Courseiva
Monitoring and Logging →easyMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

An application running on Amazon EC2 instances sends custom metrics to CloudWatch. The team notices that some metrics are not appearing. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CloudWatch agent is not installed or configured on the EC2 instances.

The most likely cause is that the CloudWatch agent is not installed or configured on the EC2 instances. Custom metrics require the CloudWatch agent to collect and send data to CloudWatch. Option A is incorrect because custom metric namespaces do not need to be pre-registered; they are automatically created when metrics are published. Option B is incorrect because instances in a private subnet can still publish metrics using a VPC endpoint or a proxy, so a NAT gateway is not strictly required. Option C is incorrect because even with proper IAM permissions, the CloudWatch agent must be installed and running to collect and send custom metrics. Therefore, option D is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The custom metric namespace is not pre-registered in CloudWatch.

    Why it's wrong here

    CloudWatch namespaces are logical containers for metrics and are created automatically the first time a metric is published to that namespace via PutMetricData. There is no pre-registration or prior creation step required; if you are seeing no custom metrics, the problem is not that the namespace does not exist but rather that no data is being sent. The absence of metrics in the console means either the publishing source is not running or the credentials/network path to CloudWatch is broken.

  • ✗

    The EC2 instances are in a private subnet without a NAT gateway.

    Why it's wrong here

    The CloudWatch agent can operate in a private subnet by using an interface VPC endpoint for CloudWatch, which routes traffic over the AWS private network without needing a NAT gateway or internet route. Security groups and network ACLs must allow outbound HTTPS to the endpoint, but a NAT gateway is not a hard requirement. Therefore, being private without a NAT is not an inherent reason no custom metrics appear, provided the appropriate VPC endpoint exists.

  • ✗

    The IAM role attached to the EC2 instance lacks permissions to publish metrics.

    Why it's wrong here

    While an improperly scoped IAM role is a plausible cause, it typically results in explicit AccessDenied errors logged by the CloudWatch agent or API calls, not simply missing metrics with no other symptoms. The agent must be installed, running, and configured to use that role; without the agent, the role is never consulted. In this scenario, the lack of any metric data at all—not just a permission failure—points more directly to the agent's absence or misconfiguration.

  • ✓

    The CloudWatch agent is not installed or configured on the EC2 instances.

    Why this is correct

    Custom metrics are not emitted by default by EC2; they require an explicit mechanism such as the CloudWatch agent or direct PutMetricData calls from the application. If the agent is not installed or its configuration file (common for statsd or collectd) is missing/invalid, no metric data will be sent even though the application is running. This is the most common root cause when an application expects to send custom metrics but nothing appears in CloudWatch, because without the agent’s collection loop, nothing triggers the metric submission.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.