Trigger instance cleanup from the Trusted Advisor cost optimization check via EventBridge
A company migrated to AWS and uses AWS Business Support. The company wants to monitor the cost-effectiveness of Amazon EC2 instances across AWS accounts. The EC2 instances have tags for department, business unit, and environment. Development EC2 instances have high cost but low utilization. The company needs to detect and stop any underutilized development EC2 instances. Instances are underutilized if they had 10% or less average daily CPU utilization and 5 MB or less network I/O for at least 4 of the past 14 days. Which solution will meet these requirements with the LEAST operational overhead?
Community Votes
80% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The Trusted Advisor low utilization EC2 instances check applies exactly the same thresholds as the question, so its findings can drive an EventBridge rule that invokes Lambda to filter by the tags and stop the instances, with no custom metric collection to build.
A company on AWS Business Support wants to stop underutilized development EC2 instances, defined as ten percent or less average daily CPU and five MB or less network I/O for at least four of the past fourteen days, and it must act on department, business unit, and environment tags.
Building the utilization detection from CloudWatch metrics and Systems Manager. That requires defining custom metric math for the multi-day CPU and network criteria, which is ongoing work that Trusted Advisor already performs as a managed check available at the Business Support level.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The AWS Trusted Advisor cost optimization check for low utilization Amazon EC2 instances reports instances with the same thresholds the question describes, at or below ten percent average daily CPU and five MB or less network I/O, and the company is on Business Support which includes these cost optimization checks. EventBridge can be configured to react to those findings and invoke a Lambda function that filters the results by the department, business unit, and environment tags, applies the development tag condition, and stops the qualifying instances. The detection logic therefore does not have to be written or maintained at all.Why the Other Options Are Wrong
A: CloudWatch dashboards are a visualization tool and do not evaluate the multi-day CPU and network criteria, and it does not define a rule that fires on utilization, so nothing would trigger the Lambda function. B: Systems Manager does not track utilization as a managed detection source, so the group would have to build and maintain the metric evaluation itself, which is more operational overhead than using a check that already computes it. D: A daily Lambda function writing to DynamoDB plus a QuickSight dashboard produces a report that people must read, but it does not stop anything automatically, and it is the highest overhead option of the four.Community Comment Notes
The community voted 80 to 20 for C. Several commenters linked the Trusted Advisor cost optimization checks documentation and observed that the criteria published there, ten percent or less average daily CPU and five MB or less network I/O over a multi-day window, are identical to the wording of the question, which is the strongest possible confirmation that the check is the intended source.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →