SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator needs to monitor the application logs of a web server and receive an email notification when the number of 'ERROR' log entries exceeds 100 in a 5-minute window. The logs are already being sent to Amazon CloudWatch Logs. Which combination of AWS services should be used to meet this requirement with the least operational overhead?
⚠ Common exam trap
Watch out — candidates often confuse CloudTrail (which logs API calls) with CloudWatch Logs (which stores application logs), leading them to choose Option C, but CloudTrail cannot inspect application log content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudWatch Logs metric filter, CloudWatch alarm, and Amazon SNS
CloudWatch Logs metric filters can parse log events for the string 'ERROR' and count them in real time. A CloudWatch alarm can then trigger when the metric exceeds 100 in a 5-minute period, and Amazon SNS sends the email notification. This combination requires no custom code or additional infrastructure, minimizing operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CloudWatch Logs metric filter, CloudWatch alarm, and Amazon SNS
Why this is correct
A CloudWatch Logs metric filter continuously scans incoming log events for a pattern you define (e.g., ERROR or Exception) and incrementally publishes a custom metric to CloudWatch. A CloudWatch alarm then evaluates that metric against a threshold, and when the threshold is breached, the alarm state changes to ALARM and triggers an Amazon SNS topic to send an email notification. This is a native, fully managed, near-real-time monitoring solution with no custom code to maintain, making it the correct architecture.
- ✗
Amazon Kinesis Data Firehose and AWS Lambda
Why it's wrong here
Amazon Kinesis Data Firehose is a streaming ingestion service designed to load high-volume data into destinations like S3, Redshift, or OpenSearch; it does not natively evaluate log content or trigger alarms. To detect keywords, you would need an AWS Lambda function to inspect each record, extract metrics, and publish them to CloudWatch, and then you still must add a CloudWatch alarm and SNS topic for notification. This adds significant cost, complexity, and end-to-end latency compared to a simple metric filter, and is therefore over-engineered for this need.
- ✗
AWS CloudTrail and Amazon EventBridge
Why it's wrong here
AWS CloudTrail records API actions performed on AWS resources, such as CreateInstance or DeleteBucket, and those events can be routed to Amazon EventBridge for event-driven automation. However, CloudTrail does not see the application logs generated inside EC2 instances, containers, or Lambda functions—it only captures control-plane operations. Using CloudTrail and EventBridge would monitor AWS account activity, not the content of application log files, so it cannot satisfy the requirement of reacting to application log patterns.
- ✗
AWS Config managed rule and Amazon SNS
Why it's wrong here
AWS Config managed rules are prebuilt rules that evaluate the configuration settings of AWS resources against best practices, such as checking whether an S3 bucket has encryption enabled or whether a security group is overly permissive. Amazon SNS would only be used to notify you when a rule evaluates a resource as NON_COMPLIANT, but the rule has no awareness of application log contents. Because Config does not parse or analyze log streams, combining a Config managed rule with SNS cannot monitor application log errors or patterns, making this option fundamentally unsuited to the use case.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.