SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company has a CloudWatch dashboard that displays metrics for several EC2 instances. The SysOps administrator wants to share the dashboard with external stakeholders who do not have AWS accounts. Which actions should the administrator take? (Select TWO.)
⚠ Common exam trap
A common mix-up: candidates confuse the CloudWatch dashboard sharing feature with IAM-based access, assuming external users must have AWS credentials, when in fact the public URL mechanism is designed specifically for sharing with non-AWS users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the CloudWatch dashboard sharing feature to make the dashboard public.
Option A is correct because CloudWatch dashboards support a built-in sharing feature that lets you share a dashboard publicly with anyone, including people who do not have AWS accounts, by configuring the dashboard's share settings. Option D is correct because after enabling sharing, CloudWatch generates a shareable URL that can be sent to external stakeholders so they can view the dashboard without signing in to AWS. Options B, C, and E are not appropriate: building a custom EC2 web application is unnecessary and overly complex, creating IAM users requires stakeholders to have AWS accounts and credentials, and exporting to QuickSight is not a supported CloudWatch dashboard sharing mechanism for anonymous external viewers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the CloudWatch dashboard sharing feature to make the dashboard public.
Why this is correct
The CloudWatch dashboard sharing feature provides a built-in mechanism to expose a dashboard to anyone via a public link without requiring AWS credentials or sign-in. This is the most direct solution for external stakeholders because they only need the URL to view the live metrics, and you can revoke access by disabling sharing at any time. It avoids the need to create AWS identities or build custom applications.
- ✗
Create a web application that reads CloudWatch metrics and host it on EC2.
Why it's wrong here
Building a custom web application on EC2 to retrieve and display CloudWatch metrics is an unnecessarily complex and costly solution. You would need to manage EC2 instances, handle API authentication with IAM roles or access keys, implement a frontend, and secure the data, all of which introduces significant operational overhead and potential security vulnerabilities. CloudWatch already provides native sharing features that achieve the same goal with far less effort, so this option is not the best practice.
- ✗
Create IAM users for each stakeholder and assign appropriate permissions.
Why it's wrong here
Creating IAM users for each stakeholder is invalid because IAM users are intended for individuals who authenticate within your AWS account, and stakeholders are external parties who likely do not have or need AWS accounts. Even if you created IAM users, you would need to distribute passwords or access keys, manage credentials, and grant dashboard permissions via policies, which is impractical for one-time or read-only sharing. The dashboard sharing feature is designed precisely to avoid this identity management burden.
- ✓
Generate a shareable URL for the dashboard and send it to the stakeholders.
Why this is correct
Generating a shareable URL and sending it to stakeholders is the practical application of the CloudWatch dashboard sharing feature. When you enable dashboard sharing, CloudWatch produces a unique URL that can be accessed by anyone without AWS credentials, and you can copy and email this link to the recipients. This option is correct because it leverages the native sharing capability, though you should be mindful that the link is public and should not expose sensitive information.
- ✗
Export the dashboard to Amazon QuickSight and share it via email.
Why it's wrong here
Amazon QuickSight is a business intelligence service for analyzing data from sources like S3, RDS, and Redshift, not a dashboard sharing mechanism for CloudWatch. CloudWatch dashboards consist of time-series metric widgets that cannot be directly exported into QuickSight, and QuickSight requires users to be provisioned with Amazon QuickSight access, which is different from sharing a simple read-only dashboard link. Therefore, this approach is neither supported nor simpler than the native CloudWatch sharing feature.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.