DOP-C02 Monitoring and Logging Practice Question
A DevOps engineer needs to set up a monitoring solution that can detect and alert on unusual patterns in application metrics. Which TWO AWS services can be used together to achieve this? (Choose TWO.)
⚠ Common exam trap
DOP-C02 often tests the confusion between security monitoring services (GuardDuty, CloudTrail) and performance monitoring services (CloudWatch), where candidates incorrectly select security tools for anomaly detection in application metrics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Alarms
Amazon CloudWatch Anomaly Detection [CORRECT] is correct because it applies machine-learning algorithms to a metric's historical baseline and creates an expected-value band, so it can flag unusual patterns in application metrics without requiring manually tuned static thresholds. Amazon CloudWatch Alarms [CORRECT] is correct because it evaluates a metric or an anomaly-detection band against a defined condition and triggers actions such as Amazon SNS notifications, making it the alerting mechanism that works together with anomaly detection. Used together, Anomaly Detection identifies the deviation and CloudWatch Alarms fires the alert, which directly satisfies the requirement to detect and alert on unusual metric patterns. Amazon GuardDuty is a threat-detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity, not application metric patterns. AWS CloudTrail records API activity for auditing and governance, and AWS Config evaluates resource configuration compliance, so neither detects anomalies in application metrics or sends metric-based alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a managed threat detection service that uses machine learning and integrated threat intelligence to identify unauthorized access, credential compromise, or malicious activity recorded in VPC Flow Logs, AWS CloudTrail management events, and DNS query logs. It inspects raw security telemetry, not CloudWatch metric streams, so it has no visibility into operational KPIs such as CPU utilization, latency, or request counts. Because it cannot analyze metric patterns or generate statistical baselines, it is unsuitable for this monitoring requirement.
- ✓
Amazon CloudWatch Alarms
Why this is correct
Amazon CloudWatch Alarms are the action engine that watches a single CloudWatch metric, a math expression, or an anomaly detection band over a specified time period, then transitions to an ALARM state when the observed value breaches a defined threshold. You can configure the alarm to publish to an SNS topic, trigger Auto Scaling, or execute an EC2 action such as a reboot when the anomaly condition persists. In this solution, the alarm consumes the band produced by CloudWatch Anomaly Detection and calls the monitoring hook when unusual metric behavior is detected.
- ✓
Amazon CloudWatch Anomaly Detection
Why this is correct
Amazon CloudWatch Anomaly Detection applies statistical and machine learning algorithms to historical metric data to generate a dynamic baseline consisting of an expected value plus an upper and lower band. Instead of requiring a static threshold, it continuously learns the metric's normal seasonal and trend behavior, and flags points that fall outside the band as anomalous. The output is a model that can be used in a math expression within an alarm; it is the detection layer, not the notification layer, which is why it must be paired with an alarm.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is a governance and auditing service that records every API call made in an AWS account, capturing details such as the identity of the caller, the time of the request, the source IP address, and the request parameters. These logs are essential for security analysis, resource change tracking, and compliance audits, but they contain little to no numerical performance data. CloudTrail events are not structured as time-series metrics and cannot be used to detect anomalous CPU, memory, or traffic patterns.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration assessment service that continuously records the configuration state of AWS resources and evaluates those configurations against customizable rules, such as verifying that EBS volumes are encrypted or that S3 buckets have versioning enabled. It detects resource configuration drift and compliance violations, but it does not ingest operational metric streams and has no concept of metric thresholds or statistical anomaly detection. Therefore it cannot satisfy a requirement to monitor unusual patterns in application metrics.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.