Courseiva
Security Logging and MonitoringhardMultiple ChoiceObjective-mapped

Setting Up CloudWatch Alarms for Lambda Function Errors

Network Topology
aws logs describe-log-groupslog-group-name-prefix /aws/lambda/my-functionaws logs describe-metric-filterslog-group-name /aws/lambda/my-function"logGroups": ["logGroupName": "/aws/lambda/my-function","creationTime": 1672531200000,"metricFilterCount": 0,"arn": "arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/my-function:*","storedBytes": 0,"retentionInDays": 7"metricFilters": []

Refer to the exhibit. A security engineer wants to monitor a Lambda function for errors and create a CloudWatch alarm when errors exceed a threshold. The engineer notices the log group exists but has no metric filters. What should the engineer do to set up the alarm?

Quick Answer

The reason a metric filter has to come first is that CloudWatch alarms can only be built on top of a metric, and a Lambda function's log output is just unstructured text sitting in a CloudWatch Logs group until something extracts a countable value from it. A metric filter is exactly that extraction step: it scans incoming log events for a pattern, in this case occurrences of the string ERROR, and converts matches into a numeric CloudWatch metric that increments every time the pattern appears. Once that metric exists, a standard CloudWatch alarm can be attached to it with a threshold, so the moment error occurrences exceed whatever count the security engineer defines, the alarm state changes and can trigger a notification. This two-step relationship, extract a metric from logs, then alarm on the metric, is the standard way to turn free-text log data into an actionable, threshold-based alert without modifying the underlying application code or introducing a separate monitoring tool. Whenever a scenario describes wanting to alert based on specific text or error patterns appearing in a log group, and there is no metric filter already in place, expect the correct first step to be creating that metric filter before an alarm can be attached to anything, since an alarm always needs a metric to watch and a metric filter is how you generate one from raw log text.

⚠ Common exam trap

Candidates often confuse CloudWatch Logs Insights (a query tool) with metric filters (a real-time monitoring mechanism), or assume that Contributor Insights can generate alarms, when in fact only metric filters can directly feed into CloudWatch alarms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a metric filter on the log group to count occurrences of 'ERROR' in log streams, then create an alarm based on that metric.

CloudWatch Logs metric filters allow you to extract and count specific patterns (like 'ERROR') from log streams, and then create a CloudWatch alarm based on that metric. This directly addresses the requirement to monitor the Lambda function for errors without needing to modify the function code or rely on external tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable CloudWatch Contributor Insights for the Lambda function to automatically detect errors.

    Why it's wrong here

    Contributor Insights is for analyzing high-cardinality data, not for simple error counting.

  • Create a metric filter on the log group to count occurrences of 'ERROR' in log streams, then create an alarm based on that metric.

    Why this is correct

    This is the standard approach: define a metric filter to extract error counts from logs, then create an alarm.

  • Configure the Lambda function to publish custom metrics for errors instead of relying on logs.

    Why it's wrong here

    While possible, the question asks about using the existing log group; custom metrics would require code changes.

  • Use CloudWatch Logs Insights to query logs for errors and create an alarm directly from the query results.

    Why it's wrong here

    CloudWatch Logs Insights does not directly support alarm creation; you need a metric filter.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SCS-C02 question is part of Courseiva's 376-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security engineer is designing a monitoring solution for an AWS Lambda function that processes sensitive data. The function occasionally fails due to timeouts. The engineer needs to be alerted immediately when the function fails and also wants to analyze the error logs. Which combination of services should the engineer use?

medium
  • A.Amazon CloudWatch Logs and Amazon Kinesis Data Firehose
  • B.Amazon CloudWatch Logs and CloudWatch Alarms with Amazon SNS
  • C.AWS CloudTrail and Amazon SNS
  • D.AWS Config and Amazon SNS

Why B: Amazon CloudWatch Logs captures the Lambda function's execution logs, including timeout errors, and CloudWatch Alarms can monitor specific metrics like `Errors` or `Throttles` for the function. When the alarm state is triggered (e.g., `ALARM`), it publishes a notification to an Amazon SNS topic, which can send immediate alerts via email, SMS, or other endpoints. This combination provides both real-time alerting and log analysis for troubleshooting.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.