SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator needs to set up monitoring for an application that runs on an EC2 instance. The application generates custom metrics that should be available for analysis in CloudWatch. Which steps are required to achieve this? (Select TWO.)
⚠ Common exam trap
Watch out — candidates often confuse the CloudWatch Logs agent with the CloudWatch agent, as the Logs agent cannot send custom metrics, and assuming detailed monitoring automatically captures application-level metrics rather than just increasing the frequency of default EC2 metrics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM role to the EC2 instance with permissions to call PutMetricData.
The EC2 instance must have an IAM role attached with permissions to call PutMetricData, which authorizes the instance to publish custom metrics to CloudWatch. Without this IAM role, any attempt to send metrics from the instance will fail due to missing credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attach an IAM role to the EC2 instance with permissions to call PutMetricData.
Why this is correct
Attaching an IAM instance profile role to the EC2 instance is the recommended and secure way to grant the application the necessary cloudwatch:PutMetricData permission. Without these credentials, any call to the PutMetricData API will fail with an authorization error, and embedding long-term access keys in the instance is a security anti-pattern. The IAM role, assumed via the instance metadata service, provides temporary credentials that are automatically rotated and scoped to the exact actions and resources allowed by the attached policy.
- ✗
Create an SNS topic and subscribe the application to send metrics.
Why it's wrong here
SNS (Simple Notification Service) is a fully managed pub/sub messaging service intended for sending notifications (e.g., email, SMS, Lambda invocations) and decoupling event producers from consumers. It does not have any endpoint or integration that accepts metric data points and forwards them to CloudWatch; attempting to publish metric values to an SNS topic would simply trigger a notification, not store or plot them. Custom metrics must be submitted directly to CloudWatch via the PutMetricData API, not through SNS.
- ✗
Install the CloudWatch Logs agent to send custom metrics.
Why it's wrong here
The CloudWatch Logs agent (or the unified agent in logs-only mode) is designed to collect, monitor, and ship log files (text/event data) to CloudWatch Logs, not to send numeric metric datapoints. While the unified agent can also collect system metrics if configured in its metrics mode, the older 'Logs agent' alone does not have the capability to invoke PutMetricData or generate metric series. For custom metrics, you need either the CloudWatch agent's metric collection feature or a direct call to the PutMetricData API.
- ✓
Use the CloudWatch agent or AWS CLI to publish custom metrics using the put-metric-data command.
Why this is correct
This is a valid alternative to the IAM role approach: you can manually publish custom metrics using the AWS CLI command `aws cloudwatch put-metric-data` or configure the unified CloudWatch agent to collect and send application/system metrics. Both methods ultimately call the PutMetricData API, which requires the calling principal to have cloudwatch:PutMetricData IAM permissions. This approach is often used for one-off queries, scripts, or on-premises servers where an instance role is not available, but it still relies on valid AWS credentials.
- ✗
Enable detailed monitoring on the EC2 instance to collect custom metrics.
Why it's wrong here
Enabling detailed monitoring on an EC2 instance merely changes the frequency of default AWS metrics—such as CPUUtilization, NetworkIn, and DiskReadOps—from 5-minute to 1-minute intervals; it does not expand the set of metrics that AWS publishes for you. Custom metrics are user-defined data points that your application or agent must submit via the PutMetricData API, and they are not affected by the instance's monitoring level. Therefore, detailed monitoring is irrelevant to collecting custom application metrics and would not achieve the desired outcome.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.