SOA-C02 Monitoring, Logging, and Remediation Practice Question
Exhibit
Consider the following IAM policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "cloudwatch:PutMetricData",
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": "arn:aws:logs:us-east-1:123456789012:*"
}
]
}Refer to the exhibit. A SysOps administrator created this IAM policy for an application that sends custom metrics to CloudWatch and writes logs to CloudWatch Logs. The application reports that it cannot publish logs. What is the most likely reason?
⚠ Common exam trap
Many candidates assume a wildcard resource ARN like `arn:aws:logs:region:account:*` is sufficient for CloudWatch Logs actions, but they overlook the required `log-group:` prefix in the ARN structure, leading them to incorrectly suspect missing conditions or role assumption issues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The resource ARN for the logs actions is incorrect; it should include 'log-group:' before the wildcard.
The IAM policy uses `arn:aws:logs:us-east-1:123456789012:*` for the `Resource` element of the `logs:PutLogEvents` and `logs:CreateLogGroup` actions. For CloudWatch Logs, the resource ARN must include the `log-group:` prefix before the log group name or wildcard, such as `arn:aws:logs:us-east-1:123456789012:log-group:*`. Without this prefix, the ARN does not match any valid CloudWatch Logs resource, causing the application to fail when attempting to publish logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The resource ARN for the logs actions is incorrect; it should include 'log-group:' before the wildcard.
Why this is correct
The ARN for CloudWatch Logs actions must follow the format arn:aws:logs:region:account-id:log-group:log-group-name:*. Omitting the 'log-group:' prefix produces an invalid ARN that cannot match any log group, so the policy would not grant the necessary permissions. Without this prefix, IAM cannot resolve the resource to a specific log group, causing the logs actions to fail at runtime.
- ✗
The policy requires a condition key to restrict access to specific log groups.
Why it's wrong here
IAM policy conditions are optional; they can be used to scope permissions by tags, time, or other context, but they are never required simply to restrict access to log groups. The malformed resource ARN is the actual defect preventing the logs actions from working. If the ARN were correctly formed with a log-group: prefix, the wildcard would already allow all log groups without needing a condition.
- ✗
The policy does not allow the cloudwatch:PutMetricData action for the specific metric.
Why it's wrong here
The cloudwatch:PutMetricData action is not resource-scoped because CloudWatch metrics do not exist as IAM resources; a policy granting this action with a resource of '*' permits writing to any metric. The metric name or namespace is not part of the IAM ARN and cannot be restricted via the Resource element. Therefore, the policy already covers PutMetricData and this statement is not a reason the policy fails.
- ✗
The application must assume an IAM role to write logs.
Why it's wrong here
Assuming an IAM role is not a prerequisite for using this policy; the policy can be attached directly to an IAM user, a group, or an EC2 instance profile. The application only needs valid credentials from the entity to which the policy is attached, and those credentials can come directly from an IAM user or a role assumed by an instance. The actual issue remains the incorrectly formatted resource ARN for the CloudWatch Logs actions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.