Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator is tasked with setting up a solution that automatically terminates EC2 instances that have been running for more than 24 hours. Which steps should the administrator take? (Select THREE.)

⚠ Common exam trap

A common mix-up: candidates confuse lifecycle hooks (which are for Auto Scaling events) with scheduled termination logic, or assume CloudWatch has a built-in 'InstanceAge' metric, when in fact no such metric exists and the correct approach requires a custom tagging and Lambda-based solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tag each EC2 instance with its launch time (e.g., key: LaunchTime, value: timestamp).

Tagging each EC2 instance with its launch time (e.g., key: LaunchTime, value: timestamp) provides a reliable, queryable metadata point that a Lambda function can use to calculate instance age. This approach avoids reliance on the EC2 instance's launch time attribute, which can be altered or unavailable in certain scenarios (e.g., stopped/started instances). The tag serves as a deterministic reference for the Lambda function to compare against the current time and decide termination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an Auto Scaling group lifecycle hook to terminate instances after 24 hours.

    Why it's wrong here

    Auto Scaling lifecycle hooks only intercept instances during scale-in or scale-out transitions to perform custom actions, such as draining connections or running scripts, before the instance is terminated or launched. They do not provide a time-based scheduling mechanism to terminate instances after a set age; instead, they pause the lifecycle transition until a timeout or manual action occurs. Therefore, a lifecycle hook cannot enforce a 24-hour maximum instance age.

  • ✗

    Create a CloudWatch alarm on the InstanceAge metric and set it to trigger the Lambda function.

    Why it's wrong here

    Amazon EC2 does not expose an 'InstanceAge' metric in CloudWatch, so you cannot create a native CloudWatch alarm on that metric to trigger a Lambda function. While you could publish a custom metric that tracks instance age, doing so would require your own code and a separate scheduling mechanism, defeating the simplicity of the intended solution. Moreover, CloudWatch alarms are designed to react to threshold breaches of monitored metrics, not to compute age from launch times directly.

  • ✓

    Tag each EC2 instance with its launch time (e.g., key: LaunchTime, value: timestamp).

    Why this is correct

    Tagging each EC2 instance with its launch time (e.g., key: LaunchTime, value: timestamp) gives the Lambda function the necessary metadata to calculate the instance's age during each invocation. This tag can be read via the DescribeInstances API call, allowing the function to compare the stored timestamp with the current time and identify any instance older than 24 hours. It also makes the process stateless and independent of EC2's built-in attribute details, ensuring the solution works across instances in any state.

  • ✓

    Create an Amazon EventBridge rule that triggers the Lambda function on a schedule (e.g., every hour).

    Why this is correct

    An Amazon EventBridge rule configured on a schedule, such as every hour or every 5 minutes, provides the event source that invokes the Lambda function regularly, ensuring age-based cleanup is performed even for instances launched between invocations. This scheduled trigger is a reliable, serverless way to drive periodic reconciliation without needing an external cron server or a continuously running process. The same rule can be scoped to run 24/7, guaranteeing that instances are terminated within the defined interval after they exceed the threshold.

  • ✓

    Create an AWS Lambda function that uses the EC2 API to terminate instances older than 24 hours.

    Why this is correct

    Creating an AWS Lambda function that uses the EC2 API to terminate instances older than 24 hours is the core execution component that performs the actual termination. The function can call DescribeInstances to list instances, filter them based on the LaunchTime tag or the instance's launch time attribute, and then call TerminateInstances for those exceeding the age threshold. This approach provides full control over the cleanup logic, including handling of edge cases and adding logging or notifications, and it aligns with a serverless architecture.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.