DOP-C02 Monitoring and Logging Practice Question
A DevOps team has set up centralized logging for multiple AWS accounts using Amazon OpenSearch Service. The team uses CloudWatch cross-account observability to collect logs from various accounts into a monitoring account. Recently, logs from one source account stopped appearing in the monitoring account's OpenSearch dashboard. Other source accounts continue to send logs successfully. Which step should the team take to troubleshoot this issue?
⚠ Common exam trap
Many exam-takers confuse the cross-account observability setup (which uses IAM roles and trust policies) with the actual log delivery mechanism (subscription filters), leading them to check the IAM role or the monitoring account configuration instead of the source account's subscription filter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the source account's CloudWatch Logs subscription filter for the OpenSearch destination.
The most likely cause of logs from a single source account failing to appear is a misconfigured or broken CloudWatch Logs subscription filter. This filter is responsible for forwarding log events from the source account to the OpenSearch destination in the monitoring account. If the filter is missing, misconfigured, or has been accidentally deleted, logs will not be sent, while other accounts continue to work normally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the monitoring account's CloudWatch cross-account observability is enabled.
Why it's wrong here
Cross-account observability being enabled in the monitoring account is a prerequisite for the overall pipeline, but since other source accounts are already ingesting data successfully, this feature is demonstrably active and functioning. If it were disabled, no accounts—including the working ones—would deliver logs, so this check would not isolate why this particular source account stopped sending logs to OpenSearch.
- ✓
Check the source account's CloudWatch Logs subscription filter for the OpenSearch destination.
Why this is correct
The source account's CloudWatch Logs subscription filter is the mechanism that continuously streams matching log events to a destination such as an OpenSearch ingestion pipeline or a Kinesis stream. If this filter was accidentally removed, disabled, or its destination ARN changed, log forwarding for that account ceases even though the logs remain in CloudWatch Logs. Verifying and if necessary recreating the subscription filter and its destination policy is the correct first step to restore the flow.
- ✗
Review the source account's CloudWatch Logs retention policy to confirm logs are not expired.
Why it's wrong here
The retention policy in CloudWatch Logs controls how long log events are kept before they are deleted; it does not trigger, throttle, or otherwise affect the real-time subscription forwarding mechanism. Because the logs are still visible in CloudWatch Logs (as stated in the scenario), they have not expired, and adjusting retention would neither resume forwarding nor explain why OpenSearch stopped receiving them. Expiry would only matter if the logs themselves were already purged, which is not the case here.
- ✗
Ensure the IAM role in the source account has the correct trust policy for the monitoring account.
Why it's wrong here
Cross-account log delivery via CloudWatch Logs subscriptions does not rely on an IAM role in the source account with a trust policy for the monitoring account. Instead, the source account uses a resource policy attached to the destination (for example, a Kinesis stream or an OpenSearch ingestion endpoint) to grant CloudWatch Logs permission to write data, and the monitoring account consumes that data through its own observability configuration. A misconfigured trust policy would break API calls that assume a role, but this particular data path has no such role assumption, so the issue lies elsewhere.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.