SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator needs to monitor the CPU utilization of an Amazon RDS DB instance and receive an alarm when CPU utilization exceeds 80% for 5 consecutive minutes. Which AWS service should be used to create this alarm?
⚠ Common exam trap
Candidates often confuse CloudTrail (for auditing API calls) with CloudWatch (for monitoring metrics and logs), leading them to select CloudTrail when the question explicitly asks about creating an alarm on a performance metric.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch
Amazon CloudWatch is the native AWS monitoring service that can track RDS DB instance metrics, such as CPU utilization, and trigger alarms based on thresholds and time periods. In this scenario, you would create a CloudWatch alarm on the `CPUUtilization` metric for the specific DB instance, with a threshold of 80% and a period of 5 consecutive minutes (e.g., 5 datapoints of 1-minute periods).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API actions performed by users, roles, or services, capturing event history for governance and audit purposes. It does not ingest or expose infrastructure performance counters such as CPU utilization, and it lacks any alarm or threshold evaluation capability for operational metrics. Consequently, CloudTrail cannot trigger notifications when an RDS instance's CPU crosses a threshold.
- ✓
Amazon CloudWatch
Why this is correct
Amazon CloudWatch is the native monitoring service for RDS, automatically collecting the CPUUtilization metric at one-minute or five-minute granularity depending on the database instance class. You can create an alarm that evaluates the metric over consecutive periods and then publishes to an SNS topic or invokes an action when the threshold is breached. This makes CloudWatch the appropriate tool for monitoring CPU utilization and alerting.
- ✗
AWS Config
Why it's wrong here
AWS Config evaluates resource configurations against managed or custom rules to assess compliance and track changes over time, such as detecting when an RDS instance is publicly accessible. It does not collect performance data or store time-series utilization metrics, so it cannot see current or historical CPU utilization. Therefore Config cannot be used to create CPU-based performance alarms.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor inspects your account and delivers best-practice recommendations in categories like cost optimization, fault tolerance, and performance, including flags for underutilized RDS instances. However, its checks are periodic advisory reports, not a real-time monitoring service, and it does not allow you to define custom alarms with thresholds for specific metrics such as CPU utilization. As a result, Trusted Advisor cannot directly notify you when CPU exceeds a configured limit.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.