Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

Network Topology
$ aws cloudtrail lookup-eventslookup-attributes AttributeKey=EventNamestart-time 2023-01-01T00:00:00Zend-time 2023-01-31T23:59:59Zregion us-east-1Refer to the exhibit."Events": []

Refer to the exhibit. A SysOps administrator runs the command to find 'CreateKeyPair' events in January 2023 but gets an empty list. The administrator knows that key pairs were created during that time. What is the most likely reason?

⚠ Common exam trap

Many exam-takers assume CloudTrail events are globally visible by default, but in reality, `lookup-events` is region-scoped unless the `--region` parameter is explicitly set to the correct region.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The events occurred in a different AWS region.

The `aws cloudtrail lookup-events` command returns events only from the region specified in the AWS CLI configuration (or the `--region` parameter). If the administrator did not specify a region, the command defaults to the region set in the CLI profile. Since `CreateKeyPair` events are regional (each key pair is created in a specific region), the empty result indicates the events occurred in a different AWS region than the one queried.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The events occurred in a different AWS region.

    Why this is correct

    The `lookup-events` API call is regional in scope. When you issue `aws cloudtrail lookup-events --region us-east-1`, CloudTrail searches only the event history for that specific region. If the trail was configured as a single-region trail in a different region (or the events themselves were generated in another region), the lookup in us-east-1 will return zero results, even though the events exist in CloudTrail's global event history. To find them, you must explicitly specify the region where the trail is logging or where the events occurred.

  • ✗

    The start and end times are outside the 90-day retention period.

    Why it's wrong here

    CloudTrail's LookupEvents API only supports querying events from the trailing 90 days. The start and end times in the command were within 90 days of the run date, so the retention period is not the cause. If the dates were older than 90 days, the API would still succeed but return an empty result set—yet that scenario does not apply here. Since the dates are valid, this explanation cannot account for the missing events.

  • ✗

    CloudTrail is not enabled in the account.

    Why it's wrong here

    CloudTrail is enabled by default in every AWS account via the built-in event history, which captures the last 90 days of management events. Even if no trail has been created, the `lookup-events` API can still retrieve those management events from the event history. Therefore, saying 'CloudTrail is not enabled' is incorrect—the event history is always on, and a trail is only needed for longer retention or multi-region aggregation. The empty result must be due to a regional mismatch, not a lack of CloudTrail enablement.

  • ✗

    The IAM user does not have 'cloudtrail:LookupEvents' permission.

    Why it's wrong here

    If the IAM user lacked `cloudtrail:LookupEvents` permission, the AWS CLI command would fail with an `AccessDeniedException` and return a non-empty error message. The fact that the command executed successfully and returned an empty list proves that the user has the required permissions. IAM authorization failures are definitive and do not silently produce empty output. Thus, a missing permission cannot explain the empty result.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.