SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator manages an Application Load Balancer (ALB) that distributes traffic to an Auto Scaling group of EC2 instances. The administrator needs to receive a notification whenever the number of unhealthy targets in the ALB target group exceeds a threshold of 2 for at least 5 consecutive minutes. Which solution meets this requirement with the least operational overhead?
⚠ Common exam trap
The trap is avoiding overcomplicated solutions like custom polling (Option D) or misapplied services (CloudTrail/Config). However, candidates must also correctly configure the CloudWatch alarm's Period and EvaluationPeriods to detect 5 consecutive minutes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudWatch alarm on the 'UnHealthyHostCount' metric for the ALB target group, with a threshold of 2 and an evaluation period of 5 minutes. Configure the alarm to send an Amazon SNS notification.
CloudWatch publishes UnHealthyHostCount for ALB target groups. To meet the requirement of >2 unhealthy targets for 5 consecutive minutes, the alarm must use a Period of 1 minute and an EvaluationPeriods value of 5. Setting the Period to 5 minutes would aggregate a 5-minute block and not verify each minute's count exceeded 2. Option A as written is imprecise and could lead to a configuration that does not meet the requirement. The correct implementation still uses an SNS notification on the CloudWatch alarm, so Option A remains the best choice if corrected to specify the appropriate Period and EvaluationPeriods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a CloudWatch alarm on the 'UnHealthyHostCount' metric for the ALB target group, with a threshold of 2 and an evaluation period of 5 minutes. Configure the alarm to send an Amazon SNS notification.
Why this is correct
CloudWatch automatically receives the UnHealthyHostCount metric from the ALB's target group, so a CloudWatch alarm can directly monitor unhealthy host counts without any custom code. Setting the threshold to 2 and an evaluation period of 5 minutes triggers the alarm when the count exceeds 2 for that duration, and the alarm's SNS action sends a notification to subscribed endpoints. This is the simplest and most reliable approach because it uses native AWS monitoring.
- ✗
Enable AWS CloudTrail logging for the ALB and create a CloudWatch metric filter for 'UnHealthyHostCount' events. Then create an alarm on that metric to notify via SNS.
Why it's wrong here
CloudTrail records API calls made to the ALB service, such as CreateLoadBalancer or ModifyTargetGroup, but it does not capture the health-check metric UnHealthyHostCount, which is continuously emitted by the ALB as a CloudWatch metric. A CloudWatch metric filter can parse log events, but CloudTrail logs do not contain the health-check values, so no metric would be generated from this filter. Therefore this approach would produce no notifications and is based on a fundamental misunderstanding of the data sources.
- ✗
Use an AWS Config rule to evaluate the health of the ALB target group and trigger an SNS notification when non-compliant.
Why it's wrong here
AWS Config rules assess resource configurations against desired policies, such as whether a target group has the correct protocol or health-check path, and are evaluated on a periodic or configuration-change basis. The UnHealthyHostCount is a dynamic operational metric that reflects the current state of target health at a given moment, not a static configuration attribute. Since Config does not ingest real-time CloudWatch metrics into its compliance evaluation, this rule would either fail to evaluate the desired condition or require custom remediation, making it unsuitable for real-time alerting.
- ✗
Create an Amazon EventBridge rule that triggers every minute to call the AWS CLI command describe-target-health and send a notification via Lambda if unhealthy count exceeds 2.
Why it's wrong here
Creating an EventBridge scheduled rule that invokes a Lambda function every minute to call describe-target-health and then parse the output to count unhealthy hosts adds unnecessary complexity and cost. This approach places a custom polling workload on the ALB's API, risks hitting rate limits, and depends on additional IAM permissions and Lambda code to interpret the response. In contrast, CloudWatch already collects the UnHealthyHostCount metric and can directly trigger an SNS alarm, eliminating the need for custom logic and infrastructure.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.