Skip to content

AWS Certified CloudOps Engineer - Associate (SOA-C03) Fact Sheet

Exam Overview

Exam Code: SOA-C03 Exam Name: AWS Certified CloudOps Engineer - Associate (formerly SysOps Administrator) Duration: 180 minutes (3 hours) Questions: 65 questions Question Format: Multiple choice, multiple response, and exam labs (hands-on) Passing Score: 720/1000 (scaled scoring, approximately 72%) Cost: $150 USD Valid For: 3 years Prerequisites: None required, but AWS Solutions Architect Associate recommended Language: Available in English, Japanese, Korean, Simplified Chinese Delivery: Pearson VUE (online proctored or testing center) Launch Date: September 30, 2025 (Registration opened September 9, 2025)

πŸ“– Official Exam Page - Registration and details πŸ“– Exam Guide PDF - Detailed exam objectives πŸ“– Sample Questions - Official practice questions

Target Audience

This certification is designed for: - Cloud operations engineers managing AWS environments - System administrators transitioning to cloud operations - DevOps engineers focused on operations - Site reliability engineers (SREs) working with AWS - IT professionals operating production AWS workloads

Recommended Experience: - 1+ years hands-on AWS operations experience - Experience deploying and managing AWS resources - Understanding of AWS core services and architecture - Familiarity with automation and IaC tools - Knowledge of networking and security concepts

πŸ“– CloudOps Engineer Role - Cloud operations overview πŸ“– AWS Operations - Management tools

What's New in SOA-C03

Major Changes from SOA-C02 (SysOps Administrator):

New Name: "CloudOps Engineer" reflects modern cloud operations practices

Domain Changes: Reduced from 6 domains to 5 domains, with reorganization: - Combined monitoring, logging, and performance into single domain - Increased focus on deployment and automation - Enhanced emphasis on reliability and business continuity

New Services in Scope: - Containers: ECS, EKS, ECR, Fargate - Modern Databases: Aurora Serverless v2, RDS Proxy, DynamoDB DAX - Infrastructure as Code: AWS CDK in addition to CloudFormation - Multi-account: AWS Organizations, Control Tower - Observability: Enhanced CloudWatch features, X-Ray

πŸ“– Exam Updates - Official announcement πŸ“– What's New - Changes overview

Exam Domains

Domain 1: Monitoring, Logging, and Analysis (22%)

This is the largest domain, covering observability and troubleshooting.

1.1 CloudWatch Monitoring

CloudWatch Metrics: - Standard vs custom metrics - Metric dimensions and namespaces - High-resolution metrics (1-second) - Metric math and expressions - Cross-account and cross-region metrics

πŸ“– Amazon CloudWatch - Monitoring service πŸ“– CloudWatch Metrics - Working with metrics πŸ“– Custom Metrics - Publishing custom metrics πŸ“– Metric Math - Metric calculations

CloudWatch Alarms: - Metric alarms and composite alarms - Alarm states and actions - SNS integration for notifications - Auto Scaling integration - EC2 actions (stop, terminate, reboot)

πŸ“– CloudWatch Alarms - Creating alarms πŸ“– Composite Alarms - Complex alarm logic πŸ“– Alarm Actions - Automated responses

1.2 CloudWatch Logs

Log Management: - Log groups and log streams - Log retention policies - Metric filters - Log insights queries - Cross-account log aggregation

πŸ“– CloudWatch Logs - Log service πŸ“– Log Groups - Organizing logs πŸ“– Metric Filters - Extract metrics from logs πŸ“– CloudWatch Logs Insights - Query and analyze logs

Log Collection: - CloudWatch Logs agent - Unified CloudWatch agent - Container logging (ECS, EKS) - Lambda function logs

πŸ“– CloudWatch Agent - Agent installation πŸ“– Agent Configuration - Configure agent πŸ“– Container Logs - ECS/EKS logging

1.3 AWS X-Ray for Tracing

Distributed Tracing: - Service maps and trace analysis - X-Ray daemon configuration - X-Ray SDK integration - Trace sampling and filtering - Performance bottleneck identification

πŸ“– AWS X-Ray - Distributed tracing πŸ“– X-Ray Concepts - Tracing concepts πŸ“– X-Ray Daemon - Daemon setup πŸ“– Service Maps - Visualizing services

1.4 CloudTrail for Auditing

API Auditing: - CloudTrail events (management, data, insights) - Trail configuration and logging - Log file integrity validation - CloudWatch Logs integration - EventBridge integration

πŸ“– AWS CloudTrail - API logging πŸ“– Creating Trails - Trail setup πŸ“– Event Types - Management vs data events πŸ“– CloudTrail Insights - Anomaly detection

1.5 Systems Manager for Operations

SSM Features: - Session Manager for secure access - Run Command for remote execution - Patch Manager for OS patching - Parameter Store for configuration - OpsCenter for operational issues

πŸ“– AWS Systems Manager - Operations hub πŸ“– Session Manager - Secure shell access πŸ“– Run Command - Remote commands πŸ“– Patch Manager - Patch management πŸ“– Parameter Store - Configuration management

Domain 2: Reliability and Business Continuity (20%)

Covers high availability, disaster recovery, and backups.

2.1 High Availability Architecture

HA Design Patterns: - Multi-AZ deployments - Load balancing (ALB, NLB, GLB) - Auto Scaling Groups - Route 53 health checks and failover - RDS Multi-AZ

πŸ“– High Availability - HA patterns πŸ“– Elastic Load Balancing - Load balancers πŸ“– Auto Scaling - EC2 Auto Scaling πŸ“– Route 53 Failover - DNS failover πŸ“– RDS Multi-AZ - Database HA

2.2 Backup and Recovery

AWS Backup: - Centralized backup management - Backup plans and policies - Cross-region and cross-account backups - Backup vaults and lifecycle - Recovery testing

πŸ“– AWS Backup - Backup service πŸ“– Backup Plans - Creating plans πŸ“– Backup Vaults - Backup storage πŸ“– Cross-Region Backup - DR backups

Service-Specific Backups: - EBS snapshots and lifecycle - RDS automated backups and snapshots - DynamoDB backups and PITR - S3 versioning and replication - EFS backups

πŸ“– EBS Snapshots - Volume backups πŸ“– RDS Backups - Database backups πŸ“– DynamoDB Backups - NoSQL backups πŸ“– S3 Replication - Object replication

2.3 Disaster Recovery

DR Strategies: - Backup and restore (RPO/RTO hours) - Pilot light (RPO/RTO minutes-hours) - Warm standby (RPO/RTO minutes) - Multi-site active-active (RPO/RTO seconds)

πŸ“– Disaster Recovery - DR patterns πŸ“– AWS Elastic Disaster Recovery - Application DR πŸ“– Pilot Light - Minimal DR

Domain 3: Deployment, Provisioning, and Automation (19%)

Covers infrastructure as code and automated deployments.

3.1 AWS CloudFormation

Infrastructure as Code: - CloudFormation templates (JSON/YAML) - Stacks and stack sets - Change sets for updates - Nested stacks - Custom resources and Lambda

πŸ“– AWS CloudFormation - IaC service πŸ“– Template Basics - Template syntax πŸ“– Stack Sets - Multi-account deployment πŸ“– Change Sets - Preview updates πŸ“– Custom Resources - Extend CloudFormation

3.2 AWS CDK (NEW in SOA-C03)

Cloud Development Kit: - Define infrastructure using programming languages - CDK constructs and stacks - CDK synthesis to CloudFormation - CDK Pipelines for CI/CD

πŸ“– AWS CDK - Infrastructure in code πŸ“– CDK Constructs - Reusable components πŸ“– CDK Stacks - Deployment units πŸ“– CDK Pipelines - CI/CD automation

3.3 Elastic Beanstalk

Platform as a Service: - Application deployment and management - Environment configuration - Blue/green deployments - Platform updates - Health monitoring

πŸ“– AWS Elastic Beanstalk - PaaS overview πŸ“– Environments - Environment management πŸ“– Deployments - Deployment options πŸ“– Health Monitoring - Enhanced health

3.4 Container Services (NEW in SOA-C03)

Amazon ECS and Fargate: - ECS cluster management - Task definitions and services - Fargate launch type - Service auto scaling - Load balancer integration

πŸ“– Amazon ECS - Container orchestration πŸ“– ECS Tasks - Task definitions πŸ“– ECS Services - Service management πŸ“– AWS Fargate - Serverless containers

Amazon EKS: - Managed Kubernetes service - Node groups and Fargate profiles - EKS add-ons - kubectl access configuration

πŸ“– Amazon EKS - Kubernetes on AWS πŸ“– EKS Node Groups - Worker nodes πŸ“– EKS Fargate - Serverless pods

Amazon ECR: - Container image registry - Image scanning - Lifecycle policies - Cross-region replication

πŸ“– Amazon ECR - Container registry πŸ“– Image Scanning - Vulnerability scanning πŸ“– Lifecycle Policies - Image cleanup

3.5 CI/CD Pipelines

AWS CodePipeline: - Pipeline stages and actions - Source, build, test, deploy stages - Integration with CodeCommit, CodeBuild, CodeDeploy - Third-party integrations (GitHub, Jenkins)

πŸ“– AWS CodePipeline - CI/CD service πŸ“– Pipeline Structure - Pipeline concepts πŸ“– AWS CodeBuild - Build service πŸ“– AWS CodeDeploy - Deployment automation

Domain 4: Security and Compliance (18%)

Covers security best practices, access control, and compliance.

4.1 Identity and Access Management

IAM Best Practices: - Principle of least privilege - IAM roles vs users - MFA enforcement - Password policies - Access key rotation

πŸ“– AWS IAM - Identity and Access Management πŸ“– IAM Best Practices - Security recommendations πŸ“– IAM Policies - Access control πŸ“– IAM Roles - Temporary credentials

Multi-Account Management (NEW focus in SOA-C03): - AWS Organizations - Service Control Policies (SCPs) - AWS Control Tower - Cross-account access

πŸ“– AWS Organizations - Multi-account management πŸ“– Service Control Policies - Organization policies πŸ“– AWS Control Tower - Landing zones

4.2 Data Protection

Encryption: - Encryption at rest (EBS, S3, RDS) - Encryption in transit (TLS/SSL) - AWS KMS for key management - CloudHSM for compliance - Certificate Manager (ACM)

πŸ“– Data Encryption - Encryption overview πŸ“– AWS KMS - Key management πŸ“– EBS Encryption - Volume encryption πŸ“– S3 Encryption - Object encryption πŸ“– ACM - SSL/TLS certificates

4.3 Network Security

VPC Security: - Security groups (stateful) - Network ACLs (stateless) - VPC Flow Logs - AWS WAF for applications - AWS Shield for DDoS protection

πŸ“– VPC Security - Network security πŸ“– Security Groups - Instance firewalls πŸ“– Network ACLs - Subnet firewalls πŸ“– VPC Flow Logs - Network traffic logs πŸ“– AWS WAF - Web application firewall

4.4 Compliance and Governance

AWS Config: - Resource inventory and configuration history - Config rules for compliance - Conformance packs - Remediation actions

πŸ“– AWS Config - Configuration management πŸ“– Config Rules - Compliance checks πŸ“– Conformance Packs - Compliance frameworks πŸ“– Remediation - Auto-remediation

AWS Trusted Advisor: - Cost optimization checks - Performance recommendations - Security best practices - Fault tolerance analysis

πŸ“– AWS Trusted Advisor - Best practice checks

Domain 5: Networking and Content Delivery (16%)

Covers VPC, networking, and CloudFront.

5.1 VPC Architecture

VPC Components: - Subnets (public and private) - Route tables and routing - Internet Gateway and NAT Gateway - VPC endpoints (Gateway and Interface) - Transit Gateway

πŸ“– Amazon VPC - Virtual private cloud πŸ“– Subnets - Subnet configuration πŸ“– Route Tables - Routing πŸ“– NAT Gateway - Outbound internet access πŸ“– VPC Endpoints - Private service access

5.2 Connectivity Options

Hybrid Connectivity: - Site-to-Site VPN - AWS Direct Connect - Transit Gateway for hub-and-spoke - VPC peering - AWS VPN CloudHub

πŸ“– Site-to-Site VPN - VPN connections πŸ“– AWS Direct Connect - Dedicated connections πŸ“– Transit Gateway - Network hub πŸ“– VPC Peering - Connect VPCs

5.3 Route 53 DNS

DNS Management: - Hosted zones (public and private) - Record types (A, AAAA, CNAME, etc.) - Routing policies (simple, weighted, latency, failover, geolocation) - Health checks and monitoring

πŸ“– Amazon Route 53 - DNS service πŸ“– Hosted Zones - DNS zones πŸ“– Routing Policies - Traffic routing πŸ“– Health Checks - Endpoint monitoring

5.4 CloudFront Content Delivery

CDN Configuration: - Distributions and origins - Cache behaviors and TTL - Origin failover - Lambda@Edge - CloudFront Functions

πŸ“– Amazon CloudFront - Content delivery network πŸ“– Distributions - CDN setup πŸ“– Cache Behavior - Caching configuration πŸ“– Lambda@Edge - Edge computing

Domain 6: Cost and Performance Optimization (15%)

Covers cost management and performance tuning.

6.1 Cost Optimization

Cost Management: - AWS Cost Explorer - Budgets and alerts - Cost allocation tags - Reserved Instances and Savings Plans - Spot Instances for non-production

πŸ“– AWS Cost Management - Cost tools πŸ“– Cost Explorer - Cost analysis πŸ“– AWS Budgets - Budget alerts πŸ“– Reserved Instances - Capacity reservations

6.2 Performance Optimization

EC2 Optimization: - Right-sizing instances - Enhanced networking - Placement groups - EBS optimization

πŸ“– EC2 Performance - Network performance πŸ“– Placement Groups - Optimize placement πŸ“– Compute Optimizer - Right-sizing recommendations

Database Optimization: - RDS Proxy for connection pooling (NEW in SOA-C03) - DynamoDB DAX for caching (NEW in SOA-C03) - Aurora Serverless v2 (NEW in SOA-C03) - Read replicas

πŸ“– RDS Proxy - Database proxy πŸ“– DynamoDB DAX - In-memory cache πŸ“– Aurora Serverless v2 - Auto-scaling database

Study Strategy

Weeks 1-2: Monitoring and Operations - CloudWatch metrics, logs, alarms - X-Ray and CloudTrail - Systems Manager - Study time: 15 hours/week

Weeks 3-4: Infrastructure and Automation - CloudFormation and AWS CDK - Elastic Beanstalk - Container services (ECS, EKS, ECR) - Study time: 18 hours/week

Weeks 5-6: Security and Networking - IAM and multi-account management - VPC architecture - Security best practices - Study time: 15 hours/week

Weeks 7-8: Review and Practice Labs - Hands-on exam labs practice - Full practice exams (aim for 75%+) - Review weak areas - Study time: 12-15 hours/week

Study Resources

Official AWS Training: πŸ“– AWS Skill Builder - Free AWS training πŸ“– CloudOps Learning Plan - Official study plan πŸ“– Exam Prep Course - Official exam prep

Hands-On Practice: - Complete AWS hands-on labs - Practice with exam lab scenarios - Build automated deployment pipelines - Configure multi-AZ architectures - Set up comprehensive monitoring

πŸ“– Hands-On Tutorials - AWS tutorials πŸ“– AWS Well-Architected Labs - Best practice labs

Exam Day Tips

Preparation

  • Review CloudWatch metrics and alarms
  • Know CloudFormation syntax basics
  • Understand container service differences (ECS vs EKS)
  • Review multi-account management
  • Practice exam labs thoroughly
  • Get adequate rest before exam

During Exam

  • Exam Labs: Complete hands-on labs first (20-40 minutes each)
  • Read scenario questions carefully
  • Look for keywords: "MOST operationally efficient", "LEAST cost"
  • Eliminate wrong answers first
  • Flag uncertain questions for review
  • Manage time: ~2.8 minutes per question (plus lab time)

Common Question Patterns

  • Troubleshooting monitoring and logging issues
  • Choosing appropriate backup and DR strategies
  • Selecting deployment automation approaches
  • Multi-AZ and high availability scenarios
  • Container deployment configurations
  • Security and compliance requirements
  • Cost optimization strategies

Exam Labs

  • 2-3 hands-on scenario labs
  • Use AWS Console to complete tasks
  • Verify your work before submitting
  • Time management is critical

πŸ“– Exam Preparation - Official resources

After Certification

Career Benefits

  • Validates cloud operations expertise
  • Opens CloudOps and SRE roles
  • Demonstrates automation skills
  • Industry recognition

Next Certifications

πŸ“– AWS DevOps Engineer Professional - Advanced DevOps πŸ“– AWS Security Specialty - Security focus πŸ“– AWS Solutions Architect Professional - Architecture mastery

Continuous Learning

  • Follow AWS operations blog
  • Experiment with new AWS services
  • Attend re:Invent operations sessions
  • Build automated workflows
  • Join cloud operations communities

πŸ“– AWS Operations Blog - Management & Governance updates


Quick Reference

Exam Details at a Glance

  • 65 questions in 180 minutes = ~2.8 minutes per question (plus lab time)
  • 720/1000 to pass = Approximately 72%
  • 22% Monitoring & logging = ~14 questions
  • 20% Reliability & business continuity = ~13 questions
  • 19% Deployment & automation = ~12 questions
  • 18% Security & compliance = ~12 questions
  • 16% Networking = ~10 questions
  • 15% Cost & performance = ~10 questions
  • Plus 2-3 hands-on exam labs

Key Services to Master

Category Core Services
Monitoring CloudWatch, X-Ray, CloudTrail, Systems Manager
Deployment CloudFormation, CDK, Elastic Beanstalk, CodePipeline
Containers ECS, EKS, ECR, Fargate
Security IAM, KMS, Organizations, Config, WAF
Networking VPC, Route 53, CloudFront, Direct Connect
Backup AWS Backup, EBS Snapshots, RDS Backups

New in SOA-C03

Service/Feature Why It's Included
AWS CDK Modern IaC with programming languages
ECS/EKS/ECR Container operations now in scope
RDS Proxy Database connection management
DynamoDB DAX NoSQL performance optimization
Aurora Serverless v2 Serverless database operations
AWS Control Tower Multi-account governance
Organizations focus Enterprise cloud operations

Good luck with your AWS Certified CloudOps Engineer - Associate exam! πŸŽ‰