DOP-C02 Monitoring and Logging Practice Question
A DevOps team needs to monitor failed API calls in their AWS account. They want to receive notifications when specific IAM actions, such as DeleteBucket, fail. Which service should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail and Amazon EventBridge.
AWS CloudTrail captures API calls, and Amazon EventBridge (formerly CloudWatch Events) can be used to create rules that match specific failed API calls (e.g., DeleteBucket) and trigger notifications. Option B is incorrect because AWS Config rules monitor resource configuration compliance, not API call failures. Option C is incorrect because S3 server access logs log requests made to an S3 bucket, not IAM API calls. Option D is incorrect because CloudWatch Logs and metric filters are used to monitor log data, but they are not the primary service for capturing API calls; CloudTrail is needed for that.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail and Amazon EventBridge.
Why this is correct
AWS CloudTrail records all management API calls in the account, including failed attempts, with metadata such as the IAM principal, source IP, event name, and error codes. Amazon EventBridge can be configured with a rule whose event pattern matches CloudTrail's api_call events and a filter condition on errorCode, routing the matched events to an SNS topic for real-time alerting. This combination is purpose-built for monitoring failed API calls.
- ✗
AWS Config rules.
Why it's wrong here
AWS Config rules evaluate resource configurations and the changes to those configurations against policies, but they do not inspect the API calls that caused the changes. Config records configuration history and compliance states, so a failed CreateBucket call that never changes the resource state is invisible to it. To catch failed API calls, an audit trail of the API activity itself is required, which is CloudTrail's job.
- ✗
Amazon S3 server access logs.
Why it's wrong here
Amazon S3 server access logs are HTTP request logs for object-level actions performed on a specific S3 bucket, such as GET, PUT, and DELETE object requests, and they include the requester, bucket, and timestamps. They do not capture AWS management API calls like IAM or EC2 actions, and they only cover S3 traffic, not failed calls to other services. Even for S3, these logs are delivered asynchronously to another bucket, making them unsuitable for real-time monitoring of failed API calls.
- ✗
CloudWatch Logs and metric filters.
Why it's wrong here
CloudWatch Logs is a log storage and analysis service, but AWS does not push API calls into it by default; only services that explicitly publish logs to CloudWatch Logs appear there. To have API calls in CloudWatch Logs, the team would first need to configure CloudTrail to deliver event data to a log group, at which point CloudTrail/EventBridge already provides the monitoring. Metric filters on CloudWatch Logs can only match data that exists in the logs, so without this prior setup they cannot surface failed API calls.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.