SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company wants to be able to query application logs in near real-time using a SQL-like syntax. Which AWS service should be used?
⚠ Common exam trap
Candidates often confuse CloudWatch Logs Insights with CloudWatch Metrics Insights, assuming both can query logs, but Metrics Insights only works with numeric metric data and cannot parse or search log message content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudWatch Logs Insights
CloudWatch Logs Insights is the correct service because it enables interactive querying of log data stored in CloudWatch Logs using a purpose-built SQL-like query language. It is designed for ad-hoc analysis of logs in near real-time, allowing users to filter, aggregate, and visualize log events without needing to export data to another analytics platform.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CloudWatch Logs Insights
Why this is correct
CloudWatch Logs Insights is a purpose-built query engine for log data stored in CloudWatch Logs. It uses a SQL-like query language to parse, filter, aggregate, and visualize log events in near real-time. Queries can be run across one or more log groups and saved for reuse, making it the correct tool for directly querying application logs.
- ✗
CloudWatch Metrics Insights
Why it's wrong here
CloudWatch Metrics Insights is designed for querying numeric CloudWatch metrics, not log data. It offers a SQL-like syntax to aggregate and analyze metric streams across resources, but it cannot access the textual content of application log events. Because the requirement is to query logs, Metrics Insights operates on the wrong data type and is therefore incorrect.
- ✗
CloudWatch Events
Why it's wrong here
CloudWatch Events, now known as Amazon EventBridge, provides a near-real-time stream of system events that describe changes in AWS resources. It is intended for event-driven automation, such as triggering Lambda functions or sending notifications, not for storing or querying historical application log data. Therefore, it cannot be used to query logs.
- ✗
CloudWatch Logs subscription filters
Why it's wrong here
CloudWatch Logs subscription filters deliver a real-time stream of log events to destinations like Kinesis Data Firehose, Lambda, or Amazon OpenSearch Service. They filter and forward logs, but they do not provide an interactive query interface; any analysis requires building additional infrastructure at the destination. For direct near-real-time querying, Logs Insights is the inherent capability, making subscription filters incorrect.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.