SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company uses AWS CloudFormation to deploy infrastructure. A SysOps admin wants to receive a notification when a stack update fails. Which approach is the most efficient?
⚠ Common exam trap
The trap here is that candidates often overcomplicate the solution by choosing CloudTrail or polling, missing the fact that EventBridge provides native, real-time event capture for CloudFormation stack status changes without additional overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an EventBridge rule that matches CloudFormation stack events
Amazon EventBridge can directly capture CloudFormation stack events (e.g., CREATE_FAILED, UPDATE_FAILED) in real time and trigger a notification via SNS or Lambda. This approach is serverless, requires no polling, and is the most efficient method for reacting to stack update failures as they occur.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Write a script that polls the CloudFormation API and sends notifications
Why it's wrong here
Polling the CloudFormation API using a custom script is an anti-pattern because it introduces latency and consumes compute resources on every poll cycle. AWS does not provide a built-in poll-and-notify mechanism, so you would need to manage the script's lifecycle, handle API throttling and pagination, and risk missing transient stack status changes. EventBridge is purpose-built to emit stack events as they occur, eliminating the need for polling altogether.
- ✗
Use AWS Config to monitor stack resources
Why it's wrong here
AWS Config is designed to record and evaluate the configuration state of individual AWS resources (e.g., EC2 instances, security groups) against rules, but it does not expose CloudFormation stack lifecycle events like ROLLBACK_IN_PROGRESS or UPDATE_COMPLETE. While Config could detect a resource that drifted from its template, it cannot notify you when the stack itself fails to update. Stack events are stored in the CloudFormation service, not in Config's configuration history.
- ✓
Create an EventBridge rule that matches CloudFormation stack events
Why this is correct
Amazon EventBridge natively receives CloudFormation events such as STACK_UPDATE_ROLLBACK_IN_PROGRESS, STACK_CREATE_COMPLETE, and others, because CloudFormation publishes stack events to the default event bus. You create a rule with an event pattern for source 'aws.cloudformation' and detail-type 'CloudFormation Stack Status Change', then target SNS, Lambda, or another service to send notifications. This is the recommended serverless, event-driven approach because it reacts immediately and reliably to stack transitions.
- ✗
Enable CloudTrail and create a metric filter for stack update failures
Why it's wrong here
CloudTrail records API calls made to CloudFormation, including the UpdateStack request, but stack update failures are not API calls; they are asynchronous events generated by the CloudFormation service. A metric filter on CloudTrail logs could detect the UpdateStack API call itself or an error code returned in the API response, but it cannot capture the subsequent ROLLBACK_IN_PROGRESS stack event that occurs minutes later. Additionally, CloudTrail logs are not designed to be filtered for internal service events, making EventBridge the more direct and robust solution.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.