Forward logs with the CloudWatch agent to CloudWatch Logs and query with Logs Insights

Answer Correct answer: C, D — the CloudWatch agent forwards logs to CloudWatch Logs and Logs Insights queries them, surviving scale-in at lowest cost.

A company has decided to move its fleet of Linux-based web server instances to an Amazon EC2 Auto Scaling group. Currently, the instances are static and are launched manually. When an administrator needs to view log files, the administrator uses SSH to establish a connection to the instances and retrieves the logs manually. The company often needs to query the logs to produce results about application sessions and user issues. The company does not want its new automatically scaling architecture to result in the loss of any log files when instances are scaled in. Which combination of steps should a security engineer take to meet these requirements MOST cost-effectively? (Choose two.)

  1. Configure a cron job on the instances to forward the log files to Amazon S3 periodically.
  2. Configure AWS Glue and Amazon Athena to query the log files.
  3. Configure the Amazon CloudWatch agent on the instances to forward the logs to Amazon CloudWatch Logs. Correct Answer
  4. Configure Amazon CloudWatch Logs Insights to query the log files. Correct Answer
  5. Configure the instances to write the logs to an Amazon Elastic File System (Amazon EFS) volume.

Community Votes

CD
100%

100% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The CloudWatch agent streams logs off-instance to CloudWatch Logs before scale-in, so logs are retained; Logs Insights queries them directly, avoiding Athena/Glue (B) or an EFS volume (E). A cron-to-S3 (A) also survives scale-in but needs Athena for querying, adding cost/complexity versus Logs Insights.

Auto-scaled Linux web servers must not lose logs on scale-in, and logs must be queryable for sessions/user issues, cost-effectively. Install the CloudWatch agent on the instances to forward logs to CloudWatch Logs (surviving termination because logs are already shipped out), and use CloudWatch Logs Insights to query them—no Athena/Glue or shared filesystem needed.

Adding Glue+Athena (B) just to query logs—Logs Insights already queries CloudWatch Logs without that stack. Using EFS (E) as a shared log volume adds cost and is not the most cost-effective centralized approach. A works for retention but pairs poorly with querying versus C+D.

Community Discussion (5 comments)

nischal77777 👍 1 Selected: CD
My answer is C & D
aescudero51 👍 3 Selected: CD
My answer is C & D Configure the Amazon CloudWatch agent on the instances to forward the logs to Amazon CloudWatch Logs: This approach ensures that log files are automatically collected and stored in Amazon CloudWatch Logs, which can be queried using CloudWatch Logs Insights. This method is cost-effective because it leverages Amazon CloudWatch, which is included in the cost of running EC2 instances. Configure CloudWatch Logs Insights to query the log files: CloudWatch Logs Insights is a fully managed service that allows you to query and analyze log data in real-time. It is integrated with Amazon CloudWatch Logs, making it a natural choice for querying log files.
3a214ce 👍 3 Selected: CD
No need of Amazon Athena to query logs in CloudWatch Logs, rather use Amazon Logs CloudWatch Insights.
Certified101 👍 2 Selected: CD
C & D are correct
Nash101 👍 2
C&D CloudWatch Agent for Centralized Logging: The CloudWatch agent provides a reliable and efficient way to collect logs from the EC2 instances and send them to a central location, CloudWatch Logs. This eliminates the need for manual log retrieval via SSH and ensures logs are collected even during scaling events. CloudWatch Logs Insights for Cost-Effective Analysis: CloudWatch Logs Insights is a serverless log query service built on top of CloudWatch Logs. It allows you to analyze log data at scale without the need for additional infrastructure or complex data warehousing solutions. This offers a cost-effective approach for querying and analyzing the log data stored in CloudWatch Logs.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The CloudWatch agent forwards logs from each instance to CloudWatch Logs continuously, so when an instance scales in the logs are already stored centrally and are not lost. CloudWatch Logs Insights then queries those logs directly for application-session and user-issue analysis, with no extra analytics stack—meeting the cost-effective, no-loss requirement.

Why the Other Options Are Wrong

B adds Glue and Athena, which are unnecessary because Logs Insights already queries CloudWatch Logs. E (EFS) is a costlier shared-volume approach, not the most cost-effective. A (cron to S3) also preserves logs but would need Athena to query, adding overhead versus C+D. C and D are the correct pair.

Community Comment Notes

Community voted C,D (100). Commenters noted no Athena is needed for CloudWatch Logs—use Logs Insights instead. The CloudWatch agent ensures logs survive scale-in by shipping them off-instance.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide