Trigger instance cleanup from the Trusted Advisor cost optimization check via EventBridge

Answer Correct answer: C — Create an EventBridge rule on the Trusted Advisor low utilization check that invokes Lambda to filter by tags and stop the instances.

A company migrated to AWS and uses AWS Business Support. The company wants to monitor the cost-effectiveness of Amazon EC2 instances across AWS accounts. The EC2 instances have tags for department, business unit, and environment. Development EC2 instances have high cost but low utilization. The company needs to detect and stop any underutilized development EC2 instances. Instances are underutilized if they had 10% or less average daily CPU utilization and 5 MB or less network I/O for at least 4 of the past 14 days. Which solution will meet these requirements with the LEAST operational overhead?

  1. Configure Amazon CloudWatch dashboards to monitor EC2 instance utilization based on tags for department, business unit, and environment. Create an Amazon EventBridge rule that invokes an AWS Lambda function to stop underutilized development EC2 instances.
  2. Configure AWS Systems Manager to track EC2 instance utilization and report underutilized instances to Amazon CloudWatch. Filter the CloudWatch data by tags for department, business unit, and environment. Create an Amazon EventBridge rule that invokes an AWS Lambda function to stop underutilized development EC2 instances.
  3. Create an Amazon EventBridge rule to detect low utilization of EC2 instances reported by AWS Trusted Advisor. Configure the rule to invoke an AWS Lambda function that filters the data by tags for department, business unit, and environment and stops underutilized development EC2 instances. Correct Answer
  4. Create an AWS Lambda function to run daily to retrieve utilization data for all EC2 instances. Save the data to an Amazon DynamoDB table. Create an Amazon QuickSight dashboard that uses the DynamoDB table as a data source to identify and stop underutilized development EC2 instances.

Community Votes

C
80%
A
20%

80% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The Trusted Advisor low utilization EC2 instances check applies exactly the same thresholds as the question, so its findings can drive an EventBridge rule that invokes Lambda to filter by the tags and stop the instances, with no custom metric collection to build.

A company on AWS Business Support wants to stop underutilized development EC2 instances, defined as ten percent or less average daily CPU and five MB or less network I/O for at least four of the past fourteen days, and it must act on department, business unit, and environment tags.

Building the utilization detection from CloudWatch metrics and Systems Manager. That requires defining custom metric math for the multi-day CPU and network criteria, which is ongoing work that Trusted Advisor already performs as a managed check available at the Business Support level.

Community Discussion (10 comments)

alexbraila 👍 1 Selected: C
Due to the link posted by Kinnam and sam2ng, together with this https://docs.aws.amazon.com/awssupport/latest/user/cloudwatch-events-ta.html
AzureDP900 👍 1
Option C, This solution meets the requirements with the least operational overhead because it uses Amazon EventBridge (formerly CloudWatch Events) to trigger a response based on low utilization reports from AWS Trusted Advisor. AWS Trusted Advisor provides pre-configured dashboards that can be used to monitor various aspects of your AWS resources, including EC2 instance utilization. By leveraging these pre-configured dashboards, you don't need to set up additional monitoring infrastructure or write custom code. The EventBridge rule will automatically invoke the Lambda function when a low utilization report is received from Trusted Advisor, which eliminates the need for daily polling or manual intervention. The other options are more resource-intensive and require additional setup and maintenance:
JoeTromundo 👍 2 Selected: C
AWS Trusted Advisor provides insights into underutilized EC2 instances automatically, including recommendations for cost-saving based on utilization metrics like CPU and network usage. Since the company is using AWS Business Support, they already have access to Trusted Advisor, making this a low-overhead solution. Amazon EventBridge can be used to create a rule that detects when Trusted Advisor reports low-utilization instances. This avoids the need for custom-built CloudWatch dashboards or manual tracking. AWS Lambda can be triggered to handle the logic of stopping instances that meet the specific criteria of low CPU utilization and network I/O, filtering by tags for department, business unit, and environment. Lambda is serverless and scales automatically, so it minimizes operational overhead.
Kinnam 👍 2 Selected: C
https://docs.aws.amazon.com/awssupport/latest/user/cost-optimization-checks.html#low-utilization-amazon-ec2-instances
sam2ng 👍 3 Selected: C
This is exactly the same criteria provided by the Trusted Advisor: https://docs.aws.amazon.com/awssupport/latest/user/cost-optimization-checks.html#low-utilization-amazon-ec2-instances
gfhbox0083 👍 2 Selected: C
C, for sure. TA for 10% or less average daily CPU utilization and 5 MB or less network I/O for at least 4 of the past 14 days. And least operational overhead
Moumita 👍 1 Selected: C
A - involves continuous monitoring and potential updates to dashboards and metrics. C - minimizes ongoing maintenance by relying on Trusted Advisor's automated reports.
asquared16 👍 1 Selected: C
A is not correct as it's missing setting up alarms for the "detect" part. I go with C.
vip2 👍 3 Selected: A
It would be A as correct answer Tagging with EC2 instances for department, business unit, and environment . CloudWatch to collect and monitor CPU utilization and network I/O metrics. Create CloudWatch Alarms to detect underutilized instances with composite alarmwith boh CPU utilization and network I/O are low. AWS Lambda Function to be triggered by the CloudWatch Alarms and check the conditions (10% or less average daily CPU utilization and 5 MB or less network I/O) hold true for at least 4 of the past 14 days. Stop the instances that meet these criteria.
paderni 👍 1
Not c because AWS Trusted Advisor does not provide real-time utilization metrics suitable for detecting underutilized instances over a specific timeframe. It focuses more on best practices and recommendations rather than real-time operational metrics. Should be B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The AWS Trusted Advisor cost optimization check for low utilization Amazon EC2 instances reports instances with the same thresholds the question describes, at or below ten percent average daily CPU and five MB or less network I/O, and the company is on Business Support which includes these cost optimization checks. EventBridge can be configured to react to those findings and invoke a Lambda function that filters the results by the department, business unit, and environment tags, applies the development tag condition, and stops the qualifying instances. The detection logic therefore does not have to be written or maintained at all.

Why the Other Options Are Wrong

A: CloudWatch dashboards are a visualization tool and do not evaluate the multi-day CPU and network criteria, and it does not define a rule that fires on utilization, so nothing would trigger the Lambda function. B: Systems Manager does not track utilization as a managed detection source, so the group would have to build and maintain the metric evaluation itself, which is more operational overhead than using a check that already computes it. D: A daily Lambda function writing to DynamoDB plus a QuickSight dashboard produces a report that people must read, but it does not stop anything automatically, and it is the highest overhead option of the four.

Community Comment Notes

The community voted 80 to 20 for C. Several commenters linked the Trusted Advisor cost optimization checks documentation and observed that the criteria published there, ten percent or less average daily CPU and five MB or less network I/O over a multi-day window, are identical to the wording of the question, which is the strongest possible confirmation that the check is the intended source.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide