SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company is using Amazon CloudWatch Logs to collect logs from multiple AWS services. The SysOps administrator needs to query logs across multiple log groups in real-time. Which THREE of the following are capabilities of CloudWatch Logs Insights?
⚠ Common exam trap
Candidates often confuse CloudWatch Logs Insights' real-time querying with scheduled or export capabilities, which are actually handled by separate AWS services like EventBridge or S3 Export tasks, not by Insights itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run queries in real-time against incoming log data.
CloudWatch Logs Insights supports real-time queries against incoming log data, allowing you to analyze logs as they are ingested. This is enabled by its ability to query live streams without requiring data to be indexed first, making it suitable for real-time troubleshooting and monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Export query results directly to an S3 bucket.
Why it's wrong here
CloudWatch Logs Insights does not provide a native one-click export of query results to S3. The service's export-to-S3 functionality (via the console or aws logs export-task API) is designed to export entire log groups in a compressed GZIP format, not the filtered/aggregated output of an Insights query. To persist query results to S3, you must orchestrate it yourself by calling StartQuery and GetQueryResults via the SDK and then writing the returned data to an S3 bucket using your own code or a Lambda function.
- ✗
Schedule queries to run at a specific time.
Why it's wrong here
CloudWatch Logs Insights is an interactive, on-demand query engine and does not support native scheduling or cron-based recurring execution. There is no console button or API to schedule a Insights query; any recurring analysis must be built externally, for example, by using Amazon EventBridge rules to trigger an AWS Lambda function that programmatically runs the query via the StartQuery API and processes the results. This distinction is why 'Schedule queries to run at a specific time' is not a valid feature of the service itself.
- ✓
Run queries in real-time against incoming log data.
Why this is correct
CloudWatch Logs Insights operates on log data that has been ingested into CloudWatch Logs, and because ingestion is a near real-time process—typically within seconds—queries reflect the most recent events. The console even offers a 'Live' button that continuously polls and re-runs the query against incoming data, giving a real-time tail-like experience. However, this is not streaming analytics; the query engine still scans the stored log data rather than processing events as a continuous stream.
- ✓
Visualize query results with bar charts and line graphs.
Why this is correct
CloudWatch Logs Insights includes built-in visualization capabilities that render query results directly in the console as bar charts, line graphs, pie charts, and other chart types. Visualizations are generated when the query uses aggregation functions such as count(), avg(), or sum() combined with GROUP BY or bin(time) to create time series. These visualizations are useful for quick visual analysis but are ephemeral—they do not create persistent dashboard widgets; for persistent dashboards, you must add the query as a widget to a CloudWatch Dashboard.
- ✓
Query multiple log groups in a single query.
Why this is correct
A single CloudWatch Logs Insights query can combine and analyze log events from multiple log groups, up to a maximum of 20 log groups per query, provided they belong to the same AWS account and Region. In the console, you simply select multiple log groups in the dropdown; when using the API, you pass an array in the logGroupNames parameter. This capability is essential for correlating logs across services (e.g., API Gateway and Lambda) in one query, avoiding the need to manually merge log data before analysis.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.