Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company's application running on EC2 instances is experiencing intermittent errors. The SysOps team needs to collect and analyze application logs from all instances centrally. The logs must be stored durably and searchable with minimal latency. Which solution meets these requirements?

⚠ Common exam trap

A common mix-up: candidates confuse CloudTrail (API logging) with application logging, or assume that S3 periodic uploads are sufficient for 'minimal latency' searchability, when in fact CloudWatch Logs is the native AWS service designed for real-time log ingestion and querying from EC2 instances.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install the CloudWatch Logs agent on each EC2 instance and stream logs to Amazon CloudWatch Logs.

The CloudWatch Logs agent (or unified CloudWatch agent) installed on each EC2 instance can stream application logs in near real-time to Amazon CloudWatch Logs, which provides durable storage, automatic encryption at rest, and a searchable interface via the console, CLI, or API with minimal latency. This centralized logging solution meets the requirements for collecting logs from all instances, storing them durably, and enabling immediate querying without additional infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS CloudTrail and store logs in an S3 bucket.

    Why it's wrong here

    AWS CloudTrail is an API-gateway audit service that records management events such as RunInstances, TerminateInstances, and console sign-ins, storing them in S3 for governance and compliance. It does not capture application-level output, stderr/stdout, or web server access logs generated by the operating system or application inside the EC2 instance. Therefore, CloudTrail cannot be used to search for application errors, debug runtime behavior, or monitor live application performance — it only traces calls to the AWS control plane.

  • ✗

    Use Amazon Kinesis Data Firehose to send logs directly from each instance to Amazon Redshift.

    Why it's wrong here

    Amazon Kinesis Data Firehose is a streaming ingestion service that can deliver data to Amazon Redshift, but Redshift is a petabyte-scale columnar data warehouse optimized for complex analytical queries over structured data, not for low-latency interactive log search. Loading into Redshift requires a COPY command via an intermediate S3 bucket, which introduces significant delivery latency and operational overhead (e.g., managing schemas, compression, and error handling). It also lacks native full-text search, live tailing, or metric-filtering capabilities that are essential for real-time troubleshooting, making it inappropriate for this use case.

  • ✓

    Install the CloudWatch Logs agent on each EC2 instance and stream logs to Amazon CloudWatch Logs.

    Why this is correct

    Installing the CloudWatch Logs agent on each EC2 instance enables near-real-time streaming of application and system log files to Amazon CloudWatch Logs, providing a centralized, scalable, and searchable log store. With CloudWatch Logs you can create metric filters to trigger CloudWatch alarms, use Logs Insights to run queries across log groups, and perform live tailing to watch logs as they arrive. The agent also handles log rotation, multi-line log records, and timestamp parsing automatically, which simplifies log management and removes the need for manual log harvesting or extra infrastructure.

  • ✗

    Store logs locally on each instance and periodically copy them to Amazon S3.

    Why it's wrong here

    Storing logs locally on each EC2 instance and periodically copying them to Amazon S3 offers durable and cost-effective archival, but it does not give you real-time visibility into application behavior because you must wait for the copy interval to elapse. S3 has no native search functionality for log contents, so to analyze the data you would need to run additional services such as Amazon Athena or an Elasticsearch cluster, adding complexity and latency to any investigation. Meanwhile, in an active incident you might be unable to access an instance's local logs if the instance is down or unreachable, making this approach both slow and operationally fragile compared to centralized streaming to CloudWatch Logs.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.