SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company uses AWS CloudFormation to deploy infrastructure. The operations team wants to be notified when a stack enters a ROLLBACK_IN_PROGRESS state. Which TWO methods can achieve this?
⚠ Common exam trap
Many exam-takers confuse CloudTrail API logging (which records the API call but not the asynchronous state transition) with event-driven notifications, or assume CloudWatch Logs subscription filters can parse CloudFormation events, when in fact CloudFormation does not write stack state changes to CloudWatch Logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Amazon CloudWatch Events rule that matches the CloudFormation stack status change.
Amazon CloudWatch Events (now Amazon EventBridge) can capture CloudFormation stack status changes, including ROLLBACK_IN_PROGRESS, by matching the 'CloudFormation Stack Status Change' event pattern. This allows you to trigger a notification action (e.g., via SNS or Lambda) in real time when the stack enters that state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config rules to evaluate the stack state.
Why it's wrong here
AWS Config rules evaluate resource configurations against desired policies, not CloudFormation stack lifecycle states. Config can assess resources created by the stack, but it does not monitor the stack's own status (e.g., UPDATE_COMPLETE, UPDATE_FAILED). Therefore, it cannot be used to directly detect a stack status change.
- ✓
Create an Amazon CloudWatch Events rule that matches the CloudFormation stack status change.
Why this is correct
CloudFormation publishes stack status change events to the default CloudWatch Events event bus. You can create an event rule with an event pattern matching the 'CloudFormation Stack Status Change' detail type and then target a Lambda function, SNS topic, or other service. This provides a near-real-time, serverless way to react to stack transitions without polling.
- ✗
Configure a CloudWatch Logs subscription filter to detect the stack state.
Why it's wrong here
CloudWatch Logs subscription filters analyze log data in log groups to route matching entries to destinations. CloudFormation does not write stack events to CloudWatch Logs by default; stack events are available through DescribeStackEvents and sent to CloudWatch Events/SNS, not to a log group. Thus, a subscription filter has nothing to subscribe to.
- ✗
Create a CloudTrail trail and monitor the UpdateStack API call.
Why it's wrong here
CloudTrail records API calls including UpdateStack, but you would need to parse the CloudTrail logs to identify the stack state, and the API call only indicates an update was initiated, not the final resulting status. Also, CloudTrail is for auditing API activity, not for real-time status change notifications. This approach requires custom logic and doesn't directly give you the stack status.
- ✓
Configure CloudFormation stack notifications to send events to an Amazon SNS topic.
Why this is correct
CloudFormation can be configured with an SNS topic in the stack's notification options, and it sends stack events (such as UPDATE_COMPLETE, UPDATE_FAILED, etc.) directly to that topic. This provides a simple push-based notification mechanism that can fan out to email, Lambda, or other subscribers. It is a valid alternative to CloudWatch Events for receiving stack status updates.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.