Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

Network Topology
$ aws cloudwatch describe-alarmsalarm-names HighCPUAlarmRefer to the exhibit.```"MetricAlarms": ["AlarmName": "HighCPUAlarm","AlarmArn": "arn:aws:cloudwatch:us-east-1:123456789012:alarm:HighCPUAlarm","AlarmConfigurationUpdatedTimestamp": "2023-01-15T10:00:00.000Z","StateValue": "ALARM","MetricName": "CPUUtilization","Namespace": "AWS/EC2","Statistic": "Average","Period": 300,"EvaluationPeriods": 1,"Threshold": 80.0,"ComparisonOperator": "GreaterThanOrEqualToThreshold","ActionsEnabled": true,"OKActions": [],"AlarmActions": ["arn:aws:sns:us-east-1:123456789012:NotifyMe"],"InsufficientDataActions": []

Refer to the exhibit. A SysOps administrator reviews the CloudWatch alarm configuration. The alarm is in ALARM state. Which statement accurately describes the alarm's behavior?

⚠ Common exam trap

Many candidates assume 'Datapoints to alarm' implies multiple consecutive breaches (like 3 out of 3) without reading the actual values, or they confuse the alarm's evaluation period with the notification frequency, leading them to pick Option A or D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The alarm triggered because the average CPU utilization over 5 minutes exceeded 80% for one consecutive period.

The alarm configuration shows 'Period: 5 minutes' and 'Statistic: Average' with 'Threshold: 80%' and 'Datapoints to alarm: 1 out of 1'. This means the alarm evaluates the average CPU utilization over a single 5-minute period, and if that average exceeds 80%, the alarm transitions to ALARM state immediately after one period's data point is available.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The alarm evaluates CPU utilization every 5 minutes and requires 3 consecutive breaches to trigger.

    Why it's wrong here

    The alarm's period is indeed set to 5 minutes, but the configuration specifies EvaluationPeriods: 1, meaning only a single evaluation is needed to transition to ALARM state. Requiring three consecutive breaches would require EvaluationPeriods: 3 (and possibly DatapointsToAlarm: 3), which is not the case here. Thus, the statement incorrectly describes the alarm's breach logic.

  • ✗

    The alarm will automatically resolve when CPU utilization drops below 80% for one period.

    Why it's wrong here

    The alarm will transition to OK when the metric is below threshold for the specified number of periods (1). This is true, but the statement says 'automatically resolve', which is misleading but not incorrect. However, the statement is not the best description of the alarm's behavior.

  • ✓

    The alarm triggered because the average CPU utilization over 5 minutes exceeded 80% for one consecutive period.

    Why this is correct

    Because the alarm is configured with metric CPUUtilization, statistic Average, Period 5 minutes, and EvaluationPeriods 1, the metric value is the mean CPU utilization over the most recent 5-minute interval. When that average exceeds the 80% threshold for a single period, the alarm immediately enters ALARM state. This precisely matches the exhibit's configuration, so the alarm triggered exactly for this reason.

  • ✗

    The alarm sends a notification to the SNS topic every 5 minutes while in ALARM state.

    Why it's wrong here

    CloudWatch alarms send notifications to an SNS topic only when the alarm state changes—for example, from OK to ALARM or from ALARM back to OK—not continuously while the alarm state remains ALARM. If the alarm stays in ALARM across multiple evaluation periods, no additional SNS messages are emitted unless the state changes again. Therefore, the claim that a notification fires every 5 minutes during ALARM state is incorrect.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.