DOP-C02 Monitoring and Logging Practice Question
A DevOps engineer needs to set up centralized logging for an application running on multiple EC2 instances across different AWS accounts. The logs must be aggregated in a single S3 bucket and also be analyzed in near real-time. Which TWO services should be used together to achieve this?
⚠ Common exam trap
DOP-C02 often tests the confusion between CloudWatch Logs (application logs) and CloudTrail (API audit logs), and between SQS (decoupling) and Firehose (delivery to S3) — candidates must recognize that only the CloudWatch Logs subscription + Firehose pairing provides both aggregation and near real-time delivery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Kinesis Data Firehose
Option B, Amazon Kinesis Data Firehose, is correct because it can ingest streaming log data and reliably deliver it to a single S3 bucket, with optional near real-time transformation and buffering, satisfying both the aggregation and near real-time analysis requirements. Option D, Amazon CloudWatch Logs subscription, is correct because a subscription filter on a CloudWatch log group can stream log events in near real time to Kinesis Data Firehose, enabling centralized collection from EC2 instances across multiple AWS accounts. Together, CloudWatch Logs subscriptions feed Firehose, which delivers the aggregated logs to S3. Option A, Amazon SQS, is not appropriate because it is a message queue, not a log ingestion or delivery service to S3. Option C, AWS CloudTrail, records API activity rather than application logs, so it does not meet the application logging requirement. Option E, AWS Lambda, is compute for processing events and is not the primary service for aggregating logs into S3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Simple Queue Service (SQS)
Why it's wrong here
Amazon SQS is a fully managed message queuing service used for decoupling application components through asynchronous, pull-based message delivery. It does not provide built-in log storage, indexing, or querying capabilities, and its message retention is limited to 14 days at most. While SQS could theoretically buffer log events if an intermediate Lambda were used, it would still require a separate consumer to persist and analyze the logs, making it unsuitable as a centralized log aggregation destination.
- ✓
Amazon Kinesis Data Firehose
Why this is correct
Amazon Kinesis Data Firehose is a fully managed streaming ingestion service that can receive log events directly from a CloudWatch Logs subscription and deliver them near-real-time to centralized destinations such as Amazon S3, Amazon Redshift, or Amazon OpenSearch Service. It automatically handles buffering, compression, and encryption, which reduces cost and operational overhead. This makes it the ideal component for aggregating logs from multiple AWS accounts into a single, queryable data lake for centralized analysis.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is primarily an audit and governance service that records API activity and resource changes across an AWS environment. It does not capture application-generated log messages, such as stdout from EC2 instances or application servers, which are the focus of centralized logging. Relying on CloudTrail would miss all application-level telemetry and therefore cannot serve as the log collection pipeline for application logs.
- ✓
Amazon CloudWatch Logs subscription
Why this is correct
Amazon CloudWatch Logs subscription is the forwarding mechanism that streams selected log groups from source accounts to a destination such as Kinesis Data Firehose via a subscription filter. It is a critical part of the centralized logging architecture because it enables near-real-time transfer of log events without requiring agents on each host to push to multiple systems. However, it acts as the source integration and forwarding layer, not the final storage or aggregation endpoint, which is why it complements rather than replaces Firehose.
- ✗
AWS Lambda
Why it's wrong here
AWS Lambda could be used to process or transform CloudWatch Log events, but it is not designed for log aggregation or durable storage. Each invocation has a maximum execution time of 15 minutes and requires custom code to write logs to another service, while scaling is governed by concurrency limits rather than by the throughput of a log stream. Using Lambda as the primary aggregation mechanism would create a fragile, throughput-limited pipeline and add significant operational burden compared to a purpose-built ingestion service like Kinesis Data Firehose.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.