SCS-C02 Security Logging and Monitoring Practice Question
A company uses Amazon CloudWatch Logs to collect application logs from EC2 instances. The security team wants to create an alarm that triggers when a specific error pattern appears in the logs. They have set up a metric filter and an alarm. However, the alarm is not triggering even though the error pattern exists in the logs. What is the most likely cause?
⚠ Common exam trap
SCS-C02 often tests the misconception that CloudWatch metric filters retroactively evaluate existing log data — candidates must remember that metric filters only apply to log events ingested after the filter is created, so historical errors will not trigger alarms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The metric filter is only applied to log events that occur after the filter is created.
CloudWatch Logs metric filters are not retroactive: they only evaluate log events that are ingested after the filter is created. If the error pattern existed in the logs before the metric filter was created, those events will not generate metric data points, so the alarm will not trigger based on historical events. This is the most likely cause of the alarm not firing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The log group retention period is set to 1 day.
Why it's wrong here
Retention controls how long CloudWatch Logs stores log events in the log group, not whether existing metric filters process those events. A metric filter evaluates each log event as it is ingested and immediately emits the resulting metric data point to CloudWatch Metrics. Even with a 1-day retention period, the filter would still run while the event is being written, so short retention cannot explain the absence of metrics.
- ✗
The metric filter uses a custom namespace that is not allowed.
Why it's wrong here
CloudWatch explicitly supports custom namespaces for metrics generated by log filters; namespaces such as 'MyApp/Errors' are valid and commonly used. The AWS API enforces only character and length constraints on namespace names, not a fixed set of permitted namespaces. Because a custom namespace does not block the metric filter's pattern matching or emission, this cannot be the reason the expected metrics are missing.
- ✗
The metric filter was created before the log group.
Why it's wrong here
The CloudWatch Logs API requires a log group to exist before you can attach a metric filter to it, so the relative creation order is not a valid cause of missing metrics. More importantly, the relevant cutoff is the filter's own creation time: metric filters only evaluate log events that are delivered after the filter is created. Earlier events in the log group, regardless of when the group was created, are not backfilled.
- ✓
The metric filter is only applied to log events that occur after the filter is created.
Why this is correct
When you create a metric filter, CloudWatch Logs begins applying it only to new log events that arrive after creation; it does not scan or backfill the log group's existing history. Any events that were recorded before the filter existed will never be evaluated, even if they match the pattern. This is why a newly added filter often shows no metrics until subsequent log events are generated.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.