AWS SysOps Administrator Associate (SOA-C02) - Fact Sheet¶
β οΈ RETIRED September 29, 2025. No longer available for new candidates. Replaced by AWS CloudOps Engineer - Associate (SOA-C03). Material preserved as historical reference.
Quick Reference¶
Exam Code: SOA-C02 Duration: 180 minutes (3 hours) Questions: 65 questions Passing Score: 720/1000 Cost: $150 USD Validity: 3 years Delivery: Pearson VUE Difficulty: ββββ (Hands-on focus)
Exam Domain Breakdown¶
| Domain | Weight | Key Focus |
|---|---|---|
| Monitoring, Logging & Remediation | 20% | CloudWatch, EventBridge, automation |
| Reliability & Business Continuity | 16% | Backups, HA, DR, Auto Scaling |
| Deployment, Provisioning & Automation | 18% | CloudFormation, Systems Manager, automation |
| Security & Compliance | 16% | IAM, encryption, patching, compliance |
| Networking & Content Delivery | 18% | VPC, Route 53, CloudFront, ELB |
| Cost & Performance Optimization | 12% | Cost Explorer, rightsizing, monitoring |
Key Services by Domain¶
Monitoring, Logging & Remediation (20%)¶
CloudWatch - Metrics: Standard (5-min), detailed (1-min), custom (1-sec high-resolution) - Alarms: Metric-based with SNS, Auto Scaling, EC2 actions - Logs: Aggregation, Insights queries, metric filters, retention - Dashboards: Cross-account, cross-region visualization - Synthetics: Canary monitoring - π CloudWatch Documentation
CloudWatch Agent - Collects system-level metrics (memory, disk, processes) - Collects logs from instances - Configuration via SSM Parameter Store - Unified agent (replaces old CloudWatch Logs and Monitoring agents) - π CloudWatch Agent Guide - Installation and configuration - π Agent Configuration - Configuration file reference - π Metrics Collected - Available metrics
EventBridge - Event-driven automation - AWS service events + custom applications - Schedule-based rules (cron expressions) - Targets: Lambda, Step Functions, SQS, SNS, EC2 actions - π EventBridge Documentation - π Event Patterns - Pattern matching - π Schedule Expressions - Cron and rate expressions - π EventBridge Targets - Available targets
Systems Manager Automation - Runbooks for common operational tasks - AWS-managed automation documents (100+) - Custom automation with YAML/JSON - Approval steps for sensitive operations - Change Calendar for maintenance windows - π SSM Automation - Runbook overview - π Automation Documents - Document reference - π Change Calendar - Maintenance windows
CloudTrail - API auditing for compliance - Management + data events - Insights for anomaly detection - Organization trails - π CloudTrail Documentation - π CloudTrail Events - Event types - π CloudTrail Insights - Anomaly detection
Reliability & Business Continuity (16%)¶
High Availability - Multi-AZ deployments - Elastic Load Balancing (ALB, NLB, GWLB) - Auto Scaling groups with health checks - RDS Multi-AZ automatic failover - Aurora with read replicas - π HA Architecture - Best practices - π RDS Multi-AZ - Database HA - π Aurora Read Replicas - Replication
Disaster Recovery - Backup & Restore: Lowest cost, RTO hours-days - Pilot Light: Core systems running, RTO 10s of minutes - Warm Standby: Scaled-down environment, RTO minutes - Multi-Region Active-Active: Highest cost, RTO seconds - π DR Strategies - Comprehensive guide
AWS Backup - Centralized backup across 35+ services - Backup plans with lifecycle rules - Cross-region and cross-account copies - Backup vault with encryption - π Backup Documentation
Auto Scaling - Dynamic scaling: Target tracking, step, simple - Scheduled scaling - Predictive scaling (ML-based) - Health checks: EC2, ELB - Lifecycle hooks for custom actions - π Auto Scaling Documentation - π Dynamic Scaling Policies - Scaling types - π Lifecycle Hooks - Custom actions - π Predictive Scaling - ML-based scaling
Deployment, Provisioning & Automation (18%)¶
