SOA-C02 Cost and Performance Optimization Practice Question
A company uses Amazon CloudWatch Logs to store application logs from EC2 instances. The log volume is 100 GB per day, and logs are retained for 1 year. The SysOps administrator wants to reduce costs while maintaining compliance. Which solution is MOST effective?
⚠ Common exam trap
SOA-C02 often tests whether candidates know CloudWatch Logs storage is far more expensive than S3, and that 'reduce retention' is a trap when compliance explicitly requires long-term retention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Export logs to Amazon S3 and configure a lifecycle policy to transition them to Glacier Deep Archive after 30 days.
Exporting logs to Amazon S3 and transitioning them to Glacier Deep Archive after 30 days is the most cost-effective compliant solution because CloudWatch Logs storage is significantly more expensive per GB than S3, and Glacier Deep Archive costs roughly $0.00099/GB-month versus CloudWatch Logs at ~$0.03/GB-month. This preserves the 1-year retention requirement while cutting storage costs by over 90%.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduce the log retention period to 30 days.
Why it's wrong here
Setting CloudWatch Logs retention to 30 days cuts storage fees but directly violates the explicit one-year compliance requirement, so it is not acceptable. Moreover, retention only limits how long data is kept; it does nothing to reduce ingestion or per-GB storage charges during the 30-day window. Because the logs are legally required for a full year, this option fails the core constraint and is therefore incorrect.
- ✗
Disable server-side encryption for the log group to reduce overhead.
Why it's wrong here
Disabling server-side encryption for the log group would remove the protection of data at rest but would not meaningfully lower costs; AWS KMS fees for SSE are negligible compared to log ingestion and storage charges. In many environments, encryption is a security baseline, and disabling it could expose sensitive application data and break compliance controls. Since it does not address the cost issue and introduces security risk, it is not a valid optimization.
- ✗
Use CloudWatch Logs Insights to query logs instead of storing them.
Why it's wrong here
CloudWatch Logs Insights is only a query engine that runs against log data that is already ingested and stored in CloudWatch Logs; it cannot query or analyze data that is not stored. Choosing Insights does not reduce storage costs, and every query scans data and incurs additional per-GB query charges. Rather than avoiding storage, this approach still requires keeping all logs in CloudWatch, so it fails to lower costs.
- ✓
Export logs to Amazon S3 and configure a lifecycle policy to transition them to Glacier Deep Archive after 30 days.
Why this is correct
Exporting logs to Amazon S3 offloads them from CloudWatch Logs, where storage is more expensive, and then an S3 Lifecycle policy can automatically transition the objects to Glacier Deep Archive after 30 days. Glacier Deep Archive provides the lowest per-GB storage cost and still satisfies the one-year retention requirement, making this the most cost-effective compliant solution. For optimal savings, after a successful export you should also delete the original log group or set a very short CloudWatch retention so you do not pay for duplicate storage.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.