nerdexam
AmazonAmazon

DOP-C02 · Question #19

DOP-C02 Question #19: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #19. The question stem and answer options stay visible for context.

Submitted by manish99· Mar 6, 2026Monitoring & Logging

Question

A company has deployed an application in a production VPC in a single AWS account. The application is popular and is experiencing heavy usage. The company's security team wants to add additional security, such as AWS WAF, to the application deployment. However, the application's product manager is concerned about cost and does not want to approve the change unless the security team can prove that additional security is necessary. The security team believes that some of the application's demand might come from users that have IP addresses that are on a deny list. The security team provides the deny list to a DevOps engineer. If any of the IP addresses on the deny list access the application, the security team wants to receive automated notification in near real time so that the security team can document that the application needs additional security. The DevOps engineer creates a VPC flow log for the production VPC. Which set of additional steps should the DevOps engineer take to meet these requirements MOST cost-effectively?

Options

  • ACreate a log group in Amazon CloudWatch Logs. Configure the VPC flow log to capture accepted
  • BCreate an Amazon S3 bucket for log files. Configure the VPC flow log to capture all traffic and to
  • CCreate an Amazon S3 bucket for log files. Configure the VPC flow log to capture accepted traffic
  • DCreate a log group in Amazon CloudWatch Logs. Create an Amazon S3 bucket to hold query

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#VPC Flow Logs#CloudWatch Logs#Security Auditing#Traffic Analysis
Full DOP-C02 PracticeBrowse All DOP-C02 Questions