CloudFormation - Infrastructure as Code (JSON/YAML) - Stacks for resource management - StackSets for multi-account/region - Change sets to preview updates - Drift detection - π CloudFormation Documentation - π StackSets - Multi-account deployment - π Change Sets - Preview changes - π Drift Detection - Configuration drift
Systems Manager - Session Manager: Secure shell without SSH keys - Run Command: Execute at scale - Patch Manager: Automated patching with maintenance windows - Parameter Store: Configuration management - State Manager: Enforce desired configuration - Inventory: Collect metadata from instances - π Systems Manager Documentation - π Session Manager - Secure shell access - π Run Command - Remote execution - π Patch Manager - OS patching - π Parameter Store - Configuration data - π State Manager - Desired state - π Inventory - Instance metadata
Elastic Beanstalk - PaaS for applications - Deployment options: All-at-once, rolling, rolling with batch, immutable, blue/green - Configuration with .ebextensions - π Elastic Beanstalk Documentation - π Deployment Policies - Deployment strategies - π .ebextensions - Configuration files
OpsWorks - Chef and Puppet managed configuration - Stacks, layers, instances - Lifecycle events with recipes - π AWS OpsWorks - Configuration management - π OpsWorks Stacks - Stack configuration
Security & Compliance (16%)¶
IAM - Users, groups, roles, policies - Least privilege principle - MFA enforcement - Access Analyzer for permission analysis - π IAM Best Practices - π IAM Policies - Policy syntax - π IAM Roles - Role delegation - π Access Analyzer - Permission analysis
Encryption - KMS for key management - EBS encryption (default per region) - S3 encryption (SSE-S3, SSE-KMS, SSE-C) - RDS/Aurora encryption at rest - In-transit via TLS/SSL - π AWS KMS - Key management - π EBS Encryption - Volume encryption - π S3 Encryption - Encryption options
Patch Management - Systems Manager Patch Manager - Patch baselines (OS-specific) - Maintenance windows for scheduling - Patch compliance reporting - π Patch Manager Guide - Patching workflow - π Patch Baselines - Baseline rules - π Maintenance Windows - Scheduling
AWS Config - Resource configuration tracking - Compliance rules (managed + custom) - Remediation actions - π Config Documentation - π Config Rules - Compliance evaluation - π Remediation Actions - Automated fixes
Networking & Content Delivery (18%)¶
VPC - Subnets (public/private) - Route tables - Internet Gateway, NAT Gateway - Security Groups (stateful) - NACLs (stateless) - VPC Flow Logs - π VPC Documentation - π VPC Subnets - Subnet configuration - π Security Groups - Instance firewall - π Network ACLs - Subnet firewall - π VPC Flow Logs - Traffic logging
Route 53 - DNS service - Routing policies: Simple, weighted, latency, failover, geolocation, geoproximity, multivalue - Health checks with failover - π Route 53 Documentation - π Routing Policies - Policy types - π Health Checks - Failover configuration
CloudFront - Global CDN - Origin: S3, ALB, custom HTTP - Edge caching with TTL - Signed URLs/cookies for private content - π CloudFront Documentation - π Cache Behavior - Caching configuration - π Signed URLs - Private content
Elastic Load Balancing - ALB: Layer 7, HTTP/HTTPS, host/path routing - NLB: Layer 4, TCP/UDP, ultra-low latency, static IPs - Health checks - Target groups - Cross-zone load balancing - π ELB Documentation - π ALB Guide - Application Load Balancer - π NLB Guide - Network Load Balancer - π Health Checks - Target health
Cost & Performance Optimization (12%)¶
Cost Management - Cost Explorer: Analyze spending - Budgets: Set alerts - Savings Plans: Up to 72% savings - Reserved Instances: 1 or 3 year - Spot Instances: Up to 90% savings - π Cost Management Documentation - π Cost Explorer - Cost analysis - π AWS Budgets - Budget alerts - π Savings Plans - Flexible pricing
