DOP-C02 Monitoring and Logging Practice Question
A DevOps engineer wants to receive an alert when the total number of error logs in an application exceeds 100 within a 5-minute period. The application writes logs to CloudWatch Logs. How can this be achieved?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a metric filter on the log group for 'ERROR', then create a CloudWatch alarm on the resulting metric with a threshold of 100.
A metric filter on the CloudWatch Logs group can count occurrences of the pattern 'ERROR', creating a custom metric. A CloudWatch alarm on that metric with a threshold of 100 and a 5-minute period will trigger when the error count exceeds 100. Option A is incorrect because dashboards are for visualization, not automated alerts. Option B is incorrect because CloudWatch Logs Insights is for ad-hoc queries, not continuous real-time alerting. Option C is incorrect because subscription filters send logs to destinations like Lambda, but the Lambda would need custom logic to count and alert, which is not as direct as a metric filter. The metric filter with alarm is the simplest native solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a CloudWatch dashboard with a line chart for error count and manually monitor it.
Why it's wrong here
A CloudWatch dashboard is a visualization tool; a line chart of error counts lets a human eyeball trends but provides no automated detection or notification when a threshold is exceeded. Without a CloudWatch alarm tied to a metric, there is no SNS event generated, so the DevOps engineer would have to be constantly watching the dashboard, which is neither reliable nor operationally practical. Also, a dashboard cannot directly parse log data; you would first need to create a metric filter from the log group to expose the error count as a graphable metric.
- ✗
Use CloudWatch Logs Insights to run a query every 5 minutes and trigger an alert based on the result.
Why it's wrong here
CloudWatch Logs Insights is designed for interactive, on-demand querying of log data, not as a managed scheduling or alerting service. You cannot natively create a recurring query that runs every five minutes to evaluate a threshold; doing so would require a custom scheduler (e.g., Lambda invoking StartQuery) and then parsing the query results just to trigger a notification. Even if scheduled, Logs Insights queries are not a real-time stream and incur delay and cost, whereas a metric filter continuously evaluates logs in real time and an alarm monitors the resulting metric.
- ✗
Create a CloudWatch Logs subscription filter to send matching logs to a Lambda function, which counts errors and sends an alert.
Why it's wrong here
While a CloudWatch Logs subscription filter can forward matching log events to Lambda, using Lambda to count errors and send alerts is an indirect, custom-built solution. Lambda functions are stateless, so a single invocation cannot maintain a running error count; you would need external state (e.g., DynamoDB) and a separate threshold-evaluation mechanism, introducing complexity, added latency, and potential for lost counts under concurrency. CloudWatch metric filters provide the same pattern matching but natively increment a metric value on a stream, enabling a CloudWatch alarm to handle thresholding and notifications directly.
- ✓
Create a metric filter on the log group for 'ERROR', then create a CloudWatch alarm on the resulting metric with a threshold of 100.
Why this is correct
A metric filter on the CloudWatch Logs group can count occurrences of the pattern 'ERROR', creating a custom metric. A CloudWatch alarm on that metric with a threshold of 100 and a 5-minute period will trigger when the error count exceeds 100.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is using Amazon CloudWatch Logs Insights to analyze application logs. The DevOps team needs to create a metric filter that counts occurrences of the word 'ERROR' in the log events. Which CloudWatch Logs Insights query should be used to test the metric filter?
medium- A.fields @timestamp, @message | stats count() by bin(5m)
- ✓ B.fields @timestamp, @message | filter @message like /ERROR/
- C.fields @timestamp, @message | parse @message '[*] *' as @severity, @log
- D.fields @timestamp, @message | sort @timestamp desc
Why B: To test a metric filter that counts occurrences of the word 'ERROR' in log events, you need a CloudWatch Logs Insights query that filters log events containing 'ERROR'. The query `fields @timestamp, @message | filter @message like /ERROR/` does exactly that: it selects the timestamp and message fields and filters for messages that match the regular expression /ERROR/. This allows you to verify that the filter pattern will correctly identify the relevant log events.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.