SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company is experiencing intermittent performance issues with an application running on an EC2 instance. The CloudWatch metrics show high CPU utilization but no correlation with the timing of the issue. The SysOps administrator needs to collect detailed performance data to identify the root cause. Which AWS service should the administrator use to capture network-level metrics and logs?
⚠ Common exam trap
Watch out — candidates often confuse VPC Flow Logs (network traffic metadata) with CloudTrail (API activity) or CloudWatch Logs (application logs), assuming any 'log' service captures network-level data, but only VPC Flow Logs provide IP traffic flow records at the network interface level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable VPC Flow Logs for the EC2 instance's subnet.
VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, packet count) at the network interface level, which is essential for diagnosing network-related performance issues. Since the problem is intermittent and uncorrelated with CPU, network-level metrics can reveal issues like packet loss, throttling, or latency that application logs or CPU metrics alone cannot. This directly addresses the need for detailed network-level data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a CloudWatch Logs agent on the instance to send application logs.
Why it's wrong here
While the CloudWatch Logs agent can collect application logs that might reveal errors or slow queries, it does not capture network-level telemetry such as IP addresses, ports, or packet counts. Intermittent performance issues often originate from network anomalies like dropped packets or congestion, which remain hidden in application output. Thus, although useful for debugging code, it cannot diagnose the network-layer cause being investigated.
- ✓
Enable VPC Flow Logs for the EC2 instance's subnet.
Why this is correct
Enabling VPC Flow Logs for the subnet captures detailed IP traffic metadata for every elastic network interface attached to your EC2 instances, including source/destination IPs, ports, protocol, packet and byte counts, and whether the action was ACCEPT or REJECT. This telemetry is published to CloudWatch Logs or an S3 bucket, letting you analyze traffic patterns to pinpoint intermittent glitches such as unexpected spikes, asymmetric routing, or security-group blockages. Because the question points to network-related performance issues, flow logs provide the exact diagnostic data needed.
- ✗
Use AWS CloudTrail to log all API calls made to the instance.
Why it's wrong here
CloudTrail records management-plane API actions performed by users, roles, or AWS services, such as RunInstances, TerminateInstances, or ModifyInstanceAttribute, but it has no visibility into the data-plane traffic flowing to or from an EC2 instance. It will not reveal source addresses, ports, packet loss, or throughput metrics, so it cannot help find the root cause of sporadic network performance problems. CloudTrail serves as an auditing and governance tool, not a network monitoring service.
- ✗
Enable AWS Config to track configuration changes to the instance.
Why it's wrong here
AWS Config evaluates and records configuration state changes of resources, such as instance type changes, new security group attachments, or AMI updates, and can show whether a change preceded an issue. However, it does not collect network flow data or real-time performance metrics, so it cannot detect transient traffic spikes or dropped connections. It is a compliance and change-management service rather than a network diagnostics tool.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.