Skip to content
BytePatterns

SOA-C03 · Domain 1: Monitoring, Logging, Analysis, Remediation, and Performance Optimization · 22% of the exam

Task 1.2: Identify and remediate issues by using monitoring and availability metrics.

Turning a signal into a fix: reading metrics to find the cause, EventBridge rules that route and reshape events, and remediation that runs by itself through Lambda and Systems Manager Automation runbooks.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An engineer used the AWS CLI to create an Amazon EventBridge rule on the default event bus and to add an AWS Lambda function as its target. The rule's MatchedEvents metric rises as expected, but the function's logs and metrics show that it is never invoked. What is the most likely fix?

  1. ARaise the function's timeout to the maximum of 15 minutes so that the invocations can complete
  2. BAdd a statement to the function's resource-based policy that allows EventBridge to invoke it
  3. CAdd the events:PutEvents permission to the function's execution role
  4. DCreate an archive on the event bus and replay the events from it
Show the answer and why
  • ARaise the function's timeout to the maximum of 15 minutes so that the invocations can complete

    Incorrect

    The timeout limits how long a running invocation may take. A function that is never invoked is not timing out.

  • BAdd a statement to the function's resource-based policy that allows EventBridge to invoke it

    Correct

    Without permission, EventBridge cannot invoke the target. The troubleshooting guide's first check for this symptom is the function's policy (aws lambda get-policy).

  • CAdd the events:PutEvents permission to the function's execution role

    Incorrect

    The execution role grants the function permission to call other services. It does not let EventBridge call the function.

  • DCreate an archive on the event bus and replay the events from it

    Incorrect

    A replay sends the archived events to the bus again, and the rule would fail to invoke the function for the same reason.

The EventBridge console sets the target's permissions for you; from the CLI the engineer adds them, for example with aws lambda add-permission for the events.amazonaws.com principal. A rule that matches but never reaches its function points first at that permission.

Question 2 · choose 1

An operations engineer wrote a custom AWS Systems Manager Automation runbook that updates a configuration file and restarts a service. It must run on about 300 running Amazon EC2 instances that carry the tag Env=prod. No more than 15 instances may be changed at the same time, and the rollout must stop sending the runbook to more instances when the fourth instance fails. How should the engineer run the runbook?

  1. ADeploy it with an AWS CloudFormation StackSet whose maximum concurrent accounts is set to 15
  2. BBake the change into a new AMI with an EC2 Image Builder pipeline
  3. CRun it with targets set to the tag Env=prod, a concurrency of 15 and an error threshold of 3
  4. DAdd it as the remediation action of an AWS Config conformance pack in the account
Show the answer and why
  • ADeploy it with an AWS CloudFormation StackSet whose maximum concurrent accounts is set to 15

    Incorrect

    StackSet operation preferences control how many accounts receive a stack at once. They do not run a runbook on instances.

  • BBake the change into a new AMI with an EC2 Image Builder pipeline

    Incorrect

    Image Builder creates new images; the running instances would not change until they were replaced.

  • CRun it with targets set to the tag Env=prod, a concurrency of 15 and an error threshold of 3

    Correct

    Automation rate controls limit how many targets run at once and stop the rollout after the error threshold is passed: with 3, it stops at the fourth error.

  • DAdd it as the remediation action of an AWS Config conformance pack in the account

    Incorrect

    A conformance pack bundles Config rules and remediation for noncompliant resources. It does not offer a controlled one-time rollout across tagged instances.

Targeting by tag creates one child automation per instance, and rate controls (concurrency and error threshold) pace the rollout and halt it when too many fail.

Question 3 · choose 1

An Amazon EventBridge rule matches EC2 Instance State-change Notification events and sends them to an Amazon SNS topic that emails the operations team. The team receives the full event JSON and wants a one-line message instead, such as "Instance i-0abc is now stopped". What should the team configure?

  1. AAdd the instance-id and state fields to the rule's event pattern
  2. BCreate an archive for the event bus with the same event pattern
  3. CAdd a subscription filter policy to the email subscription of the SNS topic
  4. DConfigure an input transformer with an input template on the rule's target
Show the answer and why
  • AAdd the instance-id and state fields to the rule's event pattern

    Incorrect

    The event pattern decides which events match the rule. It does not change the content that is sent to the target.

