Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company wants to receive alerts when an Auto Scaling group launches or terminates instances. They already have a CloudTrail trail enabled. What is the simplest way to achieve this?

⚠ Common exam trap

The trap here is that candidates often overcomplicate the solution by choosing lifecycle hooks (Option C) or custom scripts (Option B), not realizing that CloudWatch Events can directly consume CloudTrail API events for Auto Scaling without additional infrastructure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CloudWatch Events rule that matches Auto Scaling event patterns and sends notifications to an SNS topic.

CloudWatch Events (now part of Amazon EventBridge) can automatically capture Auto Scaling group state changes (launch and terminate) via CloudTrail API calls. By creating a rule that matches the specific event pattern for Auto Scaling events (e.g., 'EC2 Instance Launch Successful' and 'EC2 Instance Terminate Successful'), you can directly route those events to an SNS topic, which then sends notifications (e.g., email or SMS). This requires no custom code, lifecycle hooks, or additional monitoring configuration, making it the simplest solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a CloudWatch Events rule that matches Auto Scaling event patterns and sends notifications to an SNS topic.

    Why this is correct

    A CloudWatch Events rule (EventBridge) can filter Auto Scaling group state-change events, such as EC2 Instance Launch Successful and EC2 Instance Terminate Successful, which are published automatically by the ASG service. The rule targets an SNS topic, delivering near real-time notifications to subscribed endpoints like email or SMS. This is the simplest, fully managed approach because it requires no instances, scripts, or custom code, and leverages an existing, reliable event stream.

  • ✗

    Write a script on each EC2 instance to call the CloudWatch Logs API on launch/termination.

    Why it's wrong here

    Embedding a script in each EC2 instance's user data to call the CloudWatch Logs API on launch or termination is inherently unreliable because an instance may be terminated abruptly by a spot interruption, scaling policy, or failed health check, leaving no chance for the script to execute. It also requires distributing and maintaining scripts, managing IAM credentials on instances, and handling errors. CloudWatch Logs API is designed for ingesting log events, not for sending operational notifications about scaling events, and the ASG's native event stream already records these transitions.

  • ✗

    Configure the Auto Scaling group to publish lifecycle hooks and use Lambda to send notifications.

    Why it's wrong here

    Lifecycle hooks are intended to pause Auto Scaling activity for custom initialization or decommissioning tasks, such as draining connections or backing up data, and require the instance to signal completion via CompleteLifecycleAction. Using them merely to publish notifications introduces significant overhead: you must set up a Lambda function to handle the hook, send the SNS message, and call CompleteLifecycleAction, otherwise the instance launch or termination may time out and be abandoned. This adds complexity and latency, making it a poor fit for simple alerting when EventBridge provides a direct, no-code integration with SNS.

  • ✗

    Enable CloudWatch detailed monitoring on the Auto Scaling group and create alarms.

    Why it's wrong here

    Detailed monitoring changes the CloudWatch metric granularity for EC2 instances inside the Auto Scaling group from 5-minute to 1-minute data points, but it does not generate or expose lifecycle events. CloudWatch alarms evaluate numeric metrics like CPUUtilization or NetworkIn against thresholds; they have no concept of an instance launching or terminating as an event. While you could create a composite alarm based on group metrics such as GroupInService, that only infers scaling activity indirectly and with delay, and it cannot match specific event patterns like 'EC2 Instance Launch Successful' the way an EventBridge rule can.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.