SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator is troubleshooting an issue where an Amazon EC2 instance running Amazon Linux 2 is not sending logs to CloudWatch Logs. The CloudWatch agent is installed and configured. Which step should the administrator take FIRST to diagnose the issue?
⚠ Common exam trap
Watch out — candidates often assume the IAM role is the most common cause of log delivery failure and jump to updating it, but the question specifies the agent is already installed and configured, so the first logical step is to check the agent's own logs to confirm the exact error before making any changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the CloudWatch agent status and review its log files on the instance.
The CloudWatch agent is already installed and configured, so the first step is to check its operational status and review its own log files (typically in /var/log/aws/amazon-cloudwatch-agent/). This directly reveals whether the agent is running, encountering configuration errors, or failing to connect to the CloudWatch Logs service endpoint, without making unnecessary changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reinstall the CloudWatch agent from the AWS Systems Manager.
Why it's wrong here
Reinstalling the CloudWatch agent via Systems Manager Run Command or State Manager is a heavy-handed action that assumes the agent binary is corrupted or missing. However, the agent may already be running but misconfigured, lacking network connectivity, or experiencing an IAM credential issue; reinstall does not alter an existing agent configuration file or the instance's IAM role. It also risks losing custom agent configuration in /opt/aws/amazon-cloudwatch-agent/etc and does not provide diagnostic output for the actual error, making it a time-consuming step that should only be considered after reviewing agent logs.
- ✗
Update the IAM role attached to the instance to include CloudWatch Logs permissions.
Why it's wrong here
While insufficient IAM permissions absolutely can prevent the CloudWatch agent from publishing logs, blindly updating the IAM role is premature without first inspecting the agent's runtime state. The agent logs will show specific errors such as 'AccessDeniedException' or 'Unable to assume role', which would confirm a permissions problem rather than a configuration or network issue. Additionally, IAM policy changes may take several minutes to propagate and require the instance to refresh its temporary credentials, so this step is best supported by evidence from the agent logs rather than guessing.
- ✗
Verify the EC2 instance status in the AWS Management Console.
Why it's wrong here
Checking the EC2 instance status in the AWS Management Console only tells you about the health of the underlying VM (e.g., status checks, CPU utilization, or instance state) and provides no visibility into the CloudWatch agent process, its configuration, or its connectivity to CloudWatch Logs. The console does not expose agent-level diagnostics such as parse errors in the agent JSON configuration, missing log file paths, or throttling from CloudWatch Logs APIs. Thus, this action is far too high-level and cannot reveal the specific reason log files are not being collected or delivered.
- ✓
Check the CloudWatch agent status and review its log files on the instance.
Why this is correct
Checking the CloudWatch agent status and reviewing its log files is the correct first step because it provides direct, actionable diagnostic information about the agent's runtime and integration with CloudWatch. Use commands like 'systemctl status amazon-cloudwatch-agent' or '/opt/aws/amazon-cloudwatch-agent/bin/amazon-cloudwatch-agent-ctl -a status' to confirm the agent is running, then inspect '/opt/aws/amazon-cloudwatch-agent/logs/amazon-cloudwatch-agent.log' and 'agent.log' entries for errors such as 'Error occurred during config', 'dial tcp: i/o timeout', or 'ResourceNotFoundException'. These logs reveal whether the problem is a malformed configuration file, missing IAM permissions, a network/firewall block, or an issue with the log file path itself, enabling a targeted resolution instead of trial-and-error.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.