Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

Exhibit

Consider the following IAM policy:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "cloudwatch:PutMetricData",
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "logs:CreateLogGroup",
                "logs:CreateLogStream",
                "logs:PutLogEvents"
            ],
            "Resource": "arn:aws:logs:us-east-1:123456789012:*"
        }
    ]
}

Refer to the exhibit. A SysOps administrator created this IAM policy for an application that sends custom metrics to CloudWatch and writes logs to CloudWatch Logs. The application reports that it cannot publish logs. What is the most likely reason?

⚠ Common exam trap

Many candidates assume a wildcard resource ARN like `arn:aws:logs:region:account:*` is sufficient for CloudWatch Logs actions, but they overlook the required `log-group:` prefix in the ARN structure, leading them to incorrectly suspect missing conditions or role assumption issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The resource ARN for the logs actions is incorrect; it should include 'log-group:' before the wildcard.

The IAM policy uses `arn:aws:logs:us-east-1:123456789012:*` for the `Resource` element of the `logs:PutLogEvents` and `logs:CreateLogGroup` actions. For CloudWatch Logs, the resource ARN must include the `log-group:` prefix before the log group name or wildcard, such as `arn:aws:logs:us-east-1:123456789012:log-group:*`. Without this prefix, the ARN does not match any valid CloudWatch Logs resource, causing the application to fail when attempting to publish logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The resource ARN for the logs actions is incorrect; it should include 'log-group:' before the wildcard.

    Why this is correct

    The ARN for CloudWatch Logs actions must follow the format arn:aws:logs:region:account-id:log-group:log-group-name:*. Omitting the 'log-group:' prefix produces an invalid ARN that cannot match any log group, so the policy would not grant the necessary permissions. Without this prefix, IAM cannot resolve the resource to a specific log group, causing the logs actions to fail at runtime.

  • ✗

    The policy requires a condition key to restrict access to specific log groups.

    Why it's wrong here

    IAM policy conditions are optional; they can be used to scope permissions by tags, time, or other context, but they are never required simply to restrict access to log groups. The malformed resource ARN is the actual defect preventing the logs actions from working. If the ARN were correctly formed with a log-group: prefix, the wildcard would already allow all log groups without needing a condition.

  • ✗

    The policy does not allow the cloudwatch:PutMetricData action for the specific metric.

    Why it's wrong here

    The cloudwatch:PutMetricData action is not resource-scoped because CloudWatch metrics do not exist as IAM resources; a policy granting this action with a resource of '*' permits writing to any metric. The metric name or namespace is not part of the IAM ARN and cannot be restricted via the Resource element. Therefore, the policy already covers PutMetricData and this statement is not a reason the policy fails.

  • ✗

    The application must assume an IAM role to write logs.

    Why it's wrong here

    Assuming an IAM role is not a prerequisite for using this policy; the policy can be attached directly to an IAM user, a group, or an EC2 instance profile. The application only needs valid credentials from the entity to which the policy is attached, and those credentials can come directly from an IAM user or a role assumed by an instance. The actual issue remains the incorrectly formatted resource ARN for the CloudWatch Logs actions.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.