Courseiva

DOP-C02 Incident and Event Response Practice Question

A DevOps engineer needs to receive notifications when an EC2 instance's status check fails. Which TWO services should the engineer use? (Choose TWO.)

⚠ Common exam trap

The trap here is that candidates often select AWS Lambda or AWS Config because they associate them with automation or compliance, but the question explicitly asks for services to 'receive notifications' when a status check fails, which requires a notification delivery service (SNS) and a monitoring service (CloudWatch Alarm), not compute or configuration tracking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Simple Notification Service (SNS)

Amazon CloudWatch Alarms (Option E) can monitor EC2 instance status checks (both system and instance checks) and trigger an action when the alarm state changes to ALARM. Amazon SNS (Option B) is the service that delivers the notification by publishing messages to subscribers (e.g., email, SMS, HTTP endpoints) when the CloudWatch alarm triggers. Together, they provide a complete monitoring and notification pipeline for status check failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Lambda

    Why it's wrong here

    AWS Lambda is a serverless compute service that executes code in response to events, but it has no built-in integration for EC2 status check metrics and would require custom code to poll or process CloudWatch alarms. For simple EC2 health notifications, introducing Lambda adds unnecessary complexity and operational overhead, whereas Amazon SNS natively receives alarm notifications and delivers them directly to email, SMS, or other endpoints. Lambda could only be useful if you needed to transform or enrich the notification before delivery, which is not part of the stated requirement.

  • ✓

    Amazon Simple Notification Service (SNS)

    Why this is correct

    Amazon Simple Notification Service (SNS) is a fully managed pub/sub messaging service that delivers messages to subscribers such as email, SMS, Lambda, or HTTP endpoints. When a CloudWatch alarm transitions to the ALARM state for the StatusCheckFailed metric, it publishes a message to an SNS topic, which then fans out the notification to all subscribed endpoints. This makes SNS the essential delivery mechanism for alerting the DevOps engineer promptly without requiring polling or custom integration code, and it integrates seamlessly with CloudWatch Alarms.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity across your account, capturing events like CreateInstance, TerminateInstance, or any action performed via the AWS Console, SDK, or CLI. It does not, however, monitor the runtime health or status checks of an EC2 instance; status checks are operational metrics produced by the EC2 hypervisor and published to CloudWatch, not user-initiated API calls. Enabling CloudTrail would leave the engineer blind to instance failures such as system reachability or instance reachability issues, so it is irrelevant for this notification requirement.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a service that evaluates your AWS resource configurations against desired policies and rules, such as checking whether instances have the correct instance type or tags, and it records configuration changes over time. It does not assess the live operational status of an instance's system or instance reachability checks, because those are real-time performance metrics rather than compliance attributes of the resource configuration. Config could alert on noncompliant configurations, but it cannot detect a failed status check or trigger a notification based on the StatusCheckFailed metric emitted by EC2 to CloudWatch.

  • ✓

    Amazon CloudWatch Alarm

    Why this is correct

    Amazon CloudWatch Alarm continuously monitors a specified metric, such as EC2 StatusCheckFailed, and compares it against a threshold over a defined period; when the metric breaches the threshold, the alarm changes to the ALARM state. This alarm is the component that actually evaluates the health signal and acts as the trigger for the notification workflow, making it a correct answer because it is the direct watchdog for EC2 status check failures. It works in tandem with SNS: the alarm publishes the state change to a topic, and SNS delivers the message to the engineer.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.