SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company wants to automatically remediate an Amazon EC2 instance that becomes unresponsive by rebooting it. The solution should use AWS managed services to minimize custom code. Which combination should a SysOps administrator use? (Choose TWO.)
⚠ Common exam trap
It's easy for candidates to choose Option C (CloudWatch alarm + Lambda) because it is a common pattern, but the question explicitly requires minimizing custom code, making the managed Systems Manager Automation document the correct choice over a custom Lambda function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch alarm on EC2 status check failures
Amazon CloudWatch can monitor EC2 status check failures (both system and instance checks) and trigger an alarm. When the alarm enters the ALARM state, it can directly invoke an AWS Systems Manager Automation document to reboot the instance, which is a managed, code-free remediation approach. This combination minimizes custom code by using built-in AWS services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon EC2 Auto Scaling and lifecycle hooks
Why it's wrong here
Auto Scaling lifecycle hooks pause an instance during launch or termination transitions to let you run custom scripts or wait for health checks, but they are not invoked by EC2 status check failures. They are tied to scaling events (scale-out, scale-in), not to the ongoing operational health of a running instance. To automatically reboot an unhealthy instance, you need a CloudWatch alarm action or Systems Manager Automation, not a lifecycle hook.
- ✓
Amazon CloudWatch alarm on EC2 status check failures
Why this is correct
A CloudWatch alarm that watches the StatusCheckFailed (or StatusCheckFailed_System/Instance) metric detects when the EC2 service signals that the instance is unreachable or the OS is unresponsive. You can set the alarm to invoke the 'Reboot' EC2 action directly, requiring no custom code or additional infrastructure. Because the action is native, it is the most straightforward managed remedy for status-check-only failures.
- ✗
Amazon CloudWatch alarm and AWS Lambda function
Why it's wrong here
Using a Lambda function in conjunction with a CloudWatch alarm can reboot an instance, but it forces you to author, deploy, and maintain custom code and manage an IAM execution role. The function must parse alarm details and make an ec2:reboot-instances API call, adding complexity, cold-start latency, and potential permissions failures. Since AWS provides a fully managed Systems Manager Automation runbook for this exact purpose, this option is less appropriate for a simple auto-remediation design.
- ✗
Amazon EventBridge rule to trigger an SNS notification
Why it's wrong here
An EventBridge rule can capture EC2 status check anomalies and route them to an SNS topic, but SNS is only a push notification channel—it cannot execute an instance reboot. It will deliver messages to email, SMS, or HTTP endpoints, which might alert engineers but leaves remediation to a human or a downstream integration that isn't included here. Thus, this pattern provides insight, not automatic remediation, and fails the company's goal.
- ✓
AWS Systems Manager Automation document to reboot the instance
Why this is correct
AWS Systems Manager Automation offers a prebuilt runbook, AWS-RestartEC2Instance, that reboots an EC2 instance through a controlled, auditable workflow with IAM permissions. A CloudWatch alarm can trigger this automation via an EventBridge event or an SNS topic, giving you a managed way to respond to status-check failures without writing Lambda code. It also supports broader runbook actions such as sending status notifications or gathering logs before restart, making it a valid enterprise-grade remediation option.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.