EKS Cluster Metrics and Log Collection with CloudWatch

Answer Correct answer: B, C, E — Deploy AWS Distro for OpenTelemetry to collect metrics/logs, create CloudWatch alarms for performance thresholds, and create a log filter alarm for autoscaler errors.

A company has deployed an Amazon Elastic Kubernetes Service (Amazon EKS) cluster with Amazon EC2 node groups. The company's DevOps team uses the Kubernetes Horizontal Pod Autoscaler and recently installed a supported EKS cluster Autoscaler. The DevOps team needs to implement a solution to collect metrics and logs of the EKS cluster to establish a baseline for performance. The DevOps team will create an initial set of thresholds for specific metrics and will update the thresholds over time as the cluster is used. The DevOps team must receive an Amazon Simple Notification Service (Amazon SNS) email notification if the initial set of thresholds is exceeded or if the EKS cluster Autoscaler is not functioning properly. The solution must collect cluster, node, and pod metrics. The solution also must capture logs in Amazon CloudWatch. Which combination of steps should the DevOps team take to meet these requirements? (Choose three.)

  1. Deploy the CloudWatch agent and Fluent Bit to the cluster. Ensure that the EKS cluster has appropriate permissions to send metrics and logs to CloudWatch.
  2. Deploy AWS Distro for OpenTelemetry to the cluster. Ensure that the EKS cluster has appropriate permissions to send metrics and logs to CloudWatch. Correct Answer
  3. Create CloudWatch alarms to monitor the CPU, memory, and node failure metrics of the cluster. Configure the alarms to send an SNS email notification to the DevOps team if thresholds are exceeded. Correct Answer
  4. Create a CloudWatch composite alarm to monitor a metric log filter of the CPU, memory, and node metrics of the cluster. Configure the alarm to send an SNS email notification to the DevOps team when anomalies are detected.
  5. Create a CloudWatch alarm to monitor the logs of the Autoscaler deployments for errors. Configure the alarm to send an SNS email notification to the DevOps team if thresholds are exceeded. Correct Answer

Community Insight

The exam tests knowledge of the modern, recommended stack (ADOT) versus legacy agents (CloudWatch Agent), combined with specific alarm configurations for both performance metrics and operational logs.

This question addresses the standard AWS-recommended architecture for collecting metrics and logs from Amazon EKS clusters using AWS Distro for OpenTelemetry (ADOT) and configuring CloudWatch alarms for notification.

Many learners select Option A (CloudWatch Agent + Fluent Bit) because it is a historically common method, failing to recognize that AWS now recommends ADOT for EKS as the primary solution for metrics and logs.

Community Discussion (5 comments)

Srikantha 👍 1 Selected: AC
Explanation To collect logs and metrics from the EKS cluster, nodes, and pods, and to ensure notifications are sent when thresholds are exceeded, we need: A mechanism to collect logs and metrics (Option A). Alarms for key cluster performance metrics (Option C). Alarms to detect Autoscaler failures (Option F).
matt200 👍 1 Selected: BCE
Correct: B. Deploy AWS Distro for OpenTelemetry (ADOT): ADOT is the recommended solution for collecting metrics and logs from EKS clusters E. Create CloudWatch alarm for Autoscaler logs: Monitors Autoscaler functionality through log analysis Wrong: A. Deploy CloudWatch agent and Fluent Bit: While this would work, it's not the recommended approach for EKS F. Create CloudWatch alarm with metric log filter for Autoscaler: Direct log monitoring (Option E) is more appropriate
luisfsm_111 👍 3 Selected: AC
A collects metrics and logs, C create the alarms and F monitors the auto scaler
tinyshare 👍 1 Selected: ACE
The question asks to "collect metrics and logs". You need to install the CloudWatch Agent which is A. You need to collect metrics which is C. You need to collect logs which is E.
ArunRav 👍 4 Selected: AC
A- To collect the cloudwatch logs and send to cloudwatch service. C - To setup Alarms F - To monitor and alert

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct combination is B, C, and E. Option B is critical because AWS Distro for OpenTelemetry (ADOT) is the officially recommended solution for collecting metrics and logs from EKS clusters, replacing the older dual-agent approach of CloudWatch Agent and Fluent Bit. Option C correctly implements the requirement to monitor CPU, memory, and node failure metrics via CloudWatch Alarms, which triggers SNS notifications when thresholds are exceeded. Option E addresses the specific requirement to monitor the Autoscaler's functionality by creating an alarm on log patterns (log filters) within the Autoscaler deployment logs; if errors occur, the alarm triggers.

Why the Other Options Are Wrong

Option A is incorrect because while technically functional, the CloudWatch Agent and Fluent Bit combination is considered legacy for EKS. The exam prioritizes the current best practice, which is ADOT. Option D is incorrect because Composite Alarms are designed to aggregate status from other alarms (e.g., logical AND/OR conditions), not to directly process metric log filters or detect anomalies in raw logs.

Community Comment Notes

Several community members incorrectly selected AC or ACE, often missing the nuance between legacy and recommended collection tools. As user 'matt200' noted, ADOT is the "recommended solution," highlighting why A is wrong. Another commenter stated, "You need to collect metrics which is C. You need to collect logs which is E," but failed to identify that B is the mechanism to get those logs/metrics into CloudWatch in the first place, whereas A is the outdated mechanism.

Official Reference

Exam Strategy

Always look for the 'recommended' or 'best practice' tool over the 'legacy' tool in cloud certification exams. For EKS observability, ADOT is the standard answer unless specified otherwise.

Frequently Asked Questions

Why is Option A wrong if it works?

Option A uses the legacy CloudWatch Agent and Fluent Bit. AWS now recommends AWS Distro for OpenTelemetry (ADOT) for EKS as it provides a unified, standardized way to collect metrics and logs.

How do you monitor the Autoscaler in Option E?

You use a CloudWatch Metric Log Filter Alarm. This type of alarm monitors log groups for specific patterns (like error messages) in the Autoscaler's deployment logs.

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide