Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company uses CloudWatch Logs to monitor application logs. The SysOps administrator wants to search for specific error patterns across multiple log groups. Which THREE AWS services can be used to achieve this?

⚠ Common exam trap

The trap here is that candidates may overlook Amazon OpenSearch Service and Amazon Athena as valid options because they require additional configuration (streaming or exporting logs), but the question asks which services 'can be used' to achieve the goal, not which are the most direct or native, so all three (A, B, D) are technically feasible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudWatch Logs Insights

CloudWatch Logs Insights is correct because it is a native AWS service designed specifically for querying and analyzing log data stored in CloudWatch Logs. It allows you to run SQL-like queries (using a query language) across multiple log groups to search for specific error patterns, making it a direct and efficient solution for this use case without requiring data export or additional infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CloudWatch Logs Insights

    Why this is correct

    CloudWatch Logs Insights is the native, serverless query engine for log data already in CloudWatch Logs. It uses a purpose-built query language with commands like fields, stats, filter, parse, and sort to run interactive, ad-hoc queries across one or multiple log groups in the same AWS account and Region. Because it operates directly on the log data without requiring any export or additional infrastructure, it is the most direct and cost-effective way to query application logs already collected by CloudWatch Logs.

  • ✓

    Amazon OpenSearch Service

    Why this is correct

    Amazon OpenSearch Service can indeed index and search CloudWatch Logs, but it requires setting up a subscription filter or a Lambda function to stream logs from CloudWatch Logs into an OpenSearch cluster. Once ingested, you can perform full-text and structured queries using OpenSearch's query DSL and visualize results with OpenSearch Dashboards. While powerful for long-term retention and rich analytics, it adds operational overhead for cluster management and data ingestion, making it a heavier solution than native CloudWatch Logs Insights for simple ad-hoc queries.

  • ✗

    Amazon Kinesis Data Analytics

    Why it's wrong here

    Amazon Kinesis Data Analytics is a real-time stream-processing service that runs SQL or Apache Flink applications against streaming data sources like Kinesis Data Streams or Kinesis Data Firehose. It is designed to continuously process and analyze data in motion, not to answer interactive, point-in-time queries on historical logs stored in CloudWatch Logs. Because it cannot query existing log groups directly and does not support ad-hoc batch-style queries, it is unsuitable for this monitoring use case.

  • ✓

    Amazon Athena

    Why this is correct

    Amazon Athena can query logs that are stored in Amazon S3 using standard SQL, and you can export CloudWatch Logs to S3 via the CreateExportTask API or by streaming them through Kinesis Data Firehose. It is serverless, requires no infrastructure, and supports many data formats, including JSON, Parquet, and Avro. However, it adds the operational step of exporting or delivering logs to S3, and it does not query CloudWatch Logs directly, making it a viable but less immediate option than CloudWatch Logs Insights.

  • ✗

    AWS Glue

    Why it's wrong here

    AWS Glue is a fully managed extract, transform, and load (ETL) service used to prepare data for analytics by running crawlers to discover schema and generating code to join, clean, and transform datasets. It is not designed for interactive querying; after processing, data typically lands in S3 for later analysis by services like Athena or Redshift Spectrum. Using Glue to query logs directly would be inappropriate because its primary function is data transformation and cataloging, not executing ad-hoc SQL or log-specific search operations.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.