AWS Certified CloudOps Engineer - Associate (SOA-C03) Fact Sheet¶
Exam Overview¶
Exam Code: SOA-C03 Exam Name: AWS Certified CloudOps Engineer - Associate (formerly SysOps Administrator) Duration: 180 minutes (3 hours) Questions: 65 questions Question Format: Multiple choice, multiple response, and exam labs (hands-on) Passing Score: 720/1000 (scaled scoring, approximately 72%) Cost: $150 USD Valid For: 3 years Prerequisites: None required, but AWS Solutions Architect Associate recommended Language: Available in English, Japanese, Korean, Simplified Chinese Delivery: Pearson VUE (online proctored or testing center) Launch Date: September 30, 2025 (Registration opened September 9, 2025)
π Official Exam Page - Registration and details π Exam Guide PDF - Detailed exam objectives π Sample Questions - Official practice questions
Target Audience¶
This certification is designed for: - Cloud operations engineers managing AWS environments - System administrators transitioning to cloud operations - DevOps engineers focused on operations - Site reliability engineers (SREs) working with AWS - IT professionals operating production AWS workloads
Recommended Experience: - 1+ years hands-on AWS operations experience - Experience deploying and managing AWS resources - Understanding of AWS core services and architecture - Familiarity with automation and IaC tools - Knowledge of networking and security concepts
π CloudOps Engineer Role - Cloud operations overview π AWS Operations - Management tools
What's New in SOA-C03¶
Major Changes from SOA-C02 (SysOps Administrator):¶
New Name: "CloudOps Engineer" reflects modern cloud operations practices
Domain Changes: Reduced from 6 domains to 5 domains, with reorganization: - Combined monitoring, logging, and performance into single domain - Increased focus on deployment and automation - Enhanced emphasis on reliability and business continuity
New Services in Scope: - Containers: ECS, EKS, ECR, Fargate - Modern Databases: Aurora Serverless v2, RDS Proxy, DynamoDB DAX - Infrastructure as Code: AWS CDK in addition to CloudFormation - Multi-account: AWS Organizations, Control Tower - Observability: Enhanced CloudWatch features, X-Ray
π Exam Updates - Official announcement π What's New - Changes overview
Exam Domains¶
Domain 1: Monitoring, Logging, and Analysis (22%)¶
This is the largest domain, covering observability and troubleshooting.
1.1 CloudWatch Monitoring¶
CloudWatch Metrics: - Standard vs custom metrics - Metric dimensions and namespaces - High-resolution metrics (1-second) - Metric math and expressions - Cross-account and cross-region metrics
π Amazon CloudWatch - Monitoring service π CloudWatch Metrics - Working with metrics π Custom Metrics - Publishing custom metrics π Metric Math - Metric calculations
CloudWatch Alarms: - Metric alarms and composite alarms - Alarm states and actions - SNS integration for notifications - Auto Scaling integration - EC2 actions (stop, terminate, reboot)
π CloudWatch Alarms - Creating alarms π Composite Alarms - Complex alarm logic π Alarm Actions - Automated responses
1.2 CloudWatch Logs¶
Log Management: - Log groups and log streams - Log retention policies - Metric filters - Log insights queries - Cross-account log aggregation
π CloudWatch Logs - Log service π Log Groups - Organizing logs π Metric Filters - Extract metrics from logs π CloudWatch Logs Insights - Query and analyze logs
Log Collection: - CloudWatch Logs agent - Unified CloudWatch agent - Container logging (ECS, EKS) - Lambda function logs
π CloudWatch Agent - Agent installation π Agent Configuration - Configure agent π Container Logs - ECS/EKS logging
1.3 AWS X-Ray for Tracing¶
Distributed Tracing: - Service maps and trace analysis - X-Ray daemon configuration - X-Ray SDK integration - Trace sampling and filtering - Performance bottleneck identification
π AWS X-Ray - Distributed tracing π X-Ray Concepts - Tracing concepts π X-Ray Daemon - Daemon setup π Service Maps - Visualizing services
1.4 CloudTrail for Auditing¶
API Auditing: - CloudTrail events (management, data, insights) - Trail configuration and logging - Log file integrity validation - CloudWatch Logs integration - EventBridge integration
π AWS CloudTrail - API logging π Creating Trails - Trail setup π Event Types - Management vs data events π CloudTrail Insights - Anomaly detection
1.5 Systems Manager for Operations¶
SSM Features: - Session Manager for secure access - Run Command for remote execution - Patch Manager for OS patching - Parameter Store for configuration - OpsCenter for operational issues
π AWS Systems Manager - Operations hub π Session Manager - Secure shell access π Run Command - Remote commands π Patch Manager - Patch management π Parameter Store - Configuration management
Domain 2: Reliability and Business Continuity (20%)¶
Covers high availability, disaster recovery, and backups.
2.1 High Availability Architecture¶
HA Design Patterns: - Multi-AZ deployments - Load balancing (ALB, NLB, GLB) - Auto Scaling Groups - Route 53 health checks and failover - RDS Multi-AZ
π High Availability - HA patterns π Elastic Load Balancing - Load balancers π Auto Scaling - EC2 Auto Scaling π Route 53 Failover - DNS failover π RDS Multi-AZ - Database HA
2.2 Backup and Recovery¶
AWS Backup: - Centralized backup management - Backup plans and policies - Cross-region and cross-account backups - Backup vaults and lifecycle - Recovery testing
π AWS Backup - Backup service π Backup Plans - Creating plans π Backup Vaults - Backup storage π Cross-Region Backup - DR backups
Service-Specific Backups: - EBS snapshots and lifecycle - RDS automated backups and snapshots - DynamoDB backups and PITR - S3 versioning and replication - EFS backups
π EBS Snapshots - Volume backups π RDS Backups - Database backups π DynamoDB Backups - NoSQL backups π S3 Replication - Object replication
2.3 Disaster Recovery¶
DR Strategies: - Backup and restore (RPO/RTO hours) - Pilot light (RPO/RTO minutes-hours) - Warm standby (RPO/RTO minutes) - Multi-site active-active (RPO/RTO seconds)
π Disaster Recovery - DR patterns π AWS Elastic Disaster Recovery - Application DR π Pilot Light - Minimal DR
Domain 3: Deployment, Provisioning, and Automation (19%)¶
Covers infrastructure as code and automated deployments.
3.1 AWS CloudFormation¶
Infrastructure as Code: - CloudFormation templates (JSON/YAML) - Stacks and stack sets - Change sets for updates - Nested stacks - Custom resources and Lambda
π AWS CloudFormation - IaC service π Template Basics - Template syntax π Stack Sets - Multi-account deployment π Change Sets - Preview updates π Custom Resources - Extend CloudFormation
3.2 AWS CDK (NEW in SOA-C03)¶
Cloud Development Kit: - Define infrastructure using programming languages - CDK constructs and stacks - CDK synthesis to CloudFormation - CDK Pipelines for CI/CD
π AWS CDK - Infrastructure in code π CDK Constructs - Reusable components π CDK Stacks - Deployment units π CDK Pipelines - CI/CD automation
3.3 Elastic Beanstalk¶
Platform as a Service: - Application deployment and management - Environment configuration - Blue/green deployments - Platform updates - Health monitoring
π AWS Elastic Beanstalk - PaaS overview π Environments - Environment management π Deployments - Deployment options π Health Monitoring - Enhanced health
3.4 Container Services (NEW in SOA-C03)¶
Amazon ECS and Fargate: - ECS cluster management - Task definitions and services - Fargate launch type - Service auto scaling - Load balancer integration
π Amazon ECS - Container orchestration π ECS Tasks - Task definitions π ECS Services - Service management π AWS Fargate - Serverless containers
Amazon EKS: - Managed Kubernetes service - Node groups and Fargate profiles - EKS add-ons - kubectl access configuration
π Amazon EKS - Kubernetes on AWS π EKS Node Groups - Worker nodes π EKS Fargate - Serverless pods
Amazon ECR: - Container image registry - Image scanning - Lifecycle policies - Cross-region replication
π Amazon ECR - Container registry π Image Scanning - Vulnerability scanning π Lifecycle Policies - Image cleanup
3.5 CI/CD Pipelines¶
AWS CodePipeline: - Pipeline stages and actions - Source, build, test, deploy stages - Integration with CodeCommit, CodeBuild, CodeDeploy - Third-party integrations (GitHub, Jenkins)
π AWS CodePipeline - CI/CD service π Pipeline Structure - Pipeline concepts π AWS CodeBuild - Build service π AWS CodeDeploy - Deployment automation
Domain 4: Security and Compliance (18%)¶
Covers security best practices, access control, and compliance.