Rightsizing - Compute Optimizer recommendations - CloudWatch metrics analysis - AWS Trusted Advisor checks - π Compute Optimizer Documentation - π Trusted Advisor - Best practice checks - π Rightsizing Guide - Instance resizing
S3 Optimization - Storage classes: Standard, IA, One Zone-IA, Glacier, Deep Archive - Intelligent-Tiering for automatic optimization - Lifecycle policies - Request metrics for optimization - π S3 Storage Classes - Class comparison - π S3 Lifecycle - Lifecycle rules - π S3 Intelligent-Tiering - Automatic optimization
Performance Monitoring - CloudWatch metrics for bottlenecks - X-Ray for distributed tracing - VPC Flow Logs for network analysis - EBS IOPS and throughput optimization - π X-Ray - Application tracing - π EBS Performance - Volume types and performance
Common SysOps Tasks¶
Instance Management¶
- Launch instances with user data
- Configure CloudWatch Agent for detailed monitoring
- Implement auto-recovery for instance failures
- Schedule instance start/stop with Lambda + EventBridge
- Apply patches with Systems Manager
Backup Strategy¶
- Automated EBS snapshots with lifecycle policies
- S3 versioning and lifecycle rules
- RDS automated backups and manual snapshots
- AWS Backup for centralized management
- Cross-region backup copies for DR
Security Hardening¶
- Enable EBS encryption by default
- Enforce S3 encryption with bucket policies
- Implement least privilege IAM policies
- Enable MFA for privileged users
- Regular security audits with Config and Security Hub
Network Troubleshooting¶
- VPC Flow Logs to analyze traffic
- Reachability Analyzer for path testing
- Security Group and NACL rule verification
- Route table configuration check
- DNS resolution with Route 53 query logging
Monitoring & Alerting¶
- CloudWatch alarms for critical metrics
- SNS notifications for alerts
- EventBridge rules for automated responses
- CloudWatch Logs Insights for log analysis
- Custom metrics for application monitoring
Exam Tips¶
Hands-On Focus¶
- SOA-C02 includes lab-based questions
- Must demonstrate actual AWS console/CLI skills
- Practice in real AWS environment essential
Common Scenarios¶
- Troubleshoot failing Auto Scaling groups
- Restore from backups after data loss
- Optimize costs for EC2 and storage
- Configure CloudWatch alarms and dashboards
- Implement automated patching
- Resolve network connectivity issues
- Set up cross-region DR
Question Keywords¶
- "Automate" β Systems Manager, EventBridge, Lambda
- "Monitor" β CloudWatch, X-Ray, VPC Flow Logs
- "Cost-effective" β Savings Plans, Spot, rightsizing, S3 lifecycle
- "High availability" β Multi-AZ, Auto Scaling, ELB
- "Secure" β Encryption, IAM roles, least privilege
- "Troubleshoot" β CloudWatch Logs, VPC Flow Logs, CloudTrail
Essential Documentation¶
Core Resources¶
- π SysOps Administrator Learning Path
- π AWS Systems Manager User Guide
- π Monitoring Best Practices
- π Well-Architected Operational Excellence Pillar
Hands-On Labs¶
Final Checklist¶
Knowledge¶
- Configure CloudWatch monitoring and alarms
- Implement Auto Scaling with health checks
- Design backup and DR strategies
- Troubleshoot networking issues
- Optimize costs using various AWS tools
- Automate operations with Systems Manager
- Implement security best practices
- Deploy with CloudFormation
Skills¶
- AWS Console proficiency
- AWS CLI experience
- Systems administration experience
- Networking fundamentals
- Scripting (Python, Bash, PowerShell)
Preparation¶
- 1+ year AWS SysOps experience
- Hands-on with all core services
- Practiced lab scenarios
- Completed practice exams (80%+)
Pro Tip: SOA-C02 is the most hands-on AWS Associate exam. You MUST have practical experience - you'll need to perform tasks in a live AWS environment during the exam. Focus on automation, monitoring, and troubleshooting!
Good luck! π