CloudWatch agent fails to publish logs because the IAM policy grants cloudwatch: instead of logs:

Answer Correct answer: C — the instance role needs logs: API actions, not cloudwatch:, because CloudWatch Logs is a separate IAM namespace from CloudWatch Metrics.

An Amazon EC2 Auto Scaling group launches Amazon Linux EC2 instances and installs the Amazon CloudWatch agent to publish logs to Amazon CloudWatch Logs. The EC2 instances launch with an IAM role that has an IAM policy attached. The policy provides access to publish custom metrics to CloudWatch. The EC2 instances run in a private subnet inside a VPC The VPC provides access to the internet for private subnets through a NAT gateway. A security engineer notices that no logs are being published to CloudWatch Logs for the EC2 instances that the Auto Scaling group launches. The security engineer validates that the CloudWatch Logs agent is running and is configured properly on the EC2 instances. In addition, the security engineer validates that network communications are working properly to AWS services. What can the security engineer do to ensure that the logs are published to CloudWatch Logs?

  1. Configure the IAM policy in use by the IAM role to have access to the required cloudwatch: API actions that will publish logs.
  2. Adjust the Amazon EC2 Auto Scaling service-linked role to have permissions to write to CloudWatch Logs.
  3. Configure the IAM policy in use by the IAM role to have access to the required AWS logs: API actions that will publish logs. Correct Answer
  4. Add an interface VPC endpoint to provide a route to CloudWatch Logs.

Community Votes

A
52%
C
48%

52% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

CloudWatch Metrics and CloudWatch Logs are separate AWS services with separate IAM namespaces. The metrics namespace is cloudwatch: (e.g., PutMetricData) while the Logs namespace is logs: (e.g., CreateLogGroup, CreateLogStream, PutLogEvents). Granting cloudwatch: does not enable log publishing.

An EC2 Auto Scaling group launches Amazon Linux instances that run the CloudWatch agent to ship logs to CloudWatch Logs. The agent runs and networking is healthy, but no logs arrive. The attached instance role already has cloudwatch: permissions for custom metrics, yet those permissions belong to the CloudWatch Metrics namespace and do not cover the CloudWatch Logs API.

Choosing the option that adds cloudwatch: API actions, because the question mentions the existing policy already covers custom metrics. The agent's log pipeline actually calls the logs: API, so the missing permission is in the logs: namespace, not cloudwatch:.

Community Discussion (18 comments)

phmeeeee 👍 1 Selected: C
I vote for C cuz cloudwatch api is for METRIC not the logs. The qestion is asking to solveing that can't put the logs. So to verify logs api is my answer. https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/create-iam-roles-for-cloudwatch-agent.html
fcbflo 👍 2 Selected: C
Option A is incorrect because it specifies "cloudwatch:" API actions, but CloudWatch Logs uses a different set of API permissions. The CloudWatch service (for metrics) and CloudWatch Logs service use different API namespaces: CloudWatch metrics use the "cloudwatch:" API namespace CloudWatch Logs use the "logs:" API namespace The problem states that the IAM policy already provides access to publish custom metrics to CloudWatch (which uses the cloudwatch: namespace), but logs aren't being published to CloudWatch Logs. This indicates that the permissions for the logs: namespace are missing. Therefore, option C (configuring the IAM policy to include the required logs: API actions) is the correct solution, not option A.
AWSLoverLoverLoverLoverLover 👍 2 Selected: A
A. Configure the IAM policy in use by the IAM role to have access to the required cloudwatch: API actions that will publish logs. (Most Voted) Explanation: IAM Permissions Issue: Since the CloudWatch agent is running properly, the issue is likely related to insufficient IAM permissions for the EC2 instances' IAM role. Correct CloudWatch API Actions B. Adjust the Auto Scaling service-linked role ❌ → The Auto Scaling service-linked role does not affect CloudWatch Logs; it is only needed for managing EC2 instances. C. Configure the IAM policy for AWS logs: API actions ❌ → AWS Logs is not a valid service namespace; the CloudWatch agent requires logs: and cloudwatch: API actions. D. Add a VPC Endpoint ❌ → The question states that network communications are working fine via the NAT gateway, so connectivity to CloudWatch is not an issue.
IPLogic 👍 1 Selected: C
To ensure that the logs are published to CloudWatch Logs, the security engineer should take the following steps: Configure the IAM policy in use by the IAM role to have access to the required AWS logs: API actions that will publish logs. This ensures that the IAM role has the necessary permissions to interact with CloudWatch Logs. Therefore, the correct answer is C. This approach ensures that the IAM role has the appropriate permissions to publish logs to CloudWatch Logs, resolving the issue of logs not being published.
ericxw 👍 1 Selected: C
"What API calls does the agent make (or what actions should I add to my IAM policy)?" https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/AgentReference.html#:~:text=What%20API%20calls%20does%20the%20agent%20make%20(or%20what%20actions%20should%20I%20add%20to%20my%20IAM%20policy)%3F
mzeynalli 👍 2 Selected: A
Option C: The correct actions to publish logs are under the cloudwatch: namespace, not aws logs:; hence this option is misleading and incorrect.
DSExam 👍 1 Selected: C
C is right, see below All CloudWatch Logs actions (logs:*)
pagom 👍 1 Selected: C
cloudwatch: API is different logs: API
div05jkjl 👍 1 Selected: C
C is correct
Lingo43 👍 2 Selected: C
The scenario describes that the CloudWatch agent is running, the network is working, and the IAM role already has permissions to publish custom metrics. This suggests that the issue lies in the IAM permissions related specifically to publishing logs. The CloudWatch Logs agent needs permissions to interact with the CloudWatch Logs service, which is governed by the logs: API actions.
xTrayusx 👍 1 Selected: C
C, it's logs:* actions
navid1365 👍 1 Selected: A
A is correct.
1923 👍 1
chatgpt saids "D"
aescudero51 👍 2 Selected: A
My answer is A https://docs.aws.amazon.com/aws-managed-policy/latest/reference/CloudWatchFullAccess.html
Certified101 👍 2 Selected: A
Must be A - it states that the networking is fine in this scenario.
Zek 👍 3
A The problem is with the ec2 instance not being able to publish logs from the cloudwatch agent running on the instance and not really to do with the autoscaling service role. The auto scaling service role will instead require the following Create, describe, modify, and delete CloudWatch alarms for scaling policies and retrieve metrics used for predictive scaling. https://docs.aws.amazon.com/autoscaling/ec2/userguide/autoscaling-service-linked-role.html#service-linked-role-permissions
danish1234 👍 3 Selected: A
A is the answer . have to check IAM roles used by ec2.
krishnavamshireddy 👍 1
Answer is D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The CloudWatch agent publishes log events to the CloudWatch Logs service, which exposes its API under the logs: namespace (CreateLogGroup, CreateLogStream, PutLogEvents, DescribeLogStreams). The instance role in the scenario already has cloudwatch: permissions for custom metrics, but those permissions do not authorize any Logs API call. Adding logs: actions to the role's policy restores log publishing without touching the network, because the security engineer already validated that connectivity and the agent configuration are fine.

Why the Other Options Are Wrong

A is wrong because cloudwatch: covers metrics only; it does not grant the Logs API actions the agent needs, so logs would still fail to publish. B is wrong because the Auto Scaling service-linked role governs scaling actions (alarms, predictive scaling), not the per-instance agent's log writes; the instances use their own instance role. D is wrong because a VPC interface endpoint is unnecessary here—the engineer confirmed network communications to AWS services work, and the root cause is IAM, not routing.

Community Comment Notes

Community discussion split A vs C. The decisive point, repeated by several commenters, is that "cloudwatch: API is for METRIC not the logs" and CloudWatch Logs uses logs:*. One commenter cited the AgentReference doc listing the exact logs: API calls the agent makes. A minority incorrectly insisted on A.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide