Skip to content
BytePatterns

DOP-C02 · Domain 4: Monitoring and Logging · 15% of the exam

Task 4.3: Automate monitoring and event management of complex environments.

Monitoring that acts on its own: EventBridge patterns and S3 Event Notifications, alarms that notify or recover, health checks, agents rolled out by Systems Manager, auto scaling across services, and AWS Config remediation.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 2

A production account runs all of its workloads in eu-west-1 and has a multi-Region CloudTrail trail that logs management events. The security team wants a message on an Amazon SNS topic within a minute or two whenever anyone creates an IAM access key in the account, without polling or scheduled queries. Which actions should the DevOps engineer take? (Choose TWO.)

  1. ACreate the rule on the default event bus in us-east-1, where events from IAM are recorded
  2. BCreate the rule on a custom event bus in eu-west-1 and have CloudTrail send its events to that bus directly
  3. CCreate the rule on the default event bus in eu-west-1, where all of the company's workloads and users operate
  4. DQuery the trail's events in CloudTrail Lake every two minutes and publish new CreateAccessKey calls to the topic
  5. EUse an event pattern with source aws.iam, detail-type AWS API Call via CloudTrail and eventName CreateAccessKey, with the SNS topic as target
Show the answer and why
  • ACreate the rule on the default event bus in us-east-1, where events from IAM are recorded

    Correct

    CloudTrail records events from global services such as IAM in us-east-1, and CloudTrail delivers its events to the default event bus only.

  • BCreate the rule on a custom event bus in eu-west-1 and have CloudTrail send its events to that bus directly

    Incorrect

    CloudTrail events are delivered only to the default event bus. A custom bus would need a forwarding rule from the default bus first.

  • CCreate the rule on the default event bus in eu-west-1, where all of the company's workloads and users operate

    Incorrect

    IAM events are recorded in us-east-1 regardless of where the caller works, so a rule in eu-west-1 never sees them.

  • DQuery the trail's events in CloudTrail Lake every two minutes and publish new CreateAccessKey calls to the topic

    Incorrect

    This is the polling the team wants to avoid, and CloudTrail Lake is no longer open to new customers.

  • EUse an event pattern with source aws.iam, detail-type AWS API Call via CloudTrail and eventName CreateAccessKey, with the SNS topic as target

    Correct

    API calls recorded by an active trail reach EventBridge with the detail type AWS API Call via CloudTrail, and a pattern on the event name selects CreateAccessKey.

EventBridge receives CloudTrail events only when a trail is logging, only on the default bus, and in the Region where CloudTrail records the event. For IAM, a global service, that Region is us-east-1.

Question 2 · choose 1

Developers sometimes add security group rules that allow SSH from 0.0.0.0/0 while troubleshooting. Policy says such rules must be removed automatically within minutes of being created, and the security team wants a record of each noncompliant group and of the fix. The team prefers AWS managed components over custom code. What should the DevOps engineer do?

  1. AUse the AWS Config managed rule restricted-ssh with automatic remediation by the AWS-DisablePublicAccessForSecurityGroup runbook
  2. BUse the AWS Config managed rule restricted-ssh and send an Amazon SNS notification to the security team for each noncompliant security group
  3. CSchedule a Lambda function every 5 minutes that scans every security group and deletes rules that allow SSH from anywhere
  4. DReview the security groups check in AWS Trusted Advisor every morning and remove the open rules that it reports
Show the answer and why
  • AUse the AWS Config managed rule restricted-ssh with automatic remediation by the AWS-DisablePublicAccessForSecurityGroup runbook

    Correct

    The rule marks groups that allow SSH from 0.0.0.0/0 as noncompliant when their configuration changes, and Config remediates through Systems Manager Automation runbooks such as this managed one.

  • BUse the AWS Config managed rule restricted-ssh and send an Amazon SNS notification to the security team for each noncompliant security group

    Incorrect

    This records and reports the problem, but someone still has to remove each rule by hand.

  • CSchedule a Lambda function every 5 minutes that scans every security group and deletes rules that allow SSH from anywhere

    Incorrect

    This is custom code, and it leaves no compliance record of the noncompliant groups and their remediation.

  • DReview the security groups check in AWS Trusted Advisor every morning and remove the open rules that it reports

    Incorrect

    A daily manual review does not remove rules within minutes and depends on people acting.

AWS Config evaluates the resource when it changes and can remediate automatically with an SSM Automation document. The managed rule detects the open SSH rule, and the managed runbook closes SSH and RDP from all addresses.

Question 3 · choose 1

A third-party firewall appliance writes a compressed log file to an S3 bucket every five minutes. Security analysts need the events from each new file to be searchable in an existing Amazon OpenSearch Service domain within a few minutes of the file's arrival. The appliance cannot send logs anywhere else. Which solution meets these requirements?

  1. ACreate an Amazon Data Firehose stream that uses the S3 bucket as its source and the OpenSearch Service domain as its destination
  2. BRun an AWS Glue crawler on the bucket every hour and let analysts query the new files with Amazon Athena
  3. CAdd a CloudWatch Logs subscription filter to the bucket that streams new log lines to the OpenSearch Service domain
  4. DConfigure an S3 Event Notification for new objects that invokes a Lambda function to parse each file and index its events
Show the answer and why
  • ACreate an Amazon Data Firehose stream that uses the S3 bucket as its source and the OpenSearch Service domain as its destination

    Incorrect

    Firehose streams take data written to them directly or read from sources such as Kinesis Data Streams. An S3 bucket is not one of the sources.

  • BRun an AWS Glue crawler on the bucket every hour and let analysts query the new files with Amazon Athena

    Incorrect

    This puts the data in Athena, not in the OpenSearch Service domain, and an hourly crawler misses the few-minute target.

  • CAdd a CloudWatch Logs subscription filter to the bucket that streams new log lines to the OpenSearch Service domain

    Incorrect

    Subscription filters stream log events from CloudWatch Logs log groups, not objects in S3 buckets.

  • DConfigure an S3 Event Notification for new objects that invokes a Lambda function to parse each file and index its events

    Correct

    New objects can trigger an event notification to Lambda, which runs code that parses the file and indexes it into OpenSearch Service.

When logs can land only in S3, an S3 Event Notification is the trigger. A Lambda function invoked for each new object can transform and index the data into OpenSearch Service within seconds to minutes.

Question 4 · choose 1

An internal service runs behind an internal Network Load Balancer in a primary VPC, with a standby copy behind another internal NLB. A Route 53 private hosted zone uses failover records for the service name, and the primary record needs a health check. The NLB's targets have only private IP addresses. Which health check configuration works?

  1. AA health check that monitors the primary NLB's private IP address on the service port over TCP
  2. BA health check that monitors a CloudWatch alarm whose metric math expression adds up the HealthyHostCount metric of both Availability Zones
  3. CA health check that monitors a same-account CloudWatch alarm on the primary NLB's HealthyHostCount metric at standard resolution
  4. DA health check that monitors an alarm in a central monitoring account, evaluated as 3 out of 5 high-resolution data points
Show the answer and why
  • AA health check that monitors the primary NLB's private IP address on the service port over TCP

    Incorrect

    Route 53 health checkers are outside the VPC, so they cannot reach a private IP address in it.

  • BA health check that monitors a CloudWatch alarm whose metric math expression adds up the HealthyHostCount metric of both Availability Zones

    Incorrect

    Route 53 does not support alarms that use metric math to query multiple CloudWatch metrics.

  • CA health check that monitors a same-account CloudWatch alarm on the primary NLB's HealthyHostCount metric at standard resolution

    Correct

    For private endpoints, a health check can monitor a CloudWatch alarm in the same account, and Route 53 supports standard-resolution metrics with statistics such as Minimum.

  • DA health check that monitors an alarm in a central monitoring account, evaluated as 3 out of 5 high-resolution data points

    Incorrect

    A health check can only monitor an alarm in its own account, and Route 53 supports neither high-resolution metrics nor M out of N alarms.

Endpoint health checks probe over the internet, so private resources are checked indirectly: a CloudWatch alarm watches a metric that reflects their health, and a Route 53 health check follows the alarm's data stream. Such alarms have restrictions on account, resolution, statistics and metric math.

Question 5 · choose 1

A capacity team wants an email each time one Auto Scaling group launches or terminates an instance, and each time a launch or termination fails, with the instance ID and the cause. The group is defined in a CloudFormation template. The team wants the notification set on the group itself, with no functions, event rules or custom actions to maintain, and launches must not be slowed down. What should the DevOps engineer configure?

  1. AA CloudWatch alarm on the group's GroupInServiceInstances metric with an email notification action
  2. BLaunch and termination lifecycle hooks on the group that send each event to an SNS topic with an email subscription
  3. CAuto Scaling SNS notifications on the group for launch, terminate and both error events, sent to an email topic
  4. DCloudTrail management events for RunInstances and TerminateInstances delivered to an S3 bucket
Show the answer and why
  • AA CloudWatch alarm on the group's GroupInServiceInstances metric with an email notification action

    Incorrect

    The alarm reacts when capacity crosses a threshold, but it does not report each launch or termination with its cause.

  • BLaunch and termination lifecycle hooks on the group that send each event to an SNS topic with an email subscription

    Incorrect

    Lifecycle hooks suit custom actions during launch or termination, but they hold each instance in a wait state until the action completes or times out.

  • CAuto Scaling SNS notifications on the group for launch, terminate and both error events, sent to an email topic

    Correct

    The group can notify an SNS topic for these four event types, one message per instance, including the instance ID and the cause.

  • DCloudTrail management events for RunInstances and TerminateInstances delivered to an S3 bucket

    Incorrect

    CloudTrail records the API calls for auditing, but storing them in S3 does not email the team or explain failed scaling activities.

EC2 Auto Scaling sends SNS notifications for launch, terminate, launch error and terminate error events, configured on the group. Delivery is best effort; EventBridge is the alternative when more event types or targets are needed.

Question 6 · choose 1

Developers often leave large EBS-backed test instances running. Some of them run long tests at night and on weekends, so the instances must keep running while they are busy, whatever the time. An instance that has been idle for six hours must stop on its own so that its compute charges end, and it must not be terminated, because its volumes hold test data. No custom code should be needed. What should the DevOps engineer configure?

  1. AA CloudWatch alarm on each instance's low CPU utilization over six hours with the EC2 terminate action
  2. BA Systems Manager Quick Setup Resource Scheduler configuration that stops tagged instances every evening at 19:00
  3. CAn AWS Budgets action that stops the test instances when the monthly budget passes 90 percent
  4. DA CloudWatch alarm on each instance's low CPU utilization over six hours with the EC2 stop action
Show the answer and why
  • AA CloudWatch alarm on each instance's low CPU utilization over six hours with the EC2 terminate action

    Incorrect

    The alarm detects idleness, but terminating deletes instances that must be kept.

  • BA Systems Manager Quick Setup Resource Scheduler configuration that stops tagged instances every evening at 19:00

    Incorrect

    A schedule stops instances without code, but it ignores whether they are idle and would stop the night-time tests.

  • CAn AWS Budgets action that stops the test instances when the monthly budget passes 90 percent

    Incorrect

    Budget actions stop targeted instances when spending crosses a threshold, not when an instance is idle.

  • DA CloudWatch alarm on each instance's low CPU utilization over six hours with the EC2 stop action

    Correct

    Alarm actions can stop idle instances, which keeps their EBS volumes and lets them be started again later.

