Enable EventBridge schema discovery, monitor EventBridge and Step Functions metrics, and check failed invocation metrics
A security team sets up a workflow that invokes an AWS Step Functions workflow when Amazon EventBridge matches specific events. The events can be generated by several AWS services. AWS CloudTrail records user activities. The security team notices that some important events do not invoke the workflow as expected. The CloudTrail logs do not indicate any direct errors related to the missing events. Which combination of steps will identify the root cause of the missing event invocations? (Choose three.)
Community Votes
100% of anonymous learners picked answer ABE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The three steps localize the failure at each stage of the delivery path (A, B, E). Schema discovery addresses whether the event pattern can match the events at all (A). Metrics on both services distinguish a matching problem from a delivery or execution problem (B). The failed invocations metric specifically surfaces cases where EventBridge matched the event but could not invoke the target because the rule's IAM execution role lacks permissions, which is a failure mode that produces no CloudTrail error and is therefore easily missed (E). Options C and D do not address the EventBridge side, where the pattern and the invocation live.
Some expected events never invoke the Step Functions workflow and CloudTrail shows no direct errors, so the cause must lie in the EventBridge rule, its pattern, or the target invocation. Enabling schema discovery on the event bus reveals the actual event schema so the rule's event pattern can be checked against what the services really emit. Monitoring EventBridge and Step Functions metrics with alerts on anomalies shows whether events are being matched but not delivered, or whether the executions are failing. Finally, reviewing the EventBridge failed invocations metrics identifies whether the rule's IAM execution role lacks the permissions to invoke the workflow, which would produce delivery failures that appear as successful event matches.
Creating a Lambda logging function to monitor and log events from EventBridge (C) — this adds a function and gives visibility into events after they reach the bus, but it does not tell you whether the rule's event pattern matched, nor whether invocation failed, so it does not isolate the delivery stages where the failure occurred. Reviewing the Step Functions execution history (D) — if the workflow was never invoked there is no execution history to review; that absence is itself the symptom, so examining it cannot reveal why the invocation never happened. Impromptu's point about the execution role is what makes E necessary, since the permission is granted to the EventBridge rule's IAM execution role rather than on the Step Functions side.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When events that should invoke the workflow do not, and CloudTrail records no direct errors, the failure must be located within the EventBridge delivery path rather than in the event source. Each of the three chosen steps interrogates a different stage of that path. Enabling EventBridge schema discovery on the event bus lets the team see the actual schema of the events being emitted and therefore determine whether the rule's event pattern can match them at all, which is the first place a mismatch would occur (A). Setting up CloudWatch monitoring and alerts on EventBridge and Step Functions metrics, including anomalies in event patterns and workflow invocations, shows whether events are arriving and matching but not being delivered, or whether invocations are occurring but executions are failing, which separates the pattern problem from the delivery problem (B). Finally, reviewing the EventBridge failed invocations metrics confirms whether the IAM execution role attached to the rule has sufficient permissions to invoke the Step Functions workflow; Impromptu explained that this permission lives on the EventBridge rule's execution role rather than on the Step Functions side, so a missing permission produces failed invocations with no CloudTrail error at all (E). Together A, B, and E localize the root cause. A, B, and E are the correct combination.Why the Other Options Are Wrong
C configures an AWS Lambda logging function to monitor and log events from EventBridge to provide more detail about processed events. This adds a function to operate and only reports on events that have already reached the bus, so it cannot distinguish between an event pattern that fails to match and an invocation that fails; it therefore does not isolate which stage dropped the event. D reviews the Step Functions execution history for failure or timeout patterns. The scenario states that events are not invoking the workflow as expected, so no new executions are being started and there is consequently no execution history for those missing events; the absence of history is the symptom rather than a diagnostic source, so this step cannot explain why the invocation never occurred. A, B, and E are correct.Community Comment Notes
Community voted A,B,E unanimously. Srikantha enumerated the three steps and their purposes, validating the event structure with schema discovery, monitoring EventBridge and Step Functions metrics, and checking failed invocations metrics for IAM permissions. luisfsm_111 agreed, emphasizing the execution role reasoning. Impromptu noted that the answer should include E rather than the alternative F because the EventBridge rule's IAM execution role needs permission to invoke the Step Functions function, and that this permission is not configured on the Step Functions side. uncledana selected A, B, and F, which differs from the majority only in the third element and reflects the same missing-option pattern seen elsewhere in this exam export. No alternative received majority support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →