Correct Answer : B
Option A is incorrect because the condition “status_code = 4*” should be used to match the 4xx status code in the HTTP log events.
Option B is CORRECT because for space-delimited events, you can use shorthand notification using an ellipsis (…) for the fields that you do not care about. This pattern “[..., status_code = 4*, bytes]” can check if the status code equals with 4xx.
Option C is incorrect because to parse space-delimited events, the metric filter pattern has to specify the fields with a name, separated by commas, with the entire pattern enclosed in square brackets. To add a condition to the status_code field, you need to modify the pattern to be like “[..., status_code = 4*, bytes]”.
Option D is incorrect because similar to option C, the condition in the status_code field is incorrect. The correct filter pattern is “[ip, user, username, timestamp, request, status_code = 4*, bytes]” or “[..., status_code = 4*, bytes]”.
Reference:
https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/FilterAndPatternSyntax.html
https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/Counting404Responses.html