Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

Which TWO actions should a SysOps administrator take to set up centralized logging from multiple Amazon EC2 instances running Amazon Linux 2 to Amazon CloudWatch Logs?

⚠ Common exam trap

Candidates often confuse the unified CloudWatch agent with the older CloudWatch Logs agent or think that a VPC endpoint is required for any logging setup, when in fact the two mandatory actions are attaching an IAM role with the correct permissions and installing/configuring the unified CloudWatch agent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM role to each EC2 instance that includes permission for logs:PutLogEvents.

The EC2 instances need an IAM role with the logs:PutLogEvents permission to authenticate and authorize log delivery to CloudWatch Logs. Without this permission, the CloudWatch agent cannot send log data to the log stream, resulting in authorization failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attach an IAM role to each EC2 instance that includes permission for logs:PutLogEvents.

    Why this is correct

    Attaching an instance profile IAM role with logs:PutLogEvents is essential because the CloudWatch agent requires AWS credentials to authenticate and authorize its log writes; without this role, the agent will fail CloudWatch Logs API calls such as CreateLogStream and PutLogEvents. The role is scoped to the EC2 instance via the instance profile, eliminating the need to embed static keys in the AMI or on the instance. This is the foundational security prerequisite for any log collection, and it should also include permissions for DescribeLogStreams and CreateLogGroup if you want the agent to manage those resources automatically.

  • ✗

    Create an S3 bucket and configure the EC2 instances to write logs directly to the bucket.

    Why it's wrong here

    Writing logs directly to an S3 bucket from EC2 instances is a common misstep because S3 is an object store and not a native destination for CloudWatch Logs; there is no agent that can copy files into S3 without custom code, and even if you upload objects, CloudWatch Logs will not ingest them. You would need an additional pipeline like Lambda triggers or S3 event notifications to transform and forward the data into a log group, which defeats the purpose of a simple centralized logging setup. Moreover, you would lose real-time features such as metric filters, subscription filters, and CloudWatch Logs Insights, making the data far less useful for operations.

  • ✓

    Install and configure the unified CloudWatch agent on each EC2 instance.

    Why this is correct

    The unified CloudWatch agent is the required client-side component for collecting logs from an EC2 instance; it reads from local log files, handles log rotation and multi-line patterns, and sends the data to CloudWatch Logs using the permissions provided by the IAM role. You must install it on each instance and configure it via a JSON configuration file (or via AWS Systems Manager Run Command) that specifies which log files to collect, the destination log group, and the retention policy. Without this agent, there is no mechanism that automatically forwards OS or application logs, so this is one of the two essential actions.

  • ✗

    Create a VPC endpoint for CloudWatch Logs to allow private connectivity.

    Why it's wrong here

    A VPC endpoint for CloudWatch Logs is an optional networking enhancement that keeps traffic between your EC2 instances and the CloudWatch Logs service within the AWS network, which is useful in private VPCs with no internet gateway or NAT gateway. However, it is not a required action for setting up centralized logging; the outbound connection will still operate without a VPC endpoint if the instance has normal internet access, and the agent and IAM role are the true prerequisites. The question asks which two actions are required, and while a VPC endpoint might be part of a hardened architecture, it is not universally necessary.

  • ✗

    Export the logs from CloudWatch Logs to an Amazon S3 bucket for long-term retention.

    Why it's wrong here

    Exporting logs from CloudWatch Logs to an S3 bucket for long-term retention is a downstream archival operation, not a setup step for collecting logs from EC2; it is performed after logs have already been ingested and are present in a log group. This action is usually triggered via the CloudWatch Logs console, a CLI command, or a scheduled Lambda function to create a CreateExportTask, and it is meant for compliance or storage cost optimization, not for enabling the logging pipeline itself. Since this task depends on logs already reaching CloudWatch, it cannot be one of the initial two actions.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.