4.1 Identity and Access Management¶
IAM Best Practices: - Principle of least privilege - IAM roles vs users - MFA enforcement - Password policies - Access key rotation
π AWS IAM - Identity and Access Management π IAM Best Practices - Security recommendations π IAM Policies - Access control π IAM Roles - Temporary credentials
Multi-Account Management (NEW focus in SOA-C03): - AWS Organizations - Service Control Policies (SCPs) - AWS Control Tower - Cross-account access
π AWS Organizations - Multi-account management π Service Control Policies - Organization policies π AWS Control Tower - Landing zones
4.2 Data Protection¶
Encryption: - Encryption at rest (EBS, S3, RDS) - Encryption in transit (TLS/SSL) - AWS KMS for key management - CloudHSM for compliance - Certificate Manager (ACM)
π Data Encryption - Encryption overview π AWS KMS - Key management π EBS Encryption - Volume encryption π S3 Encryption - Object encryption π ACM - SSL/TLS certificates
4.3 Network Security¶
VPC Security: - Security groups (stateful) - Network ACLs (stateless) - VPC Flow Logs - AWS WAF for applications - AWS Shield for DDoS protection
π VPC Security - Network security π Security Groups - Instance firewalls π Network ACLs - Subnet firewalls π VPC Flow Logs - Network traffic logs π AWS WAF - Web application firewall
4.4 Compliance and Governance¶
AWS Config: - Resource inventory and configuration history - Config rules for compliance - Conformance packs - Remediation actions
π AWS Config - Configuration management π Config Rules - Compliance checks π Conformance Packs - Compliance frameworks π Remediation - Auto-remediation
AWS Trusted Advisor: - Cost optimization checks - Performance recommendations - Security best practices - Fault tolerance analysis
π AWS Trusted Advisor - Best practice checks
Domain 5: Networking and Content Delivery (16%)¶
Covers VPC, networking, and CloudFront.
5.1 VPC Architecture¶
VPC Components: - Subnets (public and private) - Route tables and routing - Internet Gateway and NAT Gateway - VPC endpoints (Gateway and Interface) - Transit Gateway
π Amazon VPC - Virtual private cloud π Subnets - Subnet configuration π Route Tables - Routing π NAT Gateway - Outbound internet access π VPC Endpoints - Private service access
5.2 Connectivity Options¶
Hybrid Connectivity: - Site-to-Site VPN - AWS Direct Connect - Transit Gateway for hub-and-spoke - VPC peering - AWS VPN CloudHub
π Site-to-Site VPN - VPN connections π AWS Direct Connect - Dedicated connections π Transit Gateway - Network hub π VPC Peering - Connect VPCs
5.3 Route 53 DNS¶
DNS Management: - Hosted zones (public and private) - Record types (A, AAAA, CNAME, etc.) - Routing policies (simple, weighted, latency, failover, geolocation) - Health checks and monitoring
π Amazon Route 53 - DNS service π Hosted Zones - DNS zones π Routing Policies - Traffic routing π Health Checks - Endpoint monitoring
5.4 CloudFront Content Delivery¶
CDN Configuration: - Distributions and origins - Cache behaviors and TTL - Origin failover - Lambda@Edge - CloudFront Functions
π Amazon CloudFront - Content delivery network π Distributions - CDN setup π Cache Behavior - Caching configuration π Lambda@Edge - Edge computing
Domain 6: Cost and Performance Optimization (15%)¶
Covers cost management and performance tuning.
6.1 Cost Optimization¶
Cost Management: - AWS Cost Explorer - Budgets and alerts - Cost allocation tags - Reserved Instances and Savings Plans - Spot Instances for non-production
π AWS Cost Management - Cost tools π Cost Explorer - Cost analysis π AWS Budgets - Budget alerts π Reserved Instances - Capacity reservations
6.2 Performance Optimization¶
EC2 Optimization: - Right-sizing instances - Enhanced networking - Placement groups - EBS optimization
π EC2 Performance - Network performance π Placement Groups - Optimize placement π Compute Optimizer - Right-sizing recommendations
Database Optimization: - RDS Proxy for connection pooling (NEW in SOA-C03) - DynamoDB DAX for caching (NEW in SOA-C03) - Aurora Serverless v2 (NEW in SOA-C03) - Read replicas
π RDS Proxy - Database proxy π DynamoDB DAX - In-memory cache π Aurora Serverless v2 - Auto-scaling database
Study Strategy¶
Recommended Timeline (6-8 weeks, 12-18 hours/week)¶
Weeks 1-2: Monitoring and Operations - CloudWatch metrics, logs, alarms - X-Ray and CloudTrail - Systems Manager - Study time: 15 hours/week
Weeks 3-4: Infrastructure and Automation - CloudFormation and AWS CDK - Elastic Beanstalk - Container services (ECS, EKS, ECR) - Study time: 18 hours/week
Weeks 5-6: Security and Networking - IAM and multi-account management - VPC architecture - Security best practices - Study time: 15 hours/week
Weeks 7-8: Review and Practice Labs - Hands-on exam labs practice - Full practice exams (aim for 75%+) - Review weak areas - Study time: 12-15 hours/week
Study Resources¶
Official AWS Training: π AWS Skill Builder - Free AWS training π CloudOps Learning Plan - Official study plan π Exam Prep Course - Official exam prep
Hands-On Practice: - Complete AWS hands-on labs - Practice with exam lab scenarios - Build automated deployment pipelines - Configure multi-AZ architectures - Set up comprehensive monitoring
π Hands-On Tutorials - AWS tutorials π AWS Well-Architected Labs - Best practice labs
Exam Day Tips¶
Preparation¶
- Review CloudWatch metrics and alarms
- Know CloudFormation syntax basics
- Understand container service differences (ECS vs EKS)
- Review multi-account management
- Practice exam labs thoroughly
- Get adequate rest before exam
During Exam¶
- Exam Labs: Complete hands-on labs first (20-40 minutes each)
- Read scenario questions carefully
- Look for keywords: "MOST operationally efficient", "LEAST cost"
- Eliminate wrong answers first
- Flag uncertain questions for review
- Manage time: ~2.8 minutes per question (plus lab time)
Common Question Patterns¶
- Troubleshooting monitoring and logging issues
- Choosing appropriate backup and DR strategies
- Selecting deployment automation approaches
- Multi-AZ and high availability scenarios
- Container deployment configurations
- Security and compliance requirements
- Cost optimization strategies
Exam Labs¶
- 2-3 hands-on scenario labs
- Use AWS Console to complete tasks
- Verify your work before submitting
- Time management is critical
π Exam Preparation - Official resources
After Certification¶
Career Benefits¶
- Validates cloud operations expertise
- Opens CloudOps and SRE roles
- Demonstrates automation skills
- Industry recognition
Next Certifications¶
π AWS DevOps Engineer Professional - Advanced DevOps π AWS Security Specialty - Security focus π AWS Solutions Architect Professional - Architecture mastery
Continuous Learning¶
- Follow AWS operations blog
- Experiment with new AWS services
- Attend re:Invent operations sessions
- Build automated workflows
- Join cloud operations communities
π AWS Operations Blog - Management & Governance updates
Quick Reference¶
Exam Details at a Glance¶
- 65 questions in 180 minutes = ~2.8 minutes per question (plus lab time)
- 720/1000 to pass = Approximately 72%
- 22% Monitoring & logging = ~14 questions
- 20% Reliability & business continuity = ~13 questions
- 19% Deployment & automation = ~12 questions
- 18% Security & compliance = ~12 questions
- 16% Networking = ~10 questions
- 15% Cost & performance = ~10 questions
- Plus 2-3 hands-on exam labs
Key Services to Master¶
| Category | Core Services |
|---|---|
| Monitoring | CloudWatch, X-Ray, CloudTrail, Systems Manager |
| Deployment | CloudFormation, CDK, Elastic Beanstalk, CodePipeline |
| Containers | ECS, EKS, ECR, Fargate |
| Security | IAM, KMS, Organizations, Config, WAF |
| Networking | VPC, Route 53, CloudFront, Direct Connect |
| Backup | AWS Backup, EBS Snapshots, RDS Backups |
New in SOA-C03¶
| Service/Feature | Why It's Included |
|---|---|
| AWS CDK | Modern IaC with programming languages |
| ECS/EKS/ECR | Container operations now in scope |
| RDS Proxy | Database connection management |
| DynamoDB DAX | NoSQL performance optimization |
| Aurora Serverless v2 | Serverless database operations |
| AWS Control Tower | Multi-account governance |
| Organizations focus | Enterprise cloud operations |
Good luck with your AWS Certified CloudOps Engineer - Associate exam! π