SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company has a production environment with multiple EC2 instances that send logs to CloudWatch Logs. The operations team wants to search across all log groups for a specific error pattern. What is the most efficient way to achieve this?
⚠ Common exam trap
The trap here is that candidates may overcomplicate the solution by choosing a more complex architecture (like streaming to Elasticsearch or using Athena) when CloudWatch Logs Insights provides a native, serverless, and efficient way to query across multiple log groups directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use CloudWatch Logs Insights to query across all log groups.
CloudWatch Logs Insights allows you to run SQL-like queries across multiple log groups in a single query, making it the most efficient way to search for a specific error pattern across all log groups without needing to set up additional infrastructure or manually query each group individually.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use CloudWatch Logs Insights to query across all log groups.
Why this is correct
CloudWatch Logs Insights is purpose-built for ad-hoc querying across multiple log groups. A single query can reference several log groups (e.g., by specifying logGroupNames with `*` wildcards or enumerating them), enabling you to search, filter, and aggregate fields like `@timestamp` and `@message` without moving data. This is the most direct and efficient way for a SysOps administrator to correlate logs from multiple EC2 instances in a production environment, because it requires no additional infrastructure or data pipelines and returns results within seconds. The query language supports commands like `fields`, `stats`, and `filter` to isolate specific errors, making it ideal for fast troubleshooting.
- ✗
Set up a subscription filter to stream logs to an Amazon ES domain.
Why it's wrong here
While streaming logs to an Amazon ES domain via a subscription filter allows centralized, ongoing analysis with Kibana, it adds significant operational overhead: you must provision and manage an ES cluster, handle index lifecycle, and ensure the subscription filter is correctly attached to every log group. For a one-off or ad-hoc investigation, this approach is over-engineered and slower—you would first need to configure the stream, wait for the data to index, and then author Kibana queries. It is a long-term analytics solution, not a quick answer to an immediate question, so it is not the simplest choice for the scenario described.
- ✗
Use CloudWatch Logs filter patterns on each log group.
Why it's wrong here
CloudWatch Logs filter patterns are applied individually to a single log group, and they only act as a mechanism to route matching log events to metrics, subscriptions, or alarms—they are not a query interface. To find a pattern across all EC2 instances, you would have to manually create and manage a separate filter pattern for every log group, then evaluate the results one by one, which is tedious and error-prone. This approach cannot aggregate or correlate data across log groups with a single operation, so it fails to meet the requirement of searching across the entire production environment efficiently.
- ✗
Download all logs to an S3 bucket and use Amazon Athena to query.
Why it's wrong here
Exporting logs to S3 and querying with Athena is viable, but it is a heavyweight process: you must first enable S3 export for each log group (via the console/CLI or a scheduled API call), wait for the export job to complete, partition the data if needed, and then write SQL queries. This introduces significant latency and manual steps, making it impractical for an urgent, ad-hoc investigation where you need answers immediately. Additionally, Athena charges per query based on the amount of data scanned, so scanning repeated exports of all logs can be costly compared to CloudWatch Logs Insights, which only charges for the data actually ingested and queried within CloudWatch.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.