‹ All DOP-C02 questions

AWS Certified DevOps Engineer – Professional (DOP-C02) · Test 7 · question 9 of 10

Incident and Event Responseeasy

An operations team wants a critical CloudWatch alarm on an EC2 instance to trigger an automatic response without any custom code or servers. When the alarm enters the ALARM state, the instance must be restarted by a managed runbook, and the on-call engineers must be notified by email and in their team chat channel at the same time.

Which configuration meets these requirements?

Select one answer
Show answer and explanation

Answer:

  • C. An EventBridge rule matching the alarm state change to ALARM, with an SSM Automation runbook target and an SNS topic target that feeds email and AWS Chatbot

CloudWatch alarms emit state change events to EventBridge. A single rule that matches the alarm entering ALARM can fan out to several targets: a Systems Manager Automation runbook (for example the AWS-managed AWS-RestartEC2Instance document) performs the remediation, and an SNS topic delivers the notification to email subscribers and to a chat channel through AWS Chatbot (now called Amazon Q Developer in chat applications). Both happen in parallel, using only managed services and no code.

Option A works but is the opposite of "no custom code or servers": polling alarms on a schedule adds latency, a Lambda function to maintain, and hand-written remediation logic that a managed runbook already provides.

Option B notifies but does not remediate. The restart stays manual, which fails the requirement for an automatic response.

Option D is a distractor on a closed service. AWS Systems Manager Incident Manager is no longer open to new customers, so it is not a recommended design for a new team; existing customers can continue to use it. The EventBridge, Automation and SNS combination in option C is built from services that remain open to everyone.

Reference: Amazon CloudWatch alarm events and EventBridge

Practice Test 7 ›