Setting Up an Alarm When RDS CPU Exceeds 80% for 5 Minutes
A company's DevOps team notices that their Amazon RDS for PostgreSQL instance's CPU utilization spikes to 90% every day at 10:00 AM, causing application latency. They want to be notified when the CPU utilization exceeds 80% for more than 5 minutes to investigate the cause. Which solution should they implement?
Quick Answer
The correct solution is to create an Amazon CloudWatch alarm on the CPUUtilization metric with a period of 5 minutes and a threshold of 80, and set the alarm action to send a notification to an Amazon SNS topic. This works because CloudWatch metric math allows you to evaluate a single metric—like RDS CPU utilization—over a specified time period, and when the value exceeds the threshold for the duration of that period, the alarm state triggers an SNS notification directly. On the AWS Certified DevOps Engineer Professional DOP-C02 exam, this question tests your understanding of CloudWatch alarms versus other services like CloudTrail or Trusted Advisor, which are common distractors; CloudTrail tracks API calls, not performance metrics, and Trusted Advisor provides best-practice checks but cannot create custom alarms. A key trap is confusing CloudWatch Logs Insights, which analyzes log data, with metric-based alarms. Remember the mnemonic: "CPU over 80 for five? CloudWatch alarm, SNS to drive."
⚠ Common exam trap
DOP-C02 often tests the misconception that CloudTrail or Logs Insights can monitor resource metrics, when only CloudWatch metrics and alarms are designed for threshold-based performance alerting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Amazon CloudWatch alarm on the CPUUtilization metric with a period of 5 minutes and a threshold of 80, and set the alarm action to send a notification to an Amazon SNS topic.
Amazon CloudWatch natively collects the CPUUtilization metric for RDS, and an alarm with a 5-minute period and an 80% threshold directly matches the requirement to alert when CPU exceeds 80% for more than 5 minutes. Configuring the alarm action to publish to an Amazon SNS topic delivers the notification to the DevOps team, which is the standard, lowest-effort solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Amazon CloudWatch Logs Insights to query the RDS logs and trigger an SNS notification when CPU utilization is high.
Why it's wrong here
Logs Insights queries log events, not CloudWatch metrics, so it cannot evaluate the CPUUtilization datapoint or its 5-minute duration. It is tempting because it searches RDS log groups for patterns, which suits diagnosing slow queries after an alert fires, not triggering one.
- ✗
Enable AWS Trusted Advisor to automatically create a CloudWatch alarm on the CPU utilization metric.
Why it's wrong here
Trusted Advisor runs periodic checks against best-practise thresholds; it cannot create CloudWatch alarms or apply a sustained 5-minute 80% condition. It is tempting because it surfaces cost, security and fault-tolerance recommendations, which suits advisory reviews rather than metric-driven alerting.
- ✓
Create an Amazon CloudWatch alarm on the CPUUtilization metric with a period of 5 minutes and a threshold of 80, and set the alarm action to send a notification to an Amazon SNS topic.
Why this is correct
A CloudWatch alarm on CPUUtilization with a five-minute period and 80% threshold, notifying via Amazon SNS, directly matches the stated requirement to alert when utilisation exceeds 80% for more than five minutes, enabling investigation of the daily 10:00 AM spike.
- ✗
Create an AWS CloudTrail trail to monitor CPU utilization and trigger an AWS Lambda function to send an email notification.
Why it's wrong here
CloudTrail records API activity, not CloudWatch CPU metrics, so it cannot detect the 80% threshold breach. It is tempting because CloudTrail can drive Lambda automation, and it would be correct for alerting on configuration changes or suspicious API calls rather than resource utilisation.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Amazon RDS for PostgreSQL and wants to monitor database performance metrics such as CPU utilization, memory, and disk I/O. Which AWS service should be used to set up custom dashboards and alarms for these metrics?
easy- A.AWS X-Ray
- B.Amazon VPC Flow Logs
- C.AWS CloudTrail
- ✓ D.Amazon CloudWatch
Why D: Amazon CloudWatch (Option D) is the correct service for monitoring Amazon RDS performance metrics such as CPU utilization, memory, and disk I/O. CloudWatch provides built-in metrics for RDS, allows creation of custom dashboards to visualize these metrics, and supports setting alarms for proactive notifications. Option A (AWS X-Ray) is used for tracing and analyzing requests through applications, not for infrastructure metrics. Option B (Amazon VPC Flow Logs) captures IP traffic information for network troubleshooting, not database performance. Option C (AWS CloudTrail) logs API calls for auditing, not performance monitoring. Therefore, CloudWatch is the appropriate choice for this use case.
Variation 2. A company needs to monitor the CPU utilization of its Amazon RDS for PostgreSQL instance. The metric should be available in Amazon CloudWatch with a granularity of 1 minute. Which action should the team take?
easy- A.Install the CloudWatch agent on the RDS instance.
- B.Enable Enhanced Monitoring for the RDS instance.
- ✓ C.No additional configuration is needed; RDS automatically sends metrics to CloudWatch.
- D.Enable Performance Insights for the RDS instance.
Why C: Amazon RDS for PostgreSQL automatically publishes metrics, including CPU utilization, to CloudWatch with a default granularity of 1 minute for standard instances. No additional configuration is required to enable this basic monitoring. The metrics are collected by the RDS hypervisor layer and sent to CloudWatch without needing an agent or extra setup.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.