SAA-C03 Design Cost-Optimized Architectures Practice Question
A team runs an EC2-based service and ships logs to Amazon CloudWatch Logs. They enabled long log retention and turned on detailed monitoring to improve troubleshooting. Their monthly CloudWatch costs have grown unexpectedly. Compliance requires that the logs remain available in CloudWatch Logs (for querying and audits) for 90 days, and alerts/alarms do not require detailed EC2 monitoring. What change best reduces cost while meeting requirements?
⚠ Common exam trap
Test-takers frequently think sampling logs or moving them to S3 is acceptable, but the requirement explicitly states logs must remain available in CloudWatch Logs for querying and audits, making those options non-compliant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the CloudWatch Logs retention to 90 days and disable detailed EC2 monitoring (use standard monitoring) for the instances
Reduces costs by setting CloudWatch Logs retention to exactly 90 days (meeting compliance) and disabling detailed monitoring (which incurs per-minute metrics charges) in favor of standard 5-minute monitoring. This directly addresses the two main cost drivers—long retention and detailed EC2 monitoring—while preserving the required 90-day log availability for queries and audits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Keep the current long retention and detailed monitoring; reduce the log volume by sampling 10% of events
Why it's wrong here
Sampling 10% of events would reduce log ingest and storage volume, but it discards 90% of log events. The compliance requirement explicitly states that the full log data must remain available in CloudWatch Logs for 90 days, so partial retention is not acceptable. Additionally, it leaves detailed EC2 monitoring enabled, so the per-instance metric costs from detailed monitoring remain unchanged. Thus this option fails both the compliance and the cost-reduction objectives.
- ✓
Set the CloudWatch Logs retention to 90 days and disable detailed EC2 monitoring (use standard monitoring) for the instances
Why this is correct
CloudWatch Logs storage costs are driven primarily by retention period. Setting retention to exactly 90 days reduces storage cost while meeting compliance. Disabling detailed EC2 monitoring reduces the number/granularity of metrics (detailed is billed more than standard), lowering monitoring cost without impacting alarms that don’t require high-resolution metrics.
- ✗
Move all logs to S3 immediately and delete the CloudWatch log groups to reduce costs
Why it's wrong here
Deleting the CloudWatch log groups would remove the logs from CloudWatch Logs before the required 90-day audit window. Even if data is exported to S3, this does not satisfy the stated compliance requirement that logs remain available in CloudWatch Logs for 90 days.
- ✗
Increase CloudWatch alarm thresholds to reduce the number of metric datapoints
Why it's wrong here
Increasing CloudWatch alarm thresholds only changes when an alarm enters an ALARM state; it does not alter how often CloudWatch collects or stores EC2 metrics. Metric collection frequency is determined by the monitoring mode: standard (5-minute) vs. detailed (1-minute), and both are billed per metric regardless of alarm settings. Since thresholds do not influence the number of datapoints ingested or the billing granularity, this change would have virtually no effect on the unexpected cost increase. It also risks masking real operational issues if alarms become too loose.
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.