SAP-C02 Continuous Improvement for Existing Solutions Practice Question
A company runs a production web application on EC2 instances in an Auto Scaling group behind an ALB. The application logs are stored on an EBS volume attached to each instance. The operations team notices that the logs are not being sent to a central location. What is the MOST efficient way to centralize log collection with minimal code changes?
⚠ Common exam trap
SAP-C02 often tests 'minimal code changes' vs 'centralized logging': candidates pick SDK modification or Kinesis pipelines, overlooking that the CloudWatch Logs agent is the lowest-effort, agent-based solution for EC2 log centralization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the CloudWatch Logs agent on each EC2 instance and configure it to stream the log files to CloudWatch Logs.
The CloudWatch Logs agent can be installed on each EC2 instance and configured to stream log files from the EBS volume to CloudWatch Logs without modifying application code. This centralizes logs efficiently and is the standard AWS approach for EC2 log collection. It requires only agent installation and configuration, meeting the minimal-code-change requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the application to use the AWS SDK to send logs to CloudWatch Logs via PutLogEvents API.
Why it's wrong here
PutLogEvents requires rewriting application code to call the SDK, contradicting the minimal-code-change requirement. The SDK approach is correct when the application itself must emit structured events directly, for example custom metrics or business-level log records.
- ✗
Use Amazon Kinesis Agent to send logs to Kinesis Data Firehose and then to S3.
Why it's wrong here
Kinesis Agent streams to Firehose and S3, which is archival storage rather than a queryable central log service, and adds pipeline components. It fits high-volume streaming analytics into S3, not consolidating instance logs for operational searching with minimal change.
- ✗
Set up an S3 bucket with a lifecycle policy to transition logs to Glacier.
Why it's wrong here
An S3 bucket with lifecycle transition stores nothing unless logs are first shipped there, and Glacier retrieval is unsuitable for operational log access. This pattern is correct for long-term retention of already-centralised archives, not for collecting logs from EBS volumes.
- ✓
Install the CloudWatch Logs agent on each EC2 instance and configure it to stream the log files to CloudWatch Logs.
Why this is correct
The CloudWatch Logs agent runs on each instance and tails the existing log files on the EBS volume, streaming them to CloudWatch Logs. This centralises collection without application code changes, unlike custom logging or instance-store approaches.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.