  • BCreate an archive for the event bus with the same event pattern

    Incorrect

    An archive stores events so that they can be replayed later. It does not reformat what the target receives.

  • CAdd a subscription filter policy to the email subscription of the SNS topic

    Incorrect

    A filter policy chooses which messages a subscriber receives, not how the message text looks.

  • DConfigure an input transformer with an input template on the rule's target

    Correct

    The input transformer reads values from the event with JSON paths and builds the text that EventBridge sends to the target instead of the original event.

Event patterns select, archives keep, filter policies route; only the input transformer rewrites the event before it reaches the target.

Question 4 · choose 2

A team created an Amazon EventBridge rule that should start remediation when an Amazon EC2 instance stops. Instances in the same account and Region stop several times a day, but the rule's MatchedEvents metric stays at zero. Which issues could explain this? (Choose TWO.)

  1. AThe rule has no IAM role that allows EventBridge to read EC2 events
  2. BThe pattern lists the state as an array, "state": ["stopped"]
  3. CThe pattern specifies "source": ["ec2"]
  4. DThe rule's target has no dead-letter queue configured
  5. EThe rule was created on an event bus that the team created, not on the default event bus
Show the answer and why
  • AThe rule has no IAM role that allows EventBridge to read EC2 events

    Incorrect

    EventBridge needs permissions to call a rule's targets. The default event bus receives events from AWS services automatically, so no role is involved in matching them.

  • BThe pattern lists the state as an array, "state": ["stopped"]

    Incorrect

    Values in an event pattern are written as arrays; ["stopped"] is the correct form.

  • CThe pattern specifies "source": ["ec2"]

    Correct

    EC2 events carry the source aws.ec2. A pattern that asks for ec2 never matches them.

  • DThe rule's target has no dead-letter queue configured

    Incorrect

    A dead-letter queue keeps events that failed to reach a target. It plays no part in whether an event matches the rule.

  • EThe rule was created on an event bus that the team created, not on the default event bus

    Correct

    AWS services send their events to the default event bus. A rule on another bus never sees EC2 state-change events.

A rule that never matches has a pattern or a bus problem. Compare the pattern with a real event (source aws.ec2, detail-type EC2 Instance State-change Notification) and make sure the rule sits on the default bus.

Question 5 · choose 1

The request count on an Application Load Balancer follows a strong daily pattern: about 200 requests a minute at night and about 9,000 at midday. A sudden drop in traffic usually means a broken client release. Alarms with a fixed threshold either miss night-time drops or fire every afternoon. The team wants an alarm that fires when traffic is unusually high or low for that time of day. What should the team do?

  1. ACreate an alarm that uses a CloudWatch anomaly detection model of the metric and fires outside the band
  2. BRaise the number of datapoints to alarm on the fixed-threshold alarm so that brief breaches are ignored
  3. CCreate a composite alarm from one high-threshold alarm and one low-threshold alarm
  4. DTurn on CloudTrail Insights events to detect unusual activity in the account
Show the answer and why
  • ACreate an alarm that uses a CloudWatch anomaly detection model of the metric and fires outside the band

    Correct

    Anomaly detection learns the metric's hourly, daily and weekly patterns and alarms when the value leaves the band of expected values, above it, below it or both.

  • BRaise the number of datapoints to alarm on the fixed-threshold alarm so that brief breaches are ignored

    Incorrect

    Datapoints to alarm only sets how many recent data points must breach. The threshold itself still ignores the time of day.

  • CCreate a composite alarm from one high-threshold alarm and one low-threshold alarm

    Incorrect

    A composite alarm combines alarm states, but both underlying alarms still use fixed thresholds that do not follow the daily pattern.

  • DTurn on CloudTrail Insights events to detect unusual activity in the account

    Incorrect

    CloudTrail Insights looks at the rate of AWS API calls and API errors, not at the traffic an application receives.

A metric with seasonality needs a threshold that moves with it. An anomaly detection alarm compares each value with the model's expected range for that moment.

Practise domain 1 →Practise all domains →