SAP-C02 Continuous Improvement for Existing Solutions Practice Question
A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local instance storage. The operations team wants to centralize log analysis and enable real-time alerting on specific error patterns. The solution must be highly available and require minimal changes to the application. Which approach should a solutions architect recommend?
⚠ Common exam trap
The trap here is assuming that application code changes or custom scripts are needed for log centralization, when the CloudWatch agent can handle it without modifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install and configure the Amazon CloudWatch agent on each instance to send logs to Amazon CloudWatch Logs, then use metric filters and alarms for alerting.
The CloudWatch agent provides a managed way to collect logs from EC2 instances and send them to CloudWatch Logs. Metric filters can monitor for specific patterns and trigger alarms in near real-time. This requires no application changes and is highly available, making it the most efficient solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the application to write logs directly to Amazon Kinesis Data Firehose, which delivers them to Amazon S3 for analysis.
Why it's wrong here
Modifying the application to use Kinesis Data Firehose requires code changes and adds complexity. While Firehose can deliver logs to S3, it does not provide real-time alerting out of the box. You would need additional services like Lambda and CloudWatch to analyze and alert, increasing the effort.
- ✗
Set up an AWS Lambda function that periodically connects to each instance via SSH to retrieve logs and publish them to Amazon SNS.
Why it's wrong here
This approach is not scalable or secure, as it requires SSH access and custom scripting. It introduces delays and is not real-time. It also adds significant operational overhead and does not leverage managed AWS services for log centralization and alerting.
- ✗
Configure the instances to mount a shared Amazon EFS file system and write logs there, then use a third-party tool to analyze the logs.
Why it's wrong here
Using Amazon EFS for log storage introduces a shared file system dependency and does not provide native alerting. It requires additional tooling for analysis and alerting, and EFS may not be ideal for high-volume log writes. This approach also requires application changes to write to the mounted path.
- ✓
Install and configure the Amazon CloudWatch agent on each instance to send logs to Amazon CloudWatch Logs, then use metric filters and alarms for alerting.
Why this is correct
The CloudWatch agent can collect logs from local files and send them to CloudWatch Logs without application changes. Metric filters can extract patterns and trigger alarms. This solution is highly available because CloudWatch Logs is a regional service, and it provides real-time alerting with minimal operational overhead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.