Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

Network Topology
aws cloudtrail lookup-eventslookup-attributes AttributeKey=EventNamestart-time 2023-06-01T00:00:00Zend-time 2023-06-01T23:59:59ZRefer to the exhibit.Output:"Events": []

Refer to the exhibit. The command returns no events for RunInstances during the specified time period. The administrator knows that instances were launched during that time. What is the most likely cause?

⚠ Common exam trap

It's easy for candidates to assume CloudTrail always logs all API calls by default, but they overlook that CloudTrail can be configured to exclude management events, and the `lookup-events` command only returns events that CloudTrail is actually recording.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudTrail is not configured to log management events.

CloudTrail can be configured to log either management events, data events, or both. If only data events are logged, management events such as RunInstances will not appear in the CloudTrail event history. The command `aws cloudtrail lookup-events` queries the CloudTrail event history, which only contains events that CloudTrail is configured to record. Since the administrator knows instances were launched but no events are returned, the most likely cause is that CloudTrail is not configured to log management events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CloudTrail logs are being delivered to an S3 bucket, not to CloudWatch Logs.

    Why it's wrong here

    CloudTrail lookup-events queries the CloudTrail event history, which is a regional, API-accessible record of account activity retained for 90 days regardless of where the actual log files are delivered. The S3 bucket is merely the destination for the trail's archived log files, not the data source for the lookup API. Therefore, even if logs are going to an S3 bucket (or to CloudWatch Logs), the lookup command would still retrieve matching events from the event history, so this option does not explain an empty result.

  • ✗

    The command is run in the wrong AWS Region.

    Why it's wrong here

    CloudTrail events are region-specific: a RunInstances event is recorded only in the region where the EC2 instance was launched. If the AWS CLI or SDK region configuration is set to a different region than the one in which the instance launch occurred, the lookup request would scan a regional event history that contains no RunInstances entries. However, the question implies the administrator is investigating the correct region, so the empty output is not caused by a region mismatch.

  • ✓

    CloudTrail is not configured to log management events.

    Why this is correct

    CloudTrail's lookup-events API returns events from the event history that have been captured by an active trail with management-event logging enabled. RunInstances is a management event (EC2 instance creation), so if the trail is configured to log only data events (e.g., S3 object-level operations) or if management-event logging is disabled, the event history will not contain this API call. Consequently, the lookup command executes successfully but returns zero matches for RunInstances.

  • ✗

    The IAM user does not have permission to view CloudTrail events.

    Why it's wrong here

    If the IAM user lacked the cloudtrail:LookupEvents permission, the AWS API would return an AccessDeniedException with an HTTP 403 status instead of an empty result set. An empty JSON array indicates the API request was authenticated and authorized, and the filtering completed with no events matching the specified LookupAttribute. Thus, insufficient permissions would manifest as a distinct error, not as a valid empty response.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.