Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company wants to be able to query application logs in near real-time using a SQL-like syntax. Which AWS service should be used?

⚠ Common exam trap

Candidates often confuse CloudWatch Logs Insights with CloudWatch Metrics Insights, assuming both can query logs, but Metrics Insights only works with numeric metric data and cannot parse or search log message content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudWatch Logs Insights

CloudWatch Logs Insights is the correct service because it enables interactive querying of log data stored in CloudWatch Logs using a purpose-built SQL-like query language. It is designed for ad-hoc analysis of logs in near real-time, allowing users to filter, aggregate, and visualize log events without needing to export data to another analytics platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CloudWatch Logs Insights

    Why this is correct

    CloudWatch Logs Insights is a purpose-built query engine for log data stored in CloudWatch Logs. It uses a SQL-like query language to parse, filter, aggregate, and visualize log events in near real-time. Queries can be run across one or more log groups and saved for reuse, making it the correct tool for directly querying application logs.

  • ✗

    CloudWatch Metrics Insights

    Why it's wrong here

    CloudWatch Metrics Insights is designed for querying numeric CloudWatch metrics, not log data. It offers a SQL-like syntax to aggregate and analyze metric streams across resources, but it cannot access the textual content of application log events. Because the requirement is to query logs, Metrics Insights operates on the wrong data type and is therefore incorrect.

  • ✗

    CloudWatch Events

    Why it's wrong here

    CloudWatch Events, now known as Amazon EventBridge, provides a near-real-time stream of system events that describe changes in AWS resources. It is intended for event-driven automation, such as triggering Lambda functions or sending notifications, not for storing or querying historical application log data. Therefore, it cannot be used to query logs.

  • ✗

    CloudWatch Logs subscription filters

    Why it's wrong here

    CloudWatch Logs subscription filters deliver a real-time stream of log events to destinations like Kinesis Data Firehose, Lambda, or Amazon OpenSearch Service. They filter and forward logs, but they do not provide an interactive query interface; any analysis requires building additional infrastructure at the destination. For direct near-real-time querying, Logs Insights is the inherent capability, making subscription filters incorrect.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.