Courseiva

SOA-C02 Practice Question: CloudWatch Logs Insights for querying structured…

Multiple microservices each write structured JSON logs to separate CloudWatch log groups. The operations team needs to find all ERROR-level log entries across all log groups for the past 24 hours and count errors by service name. Which approach achieves this with the least operational overhead?

⚠ Common exam trap

The trap here is that candidates may overcomplicate the solution by assuming cross-log-group analysis requires data aggregation pipelines (like Kinesis or S3/Athena), when CloudWatch Logs Insights natively supports querying multiple log groups with a single query, making it the simplest and most cost-effective option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a CloudWatch Logs Insights query selecting all relevant log groups, filter where level = 'ERROR', and use stats count(*) by service

CloudWatch Logs Insights natively supports querying multiple log groups in a single query. By specifying all relevant log groups in the query scope, filtering for `level = 'ERROR'` using the `filter` command, and using `stats count(*) by service`, the operations team can directly aggregate error counts per service without any data movement, additional infrastructure, or manual scripting. This approach has the least operational overhead because it leverages existing CloudWatch capabilities with no setup or maintenance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run a CloudWatch Logs Insights query selecting all relevant log groups, filter where level = 'ERROR', and use stats count(*) by service

    Why this is correct

    Logs Insights accepts a comma-separated list of log group names (or a log group name prefix pattern) in the query scope. The filter and stats commands work across all selected groups in a single query execution. No additional pipeline or aggregation layer is needed.

  • ✗

    Export each log group to S3 and run an Athena query joining all exported files

    Why it's wrong here

    Exporting to S3 is an asynchronous operation (hours for large log groups) and requires setting up Glue tables or Athena schema definitions before querying. For an ad-hoc 24-hour investigation, this approach has far more setup overhead than Logs Insights.

  • ✗

    Subscribe all log groups to a Kinesis Data Firehose stream and query the aggregated data in OpenSearch

    Why it's wrong here

    A Kinesis + OpenSearch pipeline is a persistent, always-on log aggregation architecture appropriate for long-term search and dashboarding. For a one-off cross-service query, it requires provisioning and configuring significant infrastructure before any query can be run.

  • ✗

    Use the AWS CLI to download and grep log events from each log group separately, then sum the results

    Why it's wrong here

    Using the AWS CLI (e.g., `aws logs filter-log-events` or `get-log-events`) to retrieve log events for a 24-hour window across many log groups requires handling pagination tokens for each group, downloading every matching event over the network, and then writing custom scripts to parse and aggregate error counts locally. This approach is slow, bandwidth-intensive, and error-prone, especially when log volumes are high, because there is no server-side aggregation and the CLI returns raw events. In contrast, CloudWatch Logs Insights executes the filter and `stats count(*) by service` aggregation directly in the CloudWatch Logs service, returning only the final aggregated result so no bulk data transfer or client-side processing is needed.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.