SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company runs a web application on Amazon EC2 instances. The application logs are sent to Amazon CloudWatch Logs. The SysOps administrator needs to monitor the logs for an increasing number of HTTP 500 errors. The administrator wants to create a metric filter that will count the number of lines containing 'HTTP 500' in the log group. Which syntax should the administrator use for the metric filter pattern?
⚠ Common exam trap
Watch out — candidates often confuse the space-delimited token pattern syntax (square brackets) with literal string matching, leading them to choose options like A or D that only match specific token positions rather than any occurrence of 'HTTP 500' in the log line.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
"HTTP 500"
CloudWatch Logs metric filter patterns use literal string matching by enclosing the exact text in double quotes. The pattern "HTTP 500" will match any log line that contains the exact substring 'HTTP 500', which is the simplest and most reliable way to count occurrences of HTTP 500 errors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
[error, HTTP, 500]
Why it's wrong here
The square brackets in a CloudWatch Logs metric filter pattern define a space-delimited token sequence, not a literal substring search. This pattern would attempt to match three separate space-separated fields named 'error', 'HTTP', and '500' (with commas being interpreted as part of the token names), so it will not match a log line containing the contiguous string 'HTTP 500'.
- ✓
"HTTP 500"
Why this is correct
Wrapping 'HTTP 500' in double quotes makes the pattern a single literal phrase. In CloudWatch Logs metric filters, a quoted string with spaces matches the exact substring; so any log line containing the characters 'HTTP 500' in that order will trigger the filter. That is the only correct form among the options.
- ✗
"HTTP" && "500"
Why it's wrong here
The '&&' operator is not supported in CloudWatch Logs metric filter patterns. This pattern would be treated as invalid syntax, or the parser would attempt to match a literal ampersand sequence, rather than logically requiring both 'HTTP' and '500' to appear. To match multiple terms anywhere in the line, use a space-separated pattern like 'HTTP' '500'.
- ✗
[HTTP, 500, ...]
Why it's wrong here
This pattern uses square brackets, which are intended for token-based parsing of space-delimited fields, not for literal string matching. In addition, the comma and ellipsis are not valid tokens in a metric filter pattern, so the entire expression is syntactically invalid. It would not match the literal string 'HTTP 500' at all.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.