Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company uses Amazon CloudWatch Logs to store application logs. The security team needs to be alerted when any log group contains a specific error pattern. The solution must minimize latency and operational overhead. What should a SysOps administrator do?

⚠ Common exam trap

Many exam-takers choose Option B (metric filter and alarm) because it seems simpler, but they overlook that metric filters only count occurrences over time and cannot trigger immediate, per-event alerts, which is required for minimizing latency in security alerting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Lambda function subscribed to the CloudWatch Logs log group, which checks for the error pattern and publishes to an SNS topic.

Subscribing a Lambda function directly to a CloudWatch Logs log group allows real-time, low-latency processing of log events as they arrive. The Lambda function can parse each log event for the specific error pattern and publish to an SNS topic to alert the security team, minimizing operational overhead by avoiding additional streaming or polling services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stream the logs to Amazon Kinesis Data Firehose, which then triggers a Lambda function to check for errors.

    Why it's wrong here

    Amazon Kinesis Data Firehose is a managed streaming delivery service intended to load data into Amazon S3, Redshift, OpenSearch, or Splunk, not to trigger functions per event. While Firehose can invoke a Lambda function as a data transformer, that occurs within the delivery pipeline and adds provisioning, buffering, and cost overhead that is unnecessary for real-time log alerting. A direct CloudWatch Logs subscription to Lambda processes events immediately and is the simpler, more accurate pattern.

  • ✗

    Create a CloudWatch metric filter on the log group and set an alarm that triggers an SNS notification.

    Why it's wrong here

    CloudWatch metric filters use a fixed pattern syntax that can match a literal string or a JSON field, but they only increment a metric count—they cannot run application logic to evaluate complex conditional error scenarios or parse multi-line stack traces. Alarms then evaluate the metric over a period (e.g., one minute) and require a threshold to be crossed, which introduces aggregation delay and can miss a single critical error far more slowly. Lambda, in contrast, inspects each log event as it arrives, making it the better choice for bespoke pattern matching and immediate SNS notification.

  • ✓

    Create a Lambda function subscribed to the CloudWatch Logs log group, which checks for the error pattern and publishes to an SNS topic.

    Why this is correct

    When you configure a subscription filter on a CloudWatch Logs group, CloudWatch Logs asynchronously invokes a Lambda function as log events are ingested, delivering a gzip-compressed batch of data that you can decode and search for error signatures. The Lambda function can be written in Python, Node.js, or another supported runtime, applying arbitrary regexes, aggregating events, and then directly publishing to an SNS topic for immediate fan-out to email, SMS, or Chatbot. This pattern provides real-time, event-driven alerting with minimal latency and no extra infrastructure, which is why it is the recommended approach for this requirement.

  • ✗

    Use CloudWatch Logs Insights to run a query every minute and send results via SNS.

    Why it's wrong here

    CloudWatch Logs Insights is an interactive query engine meant for tactical, on-demand exploration of logs, not a recurring scheduler—there is no built-in 'run every minute' trigger, and automating it would require an extra Lambda/EventBridge orchestrator to call the StartQuery API and then poll for results. Even then, the query would be scanning data that may be partially unindexed until the logs are ready, and Insights queries return up to 10,000 rows only, so it is unsuitable for real-time alerting. Lambda subscriptions, by contrast, operate on log events in flight, giving you immediate detection without polling.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.