SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company uses Amazon CloudWatch Logs to store application logs. The security team needs to be alerted when any log group contains a specific error pattern. The solution must minimize latency and operational overhead. What should a SysOps administrator do?
⚠ Common exam trap
Many exam-takers choose Option B (metric filter and alarm) because it seems simpler, but they overlook that metric filters only count occurrences over time and cannot trigger immediate, per-event alerts, which is required for minimizing latency in security alerting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Lambda function subscribed to the CloudWatch Logs log group, which checks for the error pattern and publishes to an SNS topic.
Subscribing a Lambda function directly to a CloudWatch Logs log group allows real-time, low-latency processing of log events as they arrive. The Lambda function can parse each log event for the specific error pattern and publish to an SNS topic to alert the security team, minimizing operational overhead by avoiding additional streaming or polling services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stream the logs to Amazon Kinesis Data Firehose, which then triggers a Lambda function to check for errors.
Why it's wrong here
Amazon Kinesis Data Firehose is a managed streaming delivery service intended to load data into Amazon S3, Redshift, OpenSearch, or Splunk, not to trigger functions per event. While Firehose can invoke a Lambda function as a data transformer, that occurs within the delivery pipeline and adds provisioning, buffering, and cost overhead that is unnecessary for real-time log alerting. A direct CloudWatch Logs subscription to Lambda processes events immediately and is the simpler, more accurate pattern.
- ✗
Create a CloudWatch metric filter on the log group and set an alarm that triggers an SNS notification.
Why it's wrong here
CloudWatch metric filters use a fixed pattern syntax that can match a literal string or a JSON field, but they only increment a metric count—they cannot run application logic to evaluate complex conditional error scenarios or parse multi-line stack traces. Alarms then evaluate the metric over a period (e.g., one minute) and require a threshold to be crossed, which introduces aggregation delay and can miss a single critical error far more slowly. Lambda, in contrast, inspects each log event as it arrives, making it the better choice for bespoke pattern matching and immediate SNS notification.
- ✓
Create a Lambda function subscribed to the CloudWatch Logs log group, which checks for the error pattern and publishes to an SNS topic.
Why this is correct
When you configure a subscription filter on a CloudWatch Logs group, CloudWatch Logs asynchronously invokes a Lambda function as log events are ingested, delivering a gzip-compressed batch of data that you can decode and search for error signatures. The Lambda function can be written in Python, Node.js, or another supported runtime, applying arbitrary regexes, aggregating events, and then directly publishing to an SNS topic for immediate fan-out to email, SMS, or Chatbot. This pattern provides real-time, event-driven alerting with minimal latency and no extra infrastructure, which is why it is the recommended approach for this requirement.
- ✗
Use CloudWatch Logs Insights to run a query every minute and send results via SNS.
Why it's wrong here
CloudWatch Logs Insights is an interactive query engine meant for tactical, on-demand exploration of logs, not a recurring scheduler—there is no built-in 'run every minute' trigger, and automating it would require an extra Lambda/EventBridge orchestrator to call the StartQuery API and then poll for results. Even then, the query would be scanning data that may be partially unindexed until the logs are ready, and Insights queries return up to 10,000 rows only, so it is unsuitable for real-time alerting. Lambda subscriptions, by contrast, operate on log events in flight, giving you immediate detection without polling.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.