SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company uses CloudWatch Logs to monitor application logs. The SysOps administrator wants to search for specific error patterns across multiple log groups. Which THREE AWS services can be used to achieve this?
⚠ Common exam trap
The trap here is that candidates may overlook Amazon OpenSearch Service and Amazon Athena as valid options because they require additional configuration (streaming or exporting logs), but the question asks which services 'can be used' to achieve the goal, not which are the most direct or native, so all three (A, B, D) are technically feasible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudWatch Logs Insights
CloudWatch Logs Insights is correct because it is a native AWS service designed specifically for querying and analyzing log data stored in CloudWatch Logs. It allows you to run SQL-like queries (using a query language) across multiple log groups to search for specific error patterns, making it a direct and efficient solution for this use case without requiring data export or additional infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CloudWatch Logs Insights
Why this is correct
CloudWatch Logs Insights is the native, serverless query engine for log data already in CloudWatch Logs. It uses a purpose-built query language with commands like fields, stats, filter, parse, and sort to run interactive, ad-hoc queries across one or multiple log groups in the same AWS account and Region. Because it operates directly on the log data without requiring any export or additional infrastructure, it is the most direct and cost-effective way to query application logs already collected by CloudWatch Logs.
- ✓
Amazon OpenSearch Service
Why this is correct
Amazon OpenSearch Service can indeed index and search CloudWatch Logs, but it requires setting up a subscription filter or a Lambda function to stream logs from CloudWatch Logs into an OpenSearch cluster. Once ingested, you can perform full-text and structured queries using OpenSearch's query DSL and visualize results with OpenSearch Dashboards. While powerful for long-term retention and rich analytics, it adds operational overhead for cluster management and data ingestion, making it a heavier solution than native CloudWatch Logs Insights for simple ad-hoc queries.
- ✗
Amazon Kinesis Data Analytics
Why it's wrong here
Amazon Kinesis Data Analytics is a real-time stream-processing service that runs SQL or Apache Flink applications against streaming data sources like Kinesis Data Streams or Kinesis Data Firehose. It is designed to continuously process and analyze data in motion, not to answer interactive, point-in-time queries on historical logs stored in CloudWatch Logs. Because it cannot query existing log groups directly and does not support ad-hoc batch-style queries, it is unsuitable for this monitoring use case.
- ✓
Amazon Athena
Why this is correct
Amazon Athena can query logs that are stored in Amazon S3 using standard SQL, and you can export CloudWatch Logs to S3 via the CreateExportTask API or by streaming them through Kinesis Data Firehose. It is serverless, requires no infrastructure, and supports many data formats, including JSON, Parquet, and Avro. However, it adds the operational step of exporting or delivering logs to S3, and it does not query CloudWatch Logs directly, making it a viable but less immediate option than CloudWatch Logs Insights.
- ✗
AWS Glue
Why it's wrong here
AWS Glue is a fully managed extract, transform, and load (ETL) service used to prepare data for analytics by running crawlers to discover schema and generating code to join, clean, and transform datasets. It is not designed for interactive querying; after processing, data typically lands in S3 for later analysis by services like Athena or Redshift Spectrum. Using Glue to query logs directly would be inappropriate because its primary function is data transformation and cataloging, not executing ad-hoc SQL or log-specific search operations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.