CloudWatch alarm actions can stop, terminate, reboot or recover EC2 instances. A stop action on an idle-CPU alarm ends compute charges while keeping the instance and its EBS volumes for later use.

Question 7 · choose 1

Security wants a ticket created automatically whenever any AWS Config rule in an account marks a resource as noncompliant, with the rule name and the resource ID in the ticket. The ticketing system accepts calls from a Lambda function. What should the DevOps engineer configure?

  1. AA daily Config advanced query that lists noncompliant resources and emails the list
  2. BAn SNS subscription on the Config delivery channel topic with email to the security team
  3. CAn EventBridge rule for Config Rules Compliance Change events targeting the function
  4. DA CloudWatch alarm on the number of compliant resources in the account
Show the answer and why
  • AA daily Config advanced query that lists noncompliant resources and emails the list

    Incorrect

    A daily list is not an automatic ticket per change.

  • BAn SNS subscription on the Config delivery channel topic with email to the security team

    Incorrect

    Email from the delivery channel does not create tickets.

  • CAn EventBridge rule for Config Rules Compliance Change events targeting the function

    Correct

    Config sends compliance change events to EventBridge, and a rule can invoke the function for each one.

  • DA CloudWatch alarm on the number of compliant resources in the account

    Incorrect

    A count does not identify the rule and resource for each ticket.

AWS Config emits events to EventBridge, including Config Rules Compliance Change events, which rules can route to targets such as Lambda.

Question 8 · choose 1

When a payment service logs a line that contains FATAL, the on-call team must receive a chat message within seconds that includes the full log line. An existing metric filter and alarm only says that the count went above zero. What should the DevOps engineer add?

  1. AA shorter period on the existing alarm so that it fires sooner
  2. BA Logs Insights scheduled query every hour that sends its results to the team by email
  3. CAn export task that copies the log group to S3 every few minutes for the team
  4. DA subscription filter for FATAL that sends matching events to a Lambda function for chat
Show the answer and why
  • AA shorter period on the existing alarm so that it fires sooner

    Incorrect

    The alarm would still not include the log line.

  • BA Logs Insights scheduled query every hour that sends its results to the team by email

    Incorrect

    Hourly results are not delivered within seconds.

  • CAn export task that copies the log group to S3 every few minutes for the team

    Incorrect

    Exports are not a real-time alerting path.

  • DA subscription filter for FATAL that sends matching events to a Lambda function for chat

    Correct

    Subscriptions give a real-time feed of matching log events to Lambda for custom processing.

Metric filters count matches for alarms, while subscription filters deliver the matching log events themselves to Lambda, Kinesis or Firehose in near real time.

Question 9 · choose 1

A sandbox account sometimes runs up large bills when experiments are left running. Finance wants AWS to stop new resource creation in that account automatically once forecast spend passes the monthly limit, without custom code. The account is a member of an organization. What should the DevOps engineer configure from the management account?

  1. AA budget alert that emails the account owner when forecast spend passes the limit
  2. BA budget action that applies an SCP denying resource creation to the sandbox account
  3. CA budget action that stops all EC2 and RDS instances in the sandbox account
  4. DA Cost Anomaly Detection monitor that sends alerts to an SNS topic
Show the answer and why
  • AA budget alert that emails the account owner when forecast spend passes the limit

    Incorrect

    An email does not stop resource creation.

  • BA budget action that applies an SCP denying resource creation to the sandbox account

    Correct

    Budget actions can apply an SCP to another account from the management account when a threshold is reached.

  • CA budget action that stops all EC2 and RDS instances in the sandbox account

    Incorrect

    From the management account, actions cannot target instances in another account, and stopping does not block creation.

  • DA Cost Anomaly Detection monitor that sends alerts to an SNS topic

    Incorrect

    Anomaly alerts notify but do not stop resource creation.

AWS Budgets actions can apply IAM policies or SCPs, or target EC2 and RDS instances in the same account. SCP actions from the management account can restrict other accounts.

Practise domain 4 →Practise all domains →