DOP-C02 Incident and Event Response Practice Question
A DevOps team is configuring CloudWatch alarms for their production environment. They want to receive notifications when the CPUUtilization metric of an EC2 instance exceeds 90% for three consecutive 5-minute periods. Which combination of settings should they use?
⚠ Common exam trap
The trap is confusing 'datapoints to alarm' with 'evaluation periods'; candidates may think that setting datapoints to 1 still requires three periods, but it actually triggers on the first breach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Period: 5 minutes; Evaluation periods: 3; Datapoints to alarm: 3
To alarm when CPUUtilization exceeds 90% for three consecutive 5-minute periods, you need a period of 5 minutes, evaluation periods of 3, and datapoints to alarm of 3. This means CloudWatch evaluates the metric over three consecutive periods, and all three must breach the threshold to trigger the alarm. This configuration exactly matches the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Period: 5 minutes; Evaluation periods: 3; Datapoints to alarm: 3
Why this is correct
With a 5-minute period, 3 evaluation periods, and 3 datapoints to alarm, the alarm enters ALARM state only when every one of the three most recent 5-minute data points breaches the threshold. This means the metric must be continuously in breach for 15 minutes, filtering out transient spikes and providing a reliable signal of a sustained problem. It is the appropriate setting for production alarms that should page responders only after a consistent degradation.
- ✗
Period: 5 minutes; Evaluation periods: 3; Datapoints to alarm: 1
Why it's wrong here
Setting datapoints to alarm to 1 with 3 evaluation periods means the alarm will trigger if any single 5-minute data point exceeds the threshold, even if the other two periods are normal. This effectively collapses the evaluation window to a single period, making the alarm highly sensitive to short-lived anomalies or measurement noise. Such a configuration is prone to false positives and is rarely suitable for alarms that page humans; it is better used for low-severity, auto-remediating actions.
- ✗
Period: 5 minutes; Evaluation periods: 1; Datapoints to alarm: 3
Why it's wrong here
This configuration is invalid because CloudWatch requires the number of datapoints to alarm to be less than or equal to the number of evaluation periods. With only 1 evaluation period, there is only one data point available to evaluate; asking for 3 breaching datapoints is impossible. The alarm would either fail validation during creation or, if forced, can never actually enter ALARM state, making it useless for monitoring.
- ✗
Period: 5 minutes; Evaluation periods: 5; Datapoints to alarm: 3
Why it's wrong here
With 5 evaluation periods and 3 datapoints to alarm, the alarm triggers when any 3 of the 5 most recent 5-minute periods breach the threshold, regardless of whether those breaches are consecutive. This allows intermittent or cyclical spikes to trigger alarms even when the workload is not persistently unhealthy. It is less restrictive than requiring 3 consecutive breaches, and while it can catch recurring issues faster, it may generate false alarms for bursty traffic patterns that are still generally healthy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.