Setting Up CloudWatch Alarms for Lambda Function Errors
Network Topology
Refer to the exhibit. A security engineer wants to monitor a Lambda function for errors and create a CloudWatch alarm when errors exceed a threshold. The engineer notices the log group exists but has no metric filters. What should the engineer do to set up the alarm?
Quick Answer
The reason a metric filter has to come first is that CloudWatch alarms can only be built on top of a metric, and a Lambda function's log output is just unstructured text sitting in a CloudWatch Logs group until something extracts a countable value from it. A metric filter is exactly that extraction step: it scans incoming log events for a pattern, in this case occurrences of the string ERROR, and converts matches into a numeric CloudWatch metric that increments every time the pattern appears. Once that metric exists, a standard CloudWatch alarm can be attached to it with a threshold, so the moment error occurrences exceed whatever count the security engineer defines, the alarm state changes and can trigger a notification. This two-step relationship, extract a metric from logs, then alarm on the metric, is the standard way to turn free-text log data into an actionable, threshold-based alert without modifying the underlying application code or introducing a separate monitoring tool. Whenever a scenario describes wanting to alert based on specific text or error patterns appearing in a log group, and there is no metric filter already in place, expect the correct first step to be creating that metric filter before an alarm can be attached to anything, since an alarm always needs a metric to watch and a metric filter is how you generate one from raw log text.
⚠ Common exam trap
Candidates often confuse CloudWatch Logs Insights (a query tool) with metric filters (a real-time monitoring mechanism), or assume that Contributor Insights can generate alarms, when in fact only metric filters can directly feed into CloudWatch alarms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a metric filter on the log group to count occurrences of 'ERROR' in log streams, then create an alarm based on that metric.
CloudWatch Logs metric filters allow you to extract and count specific patterns (like 'ERROR') from log streams, and then create a CloudWatch alarm based on that metric. This directly addresses the requirement to monitor the Lambda function for errors without needing to modify the function code or rely on external tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable CloudWatch Contributor Insights for the Lambda function to automatically detect errors.
Why it's wrong here
Contributor Insights is for analyzing high-cardinality data, not for simple error counting.
- ✓
Create a metric filter on the log group to count occurrences of 'ERROR' in log streams, then create an alarm based on that metric.
Why this is correct
This is the standard approach: define a metric filter to extract error counts from logs, then create an alarm.
- ✗
Configure the Lambda function to publish custom metrics for errors instead of relying on logs.
Why it's wrong here
While possible, the question asks about using the existing log group; custom metrics would require code changes.
- ✗
Use CloudWatch Logs Insights to query logs for errors and create an alarm directly from the query results.
Why it's wrong here
CloudWatch Logs Insights does not directly support alarm creation; you need a metric filter.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 376-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security engineer is designing a monitoring solution for an AWS Lambda function that processes sensitive data. The function occasionally fails due to timeouts. The engineer needs to be alerted immediately when the function fails and also wants to analyze the error logs. Which combination of services should the engineer use?
medium- A.Amazon CloudWatch Logs and Amazon Kinesis Data Firehose
- ✓ B.Amazon CloudWatch Logs and CloudWatch Alarms with Amazon SNS
- C.AWS CloudTrail and Amazon SNS
- D.AWS Config and Amazon SNS
Why B: Amazon CloudWatch Logs captures the Lambda function's execution logs, including timeout errors, and CloudWatch Alarms can monitor specific metrics like `Errors` or `Throttles` for the function. When the alarm state is triggered (e.g., `ALARM`), it publishes a notification to an Amazon SNS topic, which can send immediate alerts via email, SMS, or other endpoints. This combination provides both real-time alerting and log analysis for troubleshooting.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.