Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company has a VPC with public and private subnets. An EC2 instance in a private subnet needs to send logs to CloudWatch Logs. Which steps are necessary to allow this without traversing the internet? (Select TWO.)

⚠ Common exam trap

Watch out — candidates often assume a NAT gateway is required for private subnet outbound traffic, but for AWS services like CloudWatch Logs, a VPC endpoint provides a more secure and direct path without internet traversal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM role to the instance with permissions to call PutLogEvents.

The EC2 instance must have an IAM role attached that includes permissions for `logs:PutLogEvents` to authenticate and authorize log delivery to CloudWatch Logs. Without this role, the instance cannot sign API requests, even if network connectivity exists. Option C is correct because a VPC endpoint for CloudWatch Logs (com.amazonaws.region.logs) provides private connectivity via AWS PrivateLink, allowing the instance to send logs without traversing the internet or a NAT gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the instance in a public subnet with a public IP.

    Why it's wrong here

    Placing the instance in a public subnet with a public IP does not grant the IAM context required by CloudWatch Logs; the service still needs credentials that allow logs:PutLogEvents. A public IP simply activates internet routing through an internet gateway, which exposes the instance to inbound traffic and does not make CloudWatch Logs API calls succeed. The network location is irrelevant until the identity policy is in place.

  • ✓

    Attach an IAM role to the instance with permissions to call PutLogEvents.

    Why this is correct

    Attaching an IAM role with permissions to call PutLogEvents is the mandatory identity-layer step: the CloudWatch agent or SDK retrieves temporary credentials from the instance metadata service, and those credentials must include actions such as logs:CreateLogStream and logs:PutLogEvents. Without this role, every API request to CloudWatch Logs is rejected with an access-denied error, even if the network path is perfectly reachable. This role is required whether you reach CloudWatch Logs via a VPC endpoint, a NAT gateway, or the internet.

  • ✓

    Create a VPC endpoint for CloudWatch Logs (com.amazonaws.region.logs).

    Why this is correct

    Creating a VPC endpoint for CloudWatch Logs (com.amazonaws.region.logs) is a private networking requirement when the instance is in a private subnet without an internet route. The endpoint deploys elastic network interfaces in your VPC and uses AWS PrivateLink to carry traffic to CloudWatch Logs, so the instance never leaves the AWS network for these calls. This solves connectivity, but it does not grant any metadata or signing permissions, so the IAM role must still allow PutLogEvents.

  • ✗

    Ensure the instance is in the default VPC.

    Why it's wrong here

    Being in the default VPC provides no privileged access to CloudWatch Logs because the default VPC is just a standard VPC with public subnets, an internet gateway, and no preconfigured VPC endpoints for logging services. It still requires an IAM role for API access, and its public routing does not offer private or separated connectivity to CloudWatch Logs. A default VPC is not a substitute for either a VPC endpoint or a NAT gateway in the network path.

  • ✗

    Attach a NAT gateway to the private subnet's route table.

    Why it's wrong here

    Attaching a NAT gateway to the private subnet's route table is a partial and insecure solution because it provides outbound internet access, not private connectivity to CloudWatch Logs. The instance would reach CloudWatch Logs via its public endpoint across the internet, bypassing the cornerstones of a private architecture: AWS PrivateLink and a network path that never enters the public internet. Even worse, a NAT gateway sits in a public subnet, requires an IAM role anyway, and costs per gigabyte of processed data, making a VPC endpoint the better and more secure option for log delivery.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.