Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company wants to centrally collect and analyze logs from all AWS accounts in an organization. The logs include CloudTrail, VPC Flow Logs, and AWS Config logs. Which solution is the most scalable and cost-effective?

⚠ Common exam trap

The trap here is that candidates often overcomplicate the solution by choosing managed services like CloudWatch Logs or Elasticsearch, overlooking the simplicity, scalability, and cost-effectiveness of S3 + Athena for centralized log analysis across multiple accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure each account to deliver logs to a centralized S3 bucket and use Amazon Athena to query them.

It uses a centralized S3 bucket to aggregate logs from all accounts, which is highly scalable and cost-effective due to S3's low storage costs and lifecycle policies. Amazon Athena then allows serverless, pay-per-query analysis of the logs without needing to provision or manage any infrastructure, making it ideal for ad-hoc and cross-account log analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stream all logs to a central CloudWatch Logs account using cross-account subscriptions.

    Why it's wrong here

    Cross-account subscriptions require each source account to configure subscription filters that stream CloudWatch Logs to a central account, often via Kinesis Data Streams or Firehose, adding architectural complexity and cross-account IAM/resource policies. Storing large volumes of log data in CloudWatch Logs is significantly more expensive per GB than S3, and the optional Kinesis pipeline incurs data transfer and processing costs. Managing this topology across many accounts also makes troubleshooting delivery failures harder, and it still lacks a single low-cost, serverless query engine like Athena.

  • ✗

    Use CloudWatch Logs Insights to query logs from each account individually.

    Why it's wrong here

    CloudWatch Logs Insights is a query engine that only operates within the scope of a single AWS account, so administrators would have to switch between accounts and repeat every query against each account's log groups individually. It cannot span log data from multiple accounts or deliver a unified, centralized view for correlation and analysis. Additionally, keeping logs in CloudWatch Logs for the purpose of querying is costlier on a per-GB basis than offloading them to S3, and the query capabilities are limited compared to a fully serverless Athena setup over a central data lake.

  • ✗

    Use Amazon Kinesis Data Firehose to deliver logs to an Amazon Elasticsearch Service cluster.

    Why it's wrong here

    Using Kinesis Data Firehose to deliver logs into an Amazon Elasticsearch Service cluster requires you to provision, configure, and scale an Elasticsearch domain—with EBS volumes, instance counts, and shard tuning—which adds operational overhead and variable costs that grow with log volume. The Firehose-to-ES pipeline also involves managing index mappings, retries for stuck batches, and cluster health, making it a heavier and more expensive solution for central log aggregation than a passive S3 bucket. For large, high-frequency log streams, the cost of ES nodes and the complexity of ongoing cluster maintenance make this option less cost-effective and more complicated than the serverless S3-plus-Athena alternative.

  • ✓

    Configure each account to deliver logs to a centralized S3 bucket and use Amazon Athena to query them.

    Why this is correct

    This option centralizes logs by having each account deliver log files to a single S3 bucket—either directly or via S3 Cross-Account Replication—and then uses Amazon Athena to run SQL queries across that centralized data lake. S3 offers cheap, durable, and scalable storage for large volumes of logs, while Athena is serverless and charges only for the data actually scanned per query. By partitioning the S3 paths by account, region, and date and using AWS Glue Data Catalog (or a crawler), analysts can run cross-account queries from one place without managing any query infrastructure, making it the most cost-effective and operationally simple solution.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.