Courseiva

SAP-C02 Continuous Improvement for Existing Solutions Practice Question

A company has an application that runs on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local disk. The company wants to centralize log storage and enable near-real-time analysis of the logs. The company also wants to retain the logs for 7 years for compliance. The logs are currently stored in a file on each instance. The company wants a solution that requires minimal changes to the application and is cost-effective. Which solution meets these requirements?

⚠ Common exam trap

The trap here is assuming that CloudWatch Logs alone is cost-effective for 7-year retention, when S3 is far cheaper for long-term archival.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install and configure the Amazon CloudWatch agent on each instance to send logs to CloudWatch Logs. Configure a subscription filter to stream logs to Amazon Kinesis Data Firehose, which delivers to Amazon S3. Use Amazon Athena for analysis.

The combination of the CloudWatch agent, subscription filters, Kinesis Data Firehose, and Amazon S3 provides a managed, near-real-time log pipeline with minimal application changes. Logs are centralized in CloudWatch Logs, streamed to S3 for cost-effective long-term retention, and can be analyzed with Athena. This meets the compliance, analysis, and cost requirements without modifying the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the application to write logs directly to Amazon S3 and use Amazon Athena for analysis.

    Why it's wrong here

    Writing logs directly to S3 from the application requires code changes, which the company wants to minimize. While S3 is cost-effective for long-term storage and Athena can analyze logs, the application would need to be modified to use the AWS SDK to put objects. This is not minimal change. Additionally, near-real-time analysis with Athena requires partitioning and may have latency. This option is not ideal for minimal changes and near-real-time analysis.

  • ✓

    Install and configure the Amazon CloudWatch agent on each instance to send logs to CloudWatch Logs. Configure a subscription filter to stream logs to Amazon Kinesis Data Firehose, which delivers to Amazon S3. Use Amazon Athena for analysis.

    Why this is correct

    The CloudWatch agent centralizes logs with minimal application changes. A subscription filter can stream logs in near-real-time to Kinesis Data Firehose, which reliably delivers them to Amazon S3 for long-term, cost-effective storage. Athena can then query the logs directly from S3. This solution meets all requirements: centralized logging, near-real-time analysis, 7-year retention, minimal changes, and cost-effectiveness.

  • ✗

    Install and configure the Amazon CloudWatch agent on each instance to send logs to CloudWatch Logs. Set the retention period to 7 years and use CloudWatch Logs Insights for analysis.

    Why it's wrong here

    CloudWatch Logs can centralize logs and provide near-real-time analysis with Logs Insights. However, setting retention to 7 years in CloudWatch Logs can become expensive because the cost is based on ingestion and storage. For long-term archival, it is more cost-effective to export logs to Amazon S3. CloudWatch Logs also has a maximum retention of 10 years, so 7 years is possible but not the most cost-effective for compliance. This option meets requirements but at higher cost.

  • ✗

    Use AWS Systems Manager to run a script on each instance that periodically uploads log files to Amazon S3. Use Amazon QuickSight for analysis.

    Why it's wrong here

    Running a periodic script via Systems Manager requires custom scripting and scheduling, which is not minimal change. It also introduces latency for log uploads, not near-real-time. QuickSight is a business intelligence service, not ideal for ad-hoc log analysis; Athena is more appropriate. This solution is complex, not cost-effective, and does not provide near-real-time analysis. It also lacks a managed pipeline for log delivery.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.