Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company has an application that writes logs to CloudWatch Logs. The SysOps administrator needs to search for a specific error pattern across multiple log groups. Which solution is the most efficient?

⚠ Common exam trap

A common mix-up: candidates confuse metric filters (which only count occurrences) with the ability to search and retrieve actual log events, leading them to choose Option C instead of the correct query-based solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use CloudWatch Logs Insights to query the log groups.

CloudWatch Logs Insights is purpose-built for interactive ad-hoc querying of log data across multiple log groups, enabling efficient pattern matching and filtering without requiring pre-configured infrastructure. It uses a dedicated query language optimized for searching, aggregating, and analyzing log events, making it the most efficient solution for searching a specific error pattern across multiple log groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a CloudWatch dashboard to visualize log data.

    Why it's wrong here

    A CloudWatch dashboard is built around metric widgets and graphs; it cannot directly search or display raw log lines. While you can add a Logs Insights widget to a dashboard, the actual querying still occurs through Logs Insights, and the dashboard only presents a saved result. Therefore, creating a dashboard doesn't provide an interactive way to query log groups for ad-hoc troubleshooting.

  • ✓

    Use CloudWatch Logs Insights to query the log groups.

    Why this is correct

    CloudWatch Logs Insights provides a dedicated query engine with a SQL-like syntax for analyzing log data stored in log groups. It automatically parses fields such as @timestamp, @message, and @logStream, enabling you to filter, aggregate, and search across log events interactively. This is the most efficient and direct method for answering ad-hoc questions about log contents, requiring no additional services or configuration.

  • ✗

    Create a metric filter to count the error pattern.

    Why it's wrong here

    A metric filter extracts a numeric value or count from incoming log events and publishes it as a CloudWatch metric; it does not return the underlying log events or allow you to search log content. After creating the filter, you can see a metric line or set an alarm, but you cannot drill down to the specific log messages that matched. Thus, it is a monitoring tool, not a log querying tool.

  • ✗

    Create a subscription filter to stream logs to Amazon ES.

    Why it's wrong here

    Setting up a subscription filter that streams log events to Amazon ES (OpenSearch Service) requires provisioning a separate domain, configuring IAM roles, and managing the data pipeline. It is intended for real-time ingestion and long‑term analytics/visualization in OpenSearch, not for interactive ad‑hoc queries from the CloudWatch console. For simply searching existing log groups, this adds unnecessary complexity and latency compared to Logs Insights.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.