Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

Exhibit

Refer to the exhibit.

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "cloudwatch:PutMetricData",
            "Resource": "*",
            "Condition": {
                "StringEquals": {
                    "cloudwatch:namespace": "MyApp"
                }
            }
        }
    ]
}

Refer to the exhibit. An application running on EC2 is using the AWS SDK to publish custom metrics to CloudWatch. The application fails to publish metrics. The IAM role attached to the EC2 instance has this policy. What is the issue?

⚠ Common exam trap

Candidates often assume a policy with a condition key is always correct, overlooking that the application's actual namespace value must exactly match the condition value for the API call to succeed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application may be using a different namespace than 'MyApp'.

The IAM policy explicitly allows 'cloudwatch:PutMetricData' on the condition that the namespace is 'MyApp'. If the application's AWS SDK code publishes metrics under a different namespace (e.g., 'AWS/EC2' or a custom namespace like 'MyOtherApp'), the condition fails and the API call is denied. This is the most likely cause of the failure, as the policy is otherwise correctly configured for the specified namespace.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The condition key 'cloudwatch:namespace' is misspelled.

    Why it's wrong here

    The condition key \'cloudwatch:namespace\' is spelled correctly; CloudWatch and IAM both recognize it as a valid condition key specifically designed to restrict PutMetricData to a particular namespace. A misspelled key would cause the policy to fail validation or would simply not be evaluated, but since the key is properly formed, the problem must be the value being compared. The application is likely sending a different namespace than the literal string \'MyApp\', causing the StringEquals condition to evaluate to false and deny the request.

  • ✗

    The policy does not specify a specific resource ARN.

    Why it's wrong here

    The PutMetricData API action does not support resource-level permissions in IAM, meaning you cannot specify an ARN such as \'arn:aws:cloudwatch:region:account-id:namespace/MyApp\' because the action operates on the CloudWatch service itself, not on a specific resource. The wildcard \'*\' is the only allowed resource for this action, and using a more specific ARN would actually make the policy invalid or ineffective. Therefore, the absence of a specific resource ARN is not the cause of the failure; the condition key mismatch is the real issue.

  • ✓

    The application may be using a different namespace than 'MyApp'.

    Why this is correct

    This is the correct answer because the IAM policy uses a condition key `cloudwatch:namespace` with the `StringEquals` operator, which requires an exact match. If the application's code calls PutMetricData with any namespace other than \'MyApp\' — for example, a custom namespace like \'MyApplication\' or \'Company/Metrics\' — the condition fails, and the action is denied even though the policy statement otherwise allows it. CloudWatch namespaces are case-sensitive, so a mismatch in capitalization would also cause a denial, and the application may not be specifying the namespace as expected.

  • ✗

    The action 'cloudwatch:PutMetricData' is not allowed for custom metrics.

    Why it's wrong here

    PutMetricData is the primary API action for publishing custom metrics to CloudWatch and is fully supported for custom namespaces. IAM policies can grant this action explicitly, as shown in the policy, and CloudWatch does not impose restrictions that would block PutMetricData for custom metrics; in fact, custom metrics are the main use case for this action. If the action were not allowed, the error would be an "AccessDenied" due to missing permissions, not a condition key failure, so this option does not explain the problem.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.