SOA-C02 Monitoring, Logging, and Remediation Practice Question
An organization has a CloudWatch dashboard that displays metrics for multiple AWS services. The dashboard is shared with the operations team. Recently, some team members reported that the dashboard is not loading for them. Which action should the SysOps administrator take to troubleshoot the issue?
⚠ Common exam trap
It's easy for candidates to assume the issue is related to the CloudWatch agent or regional configuration, but the root cause is almost always an IAM permissions problem when a dashboard fails to load for users who previously had access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confirm that the team members have the necessary IAM permissions for cloudwatch:GetDashboard.
The most likely cause of the dashboard not loading is that the team members lack the required IAM permission to retrieve the dashboard definition. CloudWatch dashboards are stored as JSON objects, and the `cloudwatch:GetDashboard` action is necessary to fetch and render that data in the console. Without this permission, the API call fails silently, resulting in a blank or non-loading dashboard.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Confirm that the team members have the necessary IAM permissions for cloudwatch:GetDashboard.
Why this is correct
When a user accesses a CloudWatch console dashboard, the console calls the CloudWatch GetDashboard API to retrieve the dashboard's JSON definition and metric widget configuration. If the IAM policy attached to that user denies or omits the cloudwatch:GetDashboard action, the API returns AccessDenied and the dashboard fails to load even if the user can see other CloudWatch data. Because GetDashboard is a read operation scoped to the dashboard ARN, you must explicitly grant it in the user's identity-based policy, along with permissions for any metrics the widgets query. This is the first thing to verify when the dashboard renders blank or inaccessible.
- ✗
Verify that the team members have subscribed to the metric streams.
Why it's wrong here
Metric streams continuously export CloudWatch metrics to a destination such as Amazon S3, Kinesis Data Firehose, or a third-party observability platform; they do not deliver data to the CloudWatch console or to dashboards. A dashboard reads metrics directly from the CloudWatch Metrics service using the GetMetricData API, so subscribing to a metric stream has no effect on whether the dashboard will display. Users will never need a metric-stream subscription to view dashboards, because dashboards are visualization objects, not metric consumers from a stream. Therefore checking subscriptions would be a red herring.
- ✗
Ensure the CloudWatch agent is installed on the instances displaying the dashboard.
Why it's wrong here
The unified CloudWatch agent is a data-collection component installed on EC2 instances or on-premises servers to emit custom metrics and logs; it has no role in serving or rendering dashboard pages. Dashboards are served by the CloudWatch API and rendered in the user's web browser, so the client-side or server-side installation of the agent is irrelevant to dashboard availability. A user could have no agent installed on any instance and still view a dashboard, provided they have read access to the dashboard and its metric data. This option confuses the observability data pipeline with the access-control model.
- ✗
Check that the dashboard is in the same region as the resources.
Why it's wrong here
CloudWatch dashboards are regional resources in the sense that the dashboard object itself lives in a specific AWS Region, but the widget metrics inside can point to resources in any Region—for example, a single dashboard can show EC2 CPUUtilization from us-east-1 and us-west-2. Even if the dashboard's Region does not match the Region of the resources it displays, the dashboard will still load and show those cross-Region metrics as long as the viewer has the needed permissions. If the dashboard is not visible in the selected console region, the user may need to switch regions, but that is a navigation issue, not an authorization failure. Thus, a Region mismatch is not the cause of a 'cannot load' error.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.