SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company uses Amazon CloudWatch Logs to collect logs from multiple EC2 instances. The SysOps administrator needs to create a metric filter that counts the number of ERROR-level log entries per hour and triggers an alarm when the count exceeds 100 in any 5-minute period. Which metric filter pattern should be used?
⚠ Common exam trap
A common mix-up: candidates think the metric value should match the alarm threshold (e.g., 100) or that wildcards or special syntax are needed, when in fact the metric value should be 1 and the threshold is set in the alarm definition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the pattern "ERROR" and set the metric value to 1.
A CloudWatch Logs metric filter counts each log event that matches the pattern. Setting the metric value to 1 ensures that each matching log entry increments the metric by 1, allowing the alarm to evaluate the sum over a 5-minute period against the threshold of 100. The pattern "ERROR" matches any log entry containing the string "ERROR" anywhere in the message.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the pattern "ERROR" and set the metric value to 100.
Why it's wrong here
In CloudWatch Logs metric filters, the metric value is a numeric multiplier applied for every matching log event, not a severity weight or threshold. Setting it to 100 causes each log event containing the string ERROR to add 100 to the metric, so a single occurrence inflates the count by a factor of 100, producing wildly inaccurate data for monitoring. For an exact occurrence count, the metric value must be 1 regardless of how severe the log message appears.
- ✓
Use the pattern "ERROR" and set the metric value to 1.
Why this is correct
This is correct because CloudWatch Logs metric filters increment the target metric by the specified metric value each time a log event matches the given pattern. The pattern 'ERROR' is a simple, case-sensitive term that CloudWatch matches against the entire log event, not just the beginning, so it will catch every log line that contains the substring ERROR. Setting the metric value to 1 ensures that each matching event adds exactly 1, giving you an accurate real-time count of ERROR-level log entries.
- ✗
Use the pattern "ERROR *" to match any log entry starting with ERROR.
Why it's wrong here
In CloudWatch Logs metric filter syntax, 'ERROR *' is interpreted as two separate space-separated terms: the literal string 'ERROR' and a wildcard term '*'. This means a log event must contain both the term 'ERROR' and at least one additional term to satisfy the wildcard, so an entry consisting solely of 'ERROR' would not match, and the pattern does not anchor to the start of the line. The simple pattern 'ERROR' is sufficient because metric filters scan the entire log event, and adding the wildcard only introduces unnecessary constraints and false negatives.
- ✗
Use the pattern "[ERROR, 5]" to match 5 consecutive ERROR entries.
Why it's wrong here
This pattern is not valid in CloudWatch Logs metric filters. Metric filter patterns consist of space-separated terms with optional '*' wildcards; they do not support bracket notation, commas, or numeric repetition qualifiers. As a result, '[ERROR, 5]' would be treated as a literal string, matching only log events that contain that exact sequence of characters, and it certainly cannot count '5 consecutive ERROR entries' — CloudWatch Logs metric filters evaluate each log event independently and have no concept of event ordering or consecutiveness.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.