Courseiva

SAP-C02 Continuous Improvement for Existing Solutions Practice Question

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local instance storage. The operations team wants to centralize log analysis and enable near-real-time monitoring for errors. They also want to archive logs for long-term compliance. The logs are generated continuously and can be large in volume. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that CloudTrail or detailed monitoring can capture application logs, or that the CloudWatch agent can send logs directly to S3, when in fact CloudWatch Logs is the central service for log ingestion and S3 archival requires an additional streaming mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CloudWatch Logs subscription filter to stream logs to Amazon Kinesis Data Firehose, which delivers them to Amazon S3 for archival.

To centralize and monitor logs in near-real-time, the CloudWatch agent should be installed to send logs to CloudWatch Logs. For long-term archival, a subscription filter can stream logs to Kinesis Data Firehose, which delivers to S3. CloudTrail and detailed monitoring do not capture application logs, and the CloudWatch agent does not send logs directly to S3.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudTrail to capture log data from the instances and store it in an S3 bucket.

    Why it's wrong here

    CloudTrail records API activity in your AWS account, not application logs from EC2 instances. It does not capture logs written to local instance storage. While CloudTrail can deliver logs to S3, it is not suitable for application log centralization or near-real-time monitoring of application errors. This option misinterprets the purpose of CloudTrail.

  • ✗

    Enable detailed monitoring on the EC2 instances to capture application logs and store them in CloudWatch Logs.

    Why it's wrong here

    Detailed monitoring in EC2 provides metrics at 1-minute intervals, not application logs. It does not capture log data from the instance's file system. Enabling detailed monitoring only affects the frequency of metric data, not logs. This option confuses monitoring metrics with log collection, and would not centralize logs or enable log analysis.

  • ✗

    Configure the CloudWatch agent to also send logs to Amazon S3 for long-term archival.

    Why it's wrong here

    The CloudWatch agent does not directly send logs to S3. It sends logs to CloudWatch Logs, which can then be exported to S3 using subscription filters or export tasks. While S3 can be used for archival, this option incorrectly states that the agent can send logs directly to S3. The correct approach is to use CloudWatch Logs as the central repository and then archive to S3 separately.

  • ✓

    Create a CloudWatch Logs subscription filter to stream logs to Amazon Kinesis Data Firehose, which delivers them to Amazon S3 for archival.

    Why this is correct

    CloudWatch Logs subscription filters can stream log events to Kinesis Data Firehose, which can then deliver them to Amazon S3 for durable, long-term storage. This provides a scalable and reliable archival solution. It complements the near-real-time monitoring in CloudWatch Logs and meets the compliance requirement for log retention in S3.

  • ✓

    Install and configure the Amazon CloudWatch agent on each instance to send logs to CloudWatch Logs.

    Why this is correct

    The CloudWatch agent can collect logs from EC2 instances and send them to CloudWatch Logs in near-real-time. This enables centralized log analysis, metric filters for errors, and alarms. It is a managed service that scales with log volume and integrates with other AWS services for monitoring and alerting. This directly addresses the need for near-real-time monitoring and centralization.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.