Courseiva
Monitoring and Logging →mediumMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

A DevOps team needs to monitor failed API calls in their AWS account. They want to receive notifications when specific IAM actions, such as DeleteBucket, fail. Which service should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail and Amazon EventBridge.

AWS CloudTrail captures API calls, and Amazon EventBridge (formerly CloudWatch Events) can be used to create rules that match specific failed API calls (e.g., DeleteBucket) and trigger notifications. Option B is incorrect because AWS Config rules monitor resource configuration compliance, not API call failures. Option C is incorrect because S3 server access logs log requests made to an S3 bucket, not IAM API calls. Option D is incorrect because CloudWatch Logs and metric filters are used to monitor log data, but they are not the primary service for capturing API calls; CloudTrail is needed for that.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail and Amazon EventBridge.

    Why this is correct

    AWS CloudTrail records all management API calls in the account, including failed attempts, with metadata such as the IAM principal, source IP, event name, and error codes. Amazon EventBridge can be configured with a rule whose event pattern matches CloudTrail's api_call events and a filter condition on errorCode, routing the matched events to an SNS topic for real-time alerting. This combination is purpose-built for monitoring failed API calls.

  • ✗

    AWS Config rules.

    Why it's wrong here

    AWS Config rules evaluate resource configurations and the changes to those configurations against policies, but they do not inspect the API calls that caused the changes. Config records configuration history and compliance states, so a failed CreateBucket call that never changes the resource state is invisible to it. To catch failed API calls, an audit trail of the API activity itself is required, which is CloudTrail's job.

  • ✗

    Amazon S3 server access logs.

    Why it's wrong here

    Amazon S3 server access logs are HTTP request logs for object-level actions performed on a specific S3 bucket, such as GET, PUT, and DELETE object requests, and they include the requester, bucket, and timestamps. They do not capture AWS management API calls like IAM or EC2 actions, and they only cover S3 traffic, not failed calls to other services. Even for S3, these logs are delivered asynchronously to another bucket, making them unsuitable for real-time monitoring of failed API calls.

  • ✗

    CloudWatch Logs and metric filters.

    Why it's wrong here

    CloudWatch Logs is a log storage and analysis service, but AWS does not push API calls into it by default; only services that explicitly publish logs to CloudWatch Logs appear there. To have API calls in CloudWatch Logs, the team would first need to configure CloudTrail to deliver event data to a log group, at which point CloudTrail/EventBridge already provides the monitoring. Metric filters on CloudWatch Logs can only match data that exists in the logs, so without this prior setup they cannot surface failed API calls.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.