SOA-C02 Monitoring, Logging, and Remediation Practice Question
Exhibit
Refer to the exhibit. CloudWatch Logs Insights query: fields @timestamp, @message | filter @message like /ERROR|FATAL/ | stats count() by bin(5m) | sort @timestamp desc
Refer to the exhibit. A SysOps administrator runs the CloudWatch Logs Insights query shown. What does this query do?
⚠ Common exam trap
The trap here is that candidates see `ERROR|FATAL` and `sort @timestamp desc` and assume the query returns raw log messages in reverse chronological order, overlooking that `stats count(*)` aggregates the data into counts per time bucket.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Counts the number of ERROR and FATAL log entries per 5-minute interval and displays them in descending order by time.
The CloudWatch Logs Insights query uses `stats count(*) by bin(5m)` to aggregate log events into 5-minute time buckets, then filters with `filter @message like /ERROR|FATAL/` to include only those severity levels. The `sort @timestamp desc` orders the resulting time buckets in descending chronological order, producing a count of ERROR and FATAL entries per 5-minute interval. This matches option B exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Groups ERROR and FATAL entries by log stream name.
Why it's wrong here
The CloudWatch Logs Insights query shown filters on log entries containing ERROR or FATAL but the aggregation is performed on time bins, not on log streams. Grouping by log stream would require a group-by clause such as 'stats count() by bin(5m), @logStream' in the query. Since no such dimension is referenced, the query output cannot display results organized by log stream name. This option incorrectly attributes a grouping dimension that is absent from the query syntax.
- ✓
Counts the number of ERROR and FATAL log entries per 5-minute interval and displays them in descending order by time.
Why this is correct
This is the correct interpretation because the query uses the aggregation function 'stats count() by bin(5m)' which counts all matching ERROR/FATAL events within each 5-minute window, then applies 'sort @timestamp desc' to order the resulting time buckets from the most recent to the oldest. The combined pipeline first filters entries using a pattern match, then aggregates counts over fixed time intervals, and finally sorts the aggregated rows by the timestamp field in descending order. Therefore the output is a time series of error/fatal counts per five-minute bucket, not raw messages or stream-level groupings.
- ✗
Displays the full log messages of all ERROR and FATAL entries.
Why it's wrong here
The query aggregates log data with a count metric, so it does not return individual log message contents. To display the full messages, one would need to use 'fields @message' or include '@message' in the output, not apply a 'count()' aggregation. Because 'stats count()' collapses all matching events per time bucket into a numeric total, the original message text is discarded during the aggregation. Thus this option misinterprets an aggregation query as a retrieval query that shows raw log lines.
- ✗
Deletes all log entries containing ERROR or FATAL older than 5 minutes.
Why it's wrong here
CloudWatch Logs Insights is a query engine that only reads and analyzes existing log data; it has no ability to delete, modify, or alter log events in any way. Deletion of log data is handled by log group retention settings, the 'DeleteLogGroup' API, or the 'DeleteLogData' operation, none of which are triggered by an Insights query. Additionally, the query itself only performs a statistical count and sort, and it contains no action that could affect the stored log entries. Therefore, this option describes an operation completely outside the capabilities of the service and the query.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.