AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company runs an application on Amazon EC2 Linux instances that are launched by an Auto Scaling group. Operations must collect Apache access logs and memory utilization from every instance, send the data to Amazon CloudWatch, and ensure that any update to the collection settings is applied automatically to new and running instances without storing credentials on the servers. Which solution meets these requirements with the LEAST operational overhead?
Bake the CloudWatch Logs agent and a cron-based script that runs the aws cloudwatch put-metric-data CLI command into the AMI, passing long-lived access keys to the instances with user data. Rebuild the AMI whenever the configuration changes.
Store a CloudWatch agent JSON configuration in Systems Manager Parameter Store. Attach an IAM instance profile that includes AmazonSSMManagedInstanceCore and CloudWatchAgentServerPolicy in the launch template. Use Systems Manager Run Command with AWS-ConfigureAWSPackage to install the CloudWatch agent and AmazonCloudWatch-ManageAgent to start it, so the agent automatically downloads the configuration and publishes Apache logs and memory metrics.
Turn on AWS CloudTrail management and data events for the account, enable CloudTrail Insights, and create a CloudWatch Logs subscription filter to capture Apache logs and memory metrics.
Enable detailed monitoring on the Auto Scaling group and write a shell script that copies Apache logs to an S3 bucket every five minutes; configure an S3 event to import the logs into CloudWatch Logs.
The unified CloudWatch agent can collect both system-level metrics such as memory utilization and application logs like Apache access logs. By storing the agent's JSON configuration centrally in AWS Systems Manager Parameter Store, any change to the configuration can be fetched when the agent starts or is refreshed, so new and existing Auto Scaling instances stay consistent without rebuilding AMIs. Installing the package with the AWS-ConfigureAWSPackage Run Command document and then starting or reloading it with the AmazonCloudWatch-ManageAgent document lets you push the latest configuration fleet-wide. An instance profile that includes AmazonSSMManagedInstanceCore and CloudWatchAgentServerPolicy supplies the necessary permissions, so no static credentials are stored on the servers.
The older CloudWatch Logs agent publishes only logs and would still require custom scripts for memory metrics and a manual update process. Copying logs to Amazon S3 and importing them into CloudWatch Logs does not solve in-guest memory monitoring and adds scripting overhead. Enabling CloudTrail and CloudTrail Insights records management and data-plane API events but cannot collect operating-system metrics or web-server log files. Therefore, the Systems Manager-based deployment of the CloudWatch agent is the lowest-maintenance approach.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the role of AWS Systems Manager Parameter Store in this solution?
Open an interactive chat with Bash
What permissions are provided by AmazonSSMManagedInstanceCore and CloudWatchAgentServerPolicy?
Open an interactive chat with Bash
Why is the unified CloudWatch agent preferred over the older CloudWatch Logs agent?
Open an interactive chat with Bash
What is the role of Systems Manager Parameter Store in this solution?
Open an interactive chat with Bash
Why is IAM instance profile important for this solution?
Open an interactive chat with Bash
What advantages does the unified CloudWatch agent have over the older CloudWatch Logs agent?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Monitoring, Logging, Analysis, Remediation, and Performance Optimization
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .