Deploy the CloudWatch agent as a StatefulSet with IRSA and CloudWatchAgentServerPolicy, and configure the OIDC provider

Answer Correct answer: A, C, E — deploy the CloudWatch agent as a StatefulSet with IRSA and CloudWatchAgentServerPolicy, plus an OIDC provider.

A company has a web application that is hosted on an Amazon Elastic Kubernetes Service (Amazon EKS) cluster. The EKS cluster runs on AWS Fargate that is available through an internet-facing Application Load Balancer. The application is experiencing stability issues that lead to longer response times. A DevOps engineer needs to configure observability in Amazon CloudWatch to troubleshoot the issue. The solution must provide only the minimum necessary permissions. Which combination of steps will meet these requirements? (Choose three.)

  1. Deploy the CloudWatch agent as a Kubernetes StatefulSet to the EKS cluster. Correct Answer
  2. Deploy the AWS Distro for OpenTelemetry Collector as a Kubernetes DaemonSet to the EKS cluster.
  3. Associate a Kubernetes service account with an IAM role by using IAM roles for service accounts in Amazon EKS. Use the CloudWatchAgentServerPolicy AWS managed policy. Correct Answer
  4. Associate a Kubernetes service account with an IAM role by using IAM roles for service accounts in Amazon EKS. Use the CloudWatchAgentAdminPolicy AWS managed policy.
  5. Configure an IAM OpenID Connect (OIDC) provider for the EKS cluster. Correct Answer

Community Votes

BCE
100%

100% of anonymous learners picked answer BCE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

AWS documents that Daemonsets aren't supported on Fargate and that a daemon must be reconfigured as a sidecar container, which eliminates both the DaemonSet collector in B and any DaemonSet-based agent (B). The CloudWatch agent deployed as a StatefulSet is the viable option (A). Since Fargate pods have no access to the instance metadata service, IRSA is required, which in turn requires an OIDC provider configured for the cluster (E). For least privilege, the service account role uses CloudWatchAgentServerPolicy rather than CloudWatchAgentAdminPolicy, since the agent needs to publish metrics and logs but not administer CloudWatch resources (C rather than D).

The cluster runs on AWS Fargate, which changes how the observability agent must be deployed. Fargate does not support DaemonSets, so the CloudWatch agent is deployed as a Kubernetes StatefulSet rather than the AWS Distro for OpenTelemetry collector as a DaemonSet, which cannot run there. Because Fargate pods cannot use the instance metadata service for credentials, the agent must obtain them through IAM roles for service accounts, which requires an IAM OpenID Connect provider for the cluster, and the service account role is given CloudWatchAgentServerPolicy to satisfy the minimum-necessary-permissions requirement rather than the broader admin policy.

Deploying the AWS Distro for OpenTelemetry collector as a Kubernetes DaemonSet (B) — the AWS documentation states plainly that Daemonsets aren't supported on Fargate and that daemons must be reconfigured as sidecar containers, so this deployment cannot run on a Fargate cluster; several commenters made exactly this point. Using CloudWatchAgentAdminPolicy for the service account role (D) — the requirement is minimum necessary permissions, and the agent only needs to publish telemetry, not administer CloudWatch. Omitting the OIDC provider (E) — without it, IAM roles for service accounts cannot federate, so the pod cannot obtain AWS credentials at all.

Community Discussion (5 comments)

CHRIS12722222 👍 5 Selected: AC
https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/deploy-container-insights-EKS.html - No daemonsets for fargate - CloudWatchAgentServerPolicy is correct - controlplane logging
SysOps 👍 1 Selected: ACE
A instead of B only because Daemonsets aren’t supported on Fargate
jojewi8143 👍 2 Selected: AC
Changed mind to ACF. Daemonsets arent supported on Fargate, B is not possible. https://docs.aws.amazon.com/eks/latest/userguide/fargate.html
jojewi8143 👍 1 Selected: BCE
im for bce
matt200 👍 4 Selected: BCE
B: AWS Distro for OpenTelemetry (ADOT) is the recommended solution for collecting metrics and traces from EKS clusters E: OIDC provider is required to use IRSA A: Incorrect because For EKS on Fargate, ADOT is the recommended solution F: Incorrect because this alone won't provide the application-level observability needed

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The defining constraint is that the cluster runs on AWS Fargate, and AWS documentation states that Daemonsets aren't supported on Fargate and that any daemon must be reconfigured to run as a sidecar container in the pod. That rules out the DaemonSet-based OpenTelemetry collector in option B and makes deploying the CloudWatch agent as a Kubernetes StatefulSet the workable approach (A). Because Fargate pods cannot use the instance metadata service to obtain AWS credentials, the agent must be granted permissions through IAM roles for service accounts, which in turn requires an IAM OpenID Connect provider to be configured for the EKS cluster (E). To satisfy the minimum-necessary-permissions constraint, the service account role is bound to CloudWatchAgentServerPolicy, which permits publishing the telemetry the agent produces without granting CloudWatch administrative rights that CloudWatchAgentAdminPolicy would (C). A, C, and E are the correct combination.

Why the Other Options Are Wrong

B deploys the AWS Distro for OpenTelemetry collector as a Kubernetes DaemonSet. AWS Fargate documentation explicitly states that Daemonsets aren't supported on Fargate and recommends reconfiguring a daemon as a sidecar container, so this deployment cannot be scheduled on a Fargate cluster; CHRIS12722222, SysOps, and jojewi8143 all raised this, with jojewi8143 changing to a StatefulSet-based answer for that reason. D binds CloudWatchAgentAdminPolicy to the service account role, which grants CloudWatch administrative permissions well beyond what an observability agent needs, directly contradicting the requirement for only the minimum necessary permissions. The remaining option combination using B cannot run on Fargate at all. A, C, and E are correct.

Community Comment Notes

Community votes favored B,C,E (38), but that group is incorrect on the decisive technical point. Several of the highest-rated comments, including CHRIS12722222 with the documentation link, SysOps, and jojewi8143, established that DaemonSets are not supported on EKS Fargate, which invalidates B; matt200, who favored B,C,E, described the OpenTelemetry collector as generally recommended but did not address the Fargate restriction. The documented Fargate limitation takes precedence over the vote count.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide