Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A DevOps engineer notices that an EC2 instance's CloudWatch agent is not sending custom metrics to CloudWatch. The agent is installed and the configuration file is valid. The instance has an IAM role attached. What is the most likely reason for the failure?

⚠ Common exam trap

Many candidates assume internet access is required for CloudWatch communication, but AWS services can be reached via VPC endpoints or private links without internet, and the question's focus on IAM permissions is the key differentiator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM role attached to the instance does not have the cloudwatch:PutMetricData permission.

The CloudWatch agent requires IAM permissions to publish custom metrics. Even if the agent is installed, running, and has a valid configuration, it will fail to send metrics if the attached IAM role lacks the `cloudwatch:PutMetricData` action. This is a common misconfiguration where the instance has an IAM role, but the role's policy does not explicitly grant the necessary CloudWatch write permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The instance does not have internet access to reach CloudWatch endpoints.

    Why it's wrong here

    Lack of direct internet access does not inherently prevent the CloudWatch agent from publishing metrics, because the agent can reach CloudWatch through VPC interface endpoints or via a NAT gateway. The question gives no indication of network connectivity problems, and the agent's inability to reach the endpoint would normally generate connection errors in its logs, not a silent absence of metrics.

  • ✗

    The CloudWatch agent is not running as root.

    Why it's wrong here

    The CloudWatch agent is designed to run as the dedicated system user 'cwagent', not root. Root privileges are not required for the agent to collect and publish metrics; if the agent were launched as root, it would still work (though it is discouraged due to least-privilege best practices), so the absence of root is not a cause of missing CloudWatch metrics.

  • ✗

    The CloudWatch agent configuration file has a syntax error.

    Why it's wrong here

    A syntax error in the CloudWatch agent configuration file would prevent the agent from starting or cause it to reject the configuration, and the agent writes detailed parse errors to its log files. The question explicitly states the configuration file is valid, so invalid syntax cannot explain why the instance's metrics are missing from CloudWatch.

  • ✓

    The IAM role attached to the instance does not have the cloudwatch:PutMetricData permission.

    Why this is correct

    The CloudWatch agent needs IAM permissions to publish metrics to CloudWatch; specifically, the instance's attached IAM role must include cloudwatch:PutMetricData. The managed policy CloudWatchAgentServerPolicy grants this permission, and without it the agent can collect data but every publish attempt is denied by CloudWatch, resulting in no metrics appearing in the console.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.