Question 1 · choose 1
An order API's request count follows a strong daily and weekly pattern: heavy during business hours, low at night and at weekends. A static CloudWatch alarm on low request counts fires every night, and a static alarm on high counts misses daytime drops that still sit above the night-time level. The team wants one alarm that fires when the request count leaves its normal range for that time of day or week, in either direction, without hand-tuned thresholds. What should the DevOps engineer configure?
- AA composite alarm that combines the existing low-count and high-count alarms with an OR rule
- BA metric math expression that averages the request count over the last 24 hours, with a static alarm on the result of that expression
- CAn anomaly detection alarm on the request count metric that fires when the value is outside the band in either direction
- DTwo scheduled EventBridge Scheduler jobs that change the static alarm threshold at 08:00 and 20:00 on weekdays
Show the answer and why
AA composite alarm that combines the existing low-count and high-count alarms with an OR rule
Incorrect
A composite alarm combines the states of other alarms. The underlying static thresholds still ignore the time of day.
BA metric math expression that averages the request count over the last 24 hours, with a static alarm on the result of that expression
Incorrect
A 24-hour average flattens the daily pattern and still needs a fixed threshold, so short drops during busy hours are hidden.
CAn anomaly detection alarm on the request count metric that fires when the value is outside the band in either direction
Correct
Anomaly detection models account for hourly, daily and weekly seasonality, and the alarm can fire above the band, below it, or both.
DTwo scheduled EventBridge Scheduler jobs that change the static alarm threshold at 08:00 and 20:00 on weekdays
Incorrect
Switching thresholds by schedule is the hand tuning the team wants to avoid, and it does not cover weekends or gradual changes.
Seasonal metrics need a moving baseline. A CloudWatch anomaly detection alarm compares each data point with the expected range from the model instead of a static threshold.
AWS documentation