Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company uses Amazon CloudWatch Logs to store application logs. The SysOps administrator needs to count the occurrences of the string 'ERROR' in the logs and trigger an Amazon SNS notification when more than 10 errors occur within a 5-minute window. Which steps should the administrator take?

⚠ Common exam trap

It's easy for candidates to think they can directly alarm on a log group (Option B) or assume a Lambda function is required for custom log parsing (Option C), but the exam expects knowledge of CloudWatch Logs metric filters as the native solution for counting patterns and triggering alarms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a metric filter on the log group and then create a CloudWatch alarm on the resulting metric

A metric filter on a CloudWatch Logs log group extracts a numeric metric (e.g., count of 'ERROR' occurrences) and publishes it to a CloudWatch custom metric. A CloudWatch alarm can then be configured on that metric to evaluate a threshold (e.g., >10) over a specified period (e.g., 5 minutes) and trigger an SNS notification when breached. This is the native, serverless, and cost-effective approach for counting log patterns and alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a metric filter on the log group and then create a CloudWatch alarm on the resulting metric

    Why this is correct

    A metric filter applied to a CloudWatch Logs log group continuously scans incoming log events for a specified pattern (e.g., a literal string or a JSON field value) and converts matching events into a CloudWatch custom metric. Once the metric is published, you can configure a CloudWatch alarm on that metric with thresholds, evaluation periods, and actions such as sending to an SNS topic. This built-in pattern-matching capability runs entirely within the CloudWatch service, with no additional compute or custom code, and is the standard design for alerting on log content.

  • ✗

    Create a CloudWatch alarm directly on the log group

    Why it's wrong here

    CloudWatch alarms are designed to operate on numeric metrics—such as a custom metric emitted by a metric filter—not on raw log groups as a monitoring dimension. The “Alarms” console and API require you to specify a metric name, namespace, and statistic; a log group alone contains no comparable numeric data stream for a threshold to evaluate. Attempting to attach an alarm directly to a log group has no supported action in the CloudWatch service, so this option is technically invalid and would not produce any alert.

  • ✗

    Create an AWS Lambda function to parse the logs and send a notification to Amazon SNS

    Why it's wrong here

    While an AWS Lambda function could be subscribed to a CloudWatch Logs log group to parse each log event and publish to an SNS topic, this approach introduces significant operational overhead: you must manage Lambda concurrency, retries, failure handling, IAM permissions, and memory/timeout settings, and you will incur invocation costs for every log event. CloudWatch Logs metric filters already perform pattern matching natively and push only aggregated, numeric values to CloudWatch, making the Lambda-based path unnecessarily complex, less reliable, and more expensive for a straightforward log-content alert.

  • ✗

    Create an Amazon EventBridge rule to filter log events and send to SNS

    Why it's wrong here

    An Amazon EventBridge rule cannot directly “filter log events” from CloudWatch Logs because EventBridge operates on events emitted to the default or custom event buses, not on real-time log streams. While CloudWatch Logs can integrate with EventBridge for specific log-based triggers (e.g., actions like AWS API calls via CloudTrail), arbitrary log pattern matching is outside that integration model. The appropriate native mechanism is a CloudWatch Logs metric filter feeding a CloudWatch alarm, not an EventBridge rule, which would require an intermediary transport to make log data available as an event.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.