ Common exam trap

Many candidates confuse CloudTrail (API auditing) with CloudWatch Logs (application-level logging), or they mistakenly think EC2 system logs are relevant for application deployment failures, when in fact CodeDeploy-specific logs are the correct source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudWatch Logs for CodeDeploy

AWS CodeDeploy emits detailed logs about deployment lifecycle events (e.g., BeforeInstall, ApplicationStop) to CloudWatch Logs. These logs contain error messages, script output, and status codes that directly indicate why a deployment step failed, such as a permission issue or a script syntax error. Examining CloudWatch Logs for CodeDeploy is the primary method to diagnose deployment failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EC2 instance system logs

    Why it's wrong here

    EC2 instance system logs (e.g., /var/log/messages, syslog) are not automatically shipped to the AWS console; you must use AWS Systems Manager Session Manager, Run Command, or an agent on the instance to retrieve them. CodeDeploy agent logs and script output are written locally under /var/log/aws/codedeploy-agent and /opt/codedeploy-agent/deployment-root, but without centralized collection you would have to connect to each failed instance individually. For immediate troubleshooting, these are not automatically accessible and are therefore not the first source to consult.

  • ✓

    CloudWatch Logs for CodeDeploy

    Why this is correct

    CloudWatch Logs for CodeDeploy is the correct source because it centralizes deployment events and error messages. When you configure a log group for the deployment group, lifecycle event execution details—such as BeforeInstall, AfterInstall, ApplicationStart, and the associated script output—are streamed into CloudWatch Logs. This lets you query and filter by deployment ID and instance ID, making it the fastest way to identify which lifecycle hook failed and why, rather than logging into individual instances.

  • ✗

    S3 access logs

    Why it's wrong here

    S3 access logs record requests made to an S3 bucket and are not related to CodeDeploy deployment execution. While CodeDeploy may pull a revision bundle from S3, these logs only show object-level API operations like GET requests and do not contain deployment IDs, lifecycle hook results, or script errors. They are also disabled by default and can take hours to be delivered, so they provide no real-time diagnostic value for a failed deployment.

  • ✗

    CloudTrail logs

    Why it's wrong here

    CloudTrail logs record AWS API calls such as CreateDeployment, GetDeployment, and RegisterApplicationRevision, plus the IAM principal who made them. They do not capture what actually executes on the target instance—for example, whether an AppSpec script fails, a file is missing, or a hook times out. CloudTrail is useful for auditing who triggered a deployment or for detecting access-denied API errors, but it cannot explain why an instance-side deployment step failed.

  • ✓

    CodeDeploy deployment group configuration

    Why this is correct

    CodeDeploy deployment group configuration can indeed cause deployments to fail if incorrect. The deployment group controls which instances are selected via tags or Auto Scaling groups, how traffic is shifted, and whether load balancer registration or deregistration is performed. A misconfigured tag, an invalid load balancer target group, or an overly short health check grace period can cause the deployment to fail even when the application bundle and AppSpec are perfectly valid, so you must validate these settings when troubleshooting.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS CodePipeline for CI/CD. During a production deployment, the pipeline fails at the 'Deploy' stage with an error: 'The deployment failed because the deployment group does not have enough capacity to handle the deployment.' The engineer checks the CodeDeploy deployment group and sees that it is configured with a minimum healthy hosts of 100% and a deployment configuration of 'CodeDeployDefault.OneAtATime'. What is the MOST likely cause?

medium
  • A.The deployment configuration 'OneAtATime' is not compatible with the deployment group.
  • B.The target group health check is misconfigured, causing all instances to be unhealthy.
  • C.The CodeDeploy agent on the instances is not running.
  • ✓ D.The deployment group has only one instance, and the minimum healthy hosts setting prevents the deployment.

Why D: With a minimum healthy hosts of 100% and a OneAtATime deployment configuration, CodeDeploy must keep all instances healthy during the deployment. If the deployment group contains only one instance, taking it out of service to deploy would drop healthy hosts below 100%, making the deployment impossible. This is the most likely cause of the capacity error.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.