SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator needs to analyze application logs stored in Amazon CloudWatch Logs to find specific error patterns across multiple log groups. The administrator wants to run queries to filter and parse the logs. Which feature should the administrator use?
⚠ Common exam trap
A common mix-up: candidates confuse CloudWatch Metric Filters (which can filter logs for metric extraction) with the interactive querying capability of CloudWatch Logs Insights, but Metric Filters cannot parse or analyze log content across multiple log groups in a query-like manner.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudWatch Logs Insights
CloudWatch Logs Insights is the correct feature because it enables you to interactively search and analyze log data stored in CloudWatch Logs using a purpose-built query language. It allows you to run queries across multiple log groups, filter, parse, and aggregate logs to identify specific error patterns, making it ideal for ad-hoc log analysis and troubleshooting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CloudWatch Logs subscriptions
Why it's wrong here
CloudWatch Logs subscriptions are a real-time streaming mechanism that forwards log events to destinations such as AWS Lambda, Amazon Kinesis, or Amazon OpenSearch Service for processing and enrichment. They do not provide any interactive query capability against stored logs—once you set a subscription, data is pushed out as it arrives, and you would need to build separate query tooling on the destination to analyze history. For ad-hoc, on-demand investigation of application errors, subscriptions are the wrong tool because they focus on continuous egress, not on exploring already-collected log data.
- ✓
CloudWatch Logs Insights
Why this is correct
CloudWatch Logs Insights is the correct choice because it is a dedicated, fully managed query engine for log data stored in CloudWatch Logs. It uses a SQL-like query language (fields, filter, stats, sort, etc.) to run interactive, ad-hoc searches across one or more log groups, allowing you to discover error patterns, aggregate results, and visualize findings in the console. Unlike the other options, Logs Insights is specifically designed to answer arbitrary questions on historical log data without requiring any external pipeline.
- ✗
CloudWatch Metric Filters
Why it's wrong here
CloudWatch Metric Filters transform incoming log events into CloudWatch metrics by matching a specific literal pattern or a Java-style regex. Each metric filter can only count occurrences (or extract a numeric value) and publish that as a time-series metric—it does not let you retrieve or filter raw log messages for detailed inspection. While a metric filter would allow you to alarm on an increasing error count, it cannot show you the actual error messages, stack traces, or surrounding context, so it fails the requirement to analyze application logs in depth.
- ✗
CloudWatch Contributor Insights
Why it's wrong here
CloudWatch Contributor Insights is designed to analyze time-series data from logs to identify the top contributing entities—such as IP addresses, user IDs, or URLs—based on how often they appear in a field. It gives you a ranked view of high-volume contributors (e.g., which client IP causes the most errors) but does not support flexible querying for arbitrary error patterns or complex filtering across multiple log groups. Its default output is a table of top contributors with network metrics, not a general-purpose log query console, so it is not a substitute for Logs Insights.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.