DOP-C02 Monitoring and Logging Practice Question
A platform team runs Amazon EKS clusters across three AWS accounts and wants centralized observability. They need (1) container-level CPU and memory metrics with custom dimensions for namespace and workload, and (2) application logs from all pods shipped to a single destination, queryable with a structured query language. Which TWO actions should the team take? (Choose two.)
⚠ Common exam trap
The trap here is assuming Prometheus scraping alone satisfies the log requirement, when the scenario explicitly needs pod logs aggregated and queryable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Fluent Bit on each node to send pod logs to a CloudWatch Logs log group, and use CloudWatch Logs Insights for structured queries.
Container Insights via the CloudWatch Observability EKS add-on supplies the CPU and memory metrics with namespace and workload dimensions, while Fluent Bit log shipping to CloudWatch Logs provides the centralized, queryable log destination. Together they satisfy both the metric-dimension and structured-log-query requirements across the three accounts using native AWS observability services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS CloudTrail data events on the EKS cluster to capture pod-level container metrics from the Kubernetes API server.
Why it's wrong here
CloudTrail data events record API calls, not CPU or memory metrics, and cannot produce custom dimensions such as namespace or workload. CloudTrail is an audit service; using it for container resource telemetry would generate enormous volume without providing the metric data the team needs.
- ✗
Deploy Prometheus with the CloudWatch agent's Prometheus scraping feature and rely on CloudWatch Logs for log aggregation without Fluent Bit.
Why it's wrong here
Prometheus scraping can collect container metrics, but without Fluent Bit or another log shipper, pod logs are not forwarded to CloudWatch Logs. This partial approach leaves the log aggregation and structured query requirement unmet, so it is not one of the two required actions.
- ✓
Configure Fluent Bit on each node to send pod logs to a CloudWatch Logs log group, and use CloudWatch Logs Insights for structured queries.
Why this is correct
Fluent Bit shipping pod logs to a centralized CloudWatch Logs log group provides a single destination across accounts when combined with cross-account log sharing. CloudWatch Logs Insights supports a structured query language with fields, filter, stats, and parse commands, meeting the structured-query requirement for application logs.
- ✓
Deploy the CloudWatch agent with the Amazon CloudWatch Observability EKS add-on to collect Container Insights metrics with the pod and namespace dimensions.
Why this is correct
The CloudWatch Observability EKS add-on deploys the CloudWatch agent and Fluent Bit for EKS, emitting Container Insights metrics that include pod, namespace, and cluster dimensions. This directly satisfies the container-level CPU and memory requirement with custom dimensions, and supports cross-account metric sharing via CloudWatch cross-account observability.
- ✗
Use AWS Config conformance packs to aggregate pod logs from all three accounts into a single queryable destination.
Why it's wrong here
AWS Config evaluates resource configuration compliance against rules and conformance packs. It does not ingest or centralize application logs, nor does it expose a structured query language for log analysis, so it cannot satisfy either requirement in the scenario.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.