Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company runs a web application on Amazon EC2 instances. The SysOps administrator needs to monitor two metrics: high CPU utilization (greater than 90%) and high memory utilization (greater than 85%). An alarm should trigger when both conditions are true simultaneously for a period of 5 minutes. Which CloudWatch feature should the administrator use to create this alarm?

⚠ Common exam trap

Many exam-takers confuse Metric Math with composite alarms, thinking that arithmetic operations can simulate logical AND, but Metric Math cannot evaluate alarm states or combine them with logical operators—it only produces a new numeric metric series.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Composite alarm

A composite alarm in Amazon CloudWatch allows you to create an alarm that evaluates multiple conditions using logical operators (AND, OR, NOT). In this scenario, the administrator needs the alarm to trigger only when both CPU utilization > 90% AND memory utilization > 85% are true simultaneously for 5 minutes. Composite alarms evaluate the state of underlying metric alarms (e.g., two separate simple alarms for CPU and memory) and combine them with an AND condition, making it the correct feature for this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Metric math

    Why it's wrong here

    Metric math allows you to create a new time series by applying arithmetic or conditional expressions to one or more CloudWatch metrics; however, it produces a single metric that then requires its own alarm. To emulate an AND condition, you would need to write a custom expression that encodes each threshold and yields a 1 only when all are met, but this lacks the built-in state evaluation, missing-data handling, and straightforward management that composite alarms provide. Since the requirement is to combine multiple alarm conditions, metric math alone does not offer a complete alarm solution.

  • ✓

    Composite alarm

    Why this is correct

    A composite alarm evaluates a rule that combines the states of multiple underlying CloudWatch alarms using AND/OR logic, so it can trigger only when every specified alarm is in the desired state. For example, you can set it to alarm only when both the CPU utilization and memory usage alarms are in ALARM, which is exactly the kind of multi-condition trigger the scenario requires. With composite alarms, you can also incorporate up to 10 alarms or other composite alarms, and you can define a period within which the conditions must remain met. This provides a managed, declarative way to create condition-based escalation without writing custom metric math.

  • ✗

    Anomaly detection

    Why it's wrong here

    Anomaly detection builds a statistical model of a single metric's expected range based on historical behavior, using ±n standard deviations or a custom band, and it raises an alarm when the metric falls outside that band. It does not compare two or more metrics against each other, nor does it evaluate fixed thresholds based on known business requirements. If your goal is to require that several independent thresholds are all exceeded simultaneously, anomaly detection only identifies outliers over time and cannot express that multi-metric condition.

  • ✗

    Logs Insights

    Why it's wrong here

    CloudWatch Logs Insights is an interactive query engine used to search, filter, and pattern-match log events, with the ability to compute fields and aggregates on log data. It does not produce a time series metric that CloudWatch alarms can continuously evaluate, and there is no native mechanism to create an alarm directly from a Logs Insights query. To use log data in an alarm you would first need to create a metric filter that extracts a numeric value into a custom metric, which is then managed by a standard alarm—making it an indirect, extra-step solution rather than a direct way to combine existing alarm conditions.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.