SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator is troubleshooting an EC2 instance that is unresponsive. The administrator can SSH into the instance but finds that the CloudWatch agent is not sending custom metrics. The CloudWatch agent configuration file is at '/opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.json'. What should the administrator check first?
⚠ Common exam trap
The trap here is that candidates often jump to checking network connectivity (security group rules) or agent status first, overlooking that the IAM role permission is the most common root cause for a CloudWatch agent that is installed and running but not sending metrics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the IAM role attached to the EC2 instance has the CloudWatchAgentServerPolicy.
The correct first check is to verify the IAM role attached to the EC2 instance has the CloudWatchAgentServerPolicy. The CloudWatch agent uses the instance's IAM role to obtain credentials for publishing metrics to CloudWatch. Without this policy, the agent will fail to send custom metrics even if it is running correctly and the instance has network connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify that the IAM role attached to the EC2 instance has the CloudWatchAgentServerPolicy.
Why this is correct
The CloudWatch agent on EC2 uses the instance's IAM role to obtain temporary credentials via the instance metadata service. Without the CloudWatchAgentServerPolicy, which grants PutMetricData, the agent cannot publish custom metrics. This is the first thing to verify because it directly controls the agent's authorization to call CloudWatch.
- ✗
Ensure that the IAM user has permissions to access CloudWatch.
Why it's wrong here
The EC2 instance is not logged in as an IAM user; it uses an attached IAM role. IAM user permissions apply when a human uses the AWS CLI or console, not to processes running on the instance. Therefore, granting IAM user permissions would have no effect on the CloudWatch agent running on that EC2 instance.
- ✗
Check if the security group allows outbound traffic on port 443.
Why it's wrong here
The CloudWatch agent communicates with AWS endpoints over HTTPS (443), but security groups typically allow all outbound traffic by default. Even if restricted, the failure would manifest as a network connectivity error, not as a permissions error; the agent logs would show connection timeouts. The issue described (agent not sending metrics) is more likely IAM permissions; port 443 is a secondary check after confirming the IAM role.
- ✗
Run 'sudo /opt/aws/amazon-cloudwatch-agent/bin/amazon-cloudwatch-agent-ctl -a status' to check the agent status.
Why it's wrong here
Checking the agent status with amazon-cloudwatch-agent-ctl tells you whether the agent is running and its configuration, but it won't reveal IAM permission problems. The command may show the agent as active even though it cannot put metrics due to missing authorization. IAM policy issues should be diagnosed first via CloudWatch Logs or by checking the role's permissions.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.