Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator is troubleshooting an issue where an EC2 instance's CloudWatch agent is not sending memory metrics. The agent is installed and configured to collect memory metrics. The IAM role attached to the instance has the following policy:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "cloudwatch:PutMetricData",
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": "cloudwatch:ListMetrics",
      "Resource": "*"
    }
  ]
}

What is the most likely reason the memory metrics are not appearing?

⚠ Common exam trap

Candidates often focus solely on the cloudwatch:PutMetricData permission and overlook other required permissions like ssm:GetParameter. The policy already includes PutMetricData, so option C is a distractor if not read carefully; however, the real issue is the missing ssm:GetParameter permission needed for configuration retrieval from Parameter Store.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM role is missing the ssm:GetParameter permission.

The IAM policy includes cloudwatch:PutMetricData and cloudwatch:ListMetrics, but if the CloudWatch agent retrieves its memory metrics configuration from Systems Manager Parameter Store (a common setup), the instance requires the ssm:GetParameter permission. Without this permission, the agent cannot fetch the configuration, and memory metrics will not be sent. Therefore, option C correctly identifies the missing IAM permission.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The CloudWatch agent requires the SSM Agent to be installed.

    Why it's wrong here

    The CloudWatch agent is a standalone daemon and does not depend on the SSM Agent being installed. Although Systems Manager can deploy the agent, the CloudWatch agent itself directly performs all monitoring functions, including reading its configuration and calling CloudWatch APIs. The SSM Agent is a separate service used for different Systems Manager capabilities, so its absence does not prevent CloudWatch agent operation.

  • ✗

    The CloudWatch agent must be configured to send metrics to CloudWatch Logs first.

    Why it's wrong here

    Metrics and logs are independent delivery paths in the CloudWatch agent. The agent can send custom metrics to CloudWatch using the CloudWatch API while remaining completely unconfigured for log collection. There is no prerequisite that logs be sent or configured first, and the agent's metrics behavior is governed solely by its metrics configuration and IAM permissions.

  • ✓

    The IAM role is missing the ssm:GetParameter permission.

    Why this is correct

    This is the root cause because the CloudWatch agent is configured to retrieve its metrics configuration from the SSM Parameter Store. To read that configuration, the EC2 instance's IAM role must include the ssm:GetParameter permission; without it, the agent cannot fetch the JSON that defines which memory metrics to collect. Even though the role includes cloudwatch:PutMetricData, the agent has no configuration to act on, so no memory metrics are published.

  • ✗

    Detailed monitoring must be enabled on the EC2 instance.

    Why it's wrong here

    Detailed monitoring, which changes EC2 metric collection from 5-minute to 1-minute intervals, applies only to the built-in EC2 metrics such as CPUUtilization and NetworkIn. Memory usage is a custom metric that the CloudWatch agent publishes via PutMetricData, and its collection interval is controlled by the agent's configuration, not by detailed monitoring. Enabling detailed monitoring would not cause the agent to collect memory metrics.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SysOps administrator is troubleshooting an EC2 instance that is unresponsive. The administrator can SSH into the instance but finds that the CloudWatch agent is not sending custom metrics. The CloudWatch agent configuration file is at '/opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.json'. What should the administrator check first?

medium
  • ✓ A.Verify that the IAM role attached to the EC2 instance has the CloudWatchAgentServerPolicy.
  • B.Ensure that the IAM user has permissions to access CloudWatch.
  • C.Check if the security group allows outbound traffic on port 443.
  • D.Run 'sudo /opt/aws/amazon-cloudwatch-agent/bin/amazon-cloudwatch-agent-ctl -a status' to check the agent status.

Why A: The correct first check is to verify the IAM role attached to the EC2 instance has the CloudWatchAgentServerPolicy. The CloudWatch agent uses the instance's IAM role to obtain credentials for publishing metrics to CloudWatch. Without this policy, the agent will fail to send custom metrics even if it is running correctly and the instance has network connectivity.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.