Troubleshooting CloudWatch Synthetics Canary Timeout Errors
A company is using Amazon CloudWatch Synthetics canaries to monitor its web application endpoints. The canaries are failing intermittently with timeout errors. The DevOps team needs to troubleshoot the root cause. Which THREE actions should they take? (Select THREE.)
Quick Answer
The correct actions are to examine the canary logs in CloudWatch Logs, check VPC Flow Logs for network issues, and increase the canary timeout setting. These three steps directly address the root causes of timeout errors in CloudWatch Synthetics: application-level failures logged in the canary’s execution logs, network connectivity problems visible in VPC Flow Logs, and an insufficient timeout threshold that prematurely terminates the canary. On the AWS Certified DevOps Engineer Professional DOP-C02 exam, this question tests your understanding that Synthetics canaries run as AWS Lambda functions, not on EC2, so EC2-related troubleshooting is a common trap. CloudTrail is also a distractor because it records API calls, not canary execution details. A useful memory tip is “Logs, Flows, Timeout” — always check the canary’s own logs first, then network flow logs for connectivity, and finally adjust the timeout if the application response is legitimately slow.
⚠ Common exam trap
DOP-C02 often tests the scope of monitoring tools; the trap is confusing CloudTrail (API activity) with canary execution logs, or assuming canaries run on customer EC2 instances when they actually run on AWS-managed infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the canary timeout configuration to allow more time for the endpoint to respond.
Option B is correct because CloudWatch Synthetics canaries have a configurable timeout setting, and if the endpoint legitimately needs more time to respond, raising the timeout prevents intermittent timeout failures. Option D is correct because canaries can run inside a VPC, and VPC Flow Logs capture ACCEPT/REJECT records for traffic to and from the canary's ENIs, revealing whether security groups, NACLs, or routing are dropping the requests. Option E is correct because each canary writes execution logs, screenshots, and HAR files to CloudWatch Logs under /aws/lambda/cwsyn-* log groups, and these logs contain the exact error messages and timing data needed to diagnose the timeout. Option A is not appropriate because CloudTrail records control-plane API calls (e.g., CreateCanary, UpdateCanary), not the canary's runtime HTTP request behavior. Option C is not appropriate because canaries run as Lambda functions managed by the Synthetics service, not on customer EC2 instances, so EC2 CPU utilization in the VPC is irrelevant to canary timeouts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudTrail to review Canary API calls.
Why it's wrong here
CloudTrail logs API calls to create canaries, not execution details.
- ✓
Increase the canary timeout configuration to allow more time for the endpoint to respond.
Why this is correct
If the timeout is too low, increasing it may resolve false positives.
- ✗
Check the EC2 instance CPU utilization in the VPC where the canaries run.
Why it's wrong here
Canaries run as Lambda functions, not on EC2 instances.
- ✓
Review VPC Flow Logs to see if requests are being dropped or denied.
Why this is correct
Flow logs can reveal network issues causing timeouts.
- ✓
Examine the canary logs in CloudWatch Logs for error messages.
Why this is correct
Canary logs contain output from the script execution.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is using Amazon CloudWatch Synthetics to monitor the availability of a web application. The canary runs every 5 minutes from multiple locations. Recently, the canary has been failing intermittently with HTTP 503 errors, but the application team reports that the application is healthy. Which step should the DevOps engineer take to identify the cause of the false positives?
medium- A.Increase the canary timeout setting to allow more time for the application to respond.
- B.Add more canary locations to increase coverage.
- ✓ C.Review the canary's CloudWatch Logs to check for network errors or timeouts.
- D.Increase the canary run frequency to every 1 minute.
Why C: Reviewing the canary's CloudWatch Logs is the correct first step because Synthetics canaries write detailed logs and screenshots for each run, including network errors, timeouts, and HTTP response details. Since the application team reports the app is healthy, the 503 errors are likely caused by the canary's network path, DNS resolution, or a transient issue that the logs will reveal. This is the diagnostic step that identifies the root cause of the false positives.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.