Skip to content

AWS SysOps Administrator Associate (SOA-C02) - Fact Sheet

⚠️ RETIRED September 29, 2025. No longer available for new candidates. Replaced by AWS CloudOps Engineer - Associate (SOA-C03). Material preserved as historical reference.

Quick Reference

Exam Code: SOA-C02 Duration: 180 minutes (3 hours) Questions: 65 questions Passing Score: 720/1000 Cost: $150 USD Validity: 3 years Delivery: Pearson VUE Difficulty: ⭐⭐⭐⭐ (Hands-on focus)

Exam Domain Breakdown

Domain Weight Key Focus
Monitoring, Logging & Remediation 20% CloudWatch, EventBridge, automation
Reliability & Business Continuity 16% Backups, HA, DR, Auto Scaling
Deployment, Provisioning & Automation 18% CloudFormation, Systems Manager, automation
Security & Compliance 16% IAM, encryption, patching, compliance
Networking & Content Delivery 18% VPC, Route 53, CloudFront, ELB
Cost & Performance Optimization 12% Cost Explorer, rightsizing, monitoring

Key Services by Domain

Monitoring, Logging & Remediation (20%)

CloudWatch - Metrics: Standard (5-min), detailed (1-min), custom (1-sec high-resolution) - Alarms: Metric-based with SNS, Auto Scaling, EC2 actions - Logs: Aggregation, Insights queries, metric filters, retention - Dashboards: Cross-account, cross-region visualization - Synthetics: Canary monitoring - πŸ“– CloudWatch Documentation

CloudWatch Agent - Collects system-level metrics (memory, disk, processes) - Collects logs from instances - Configuration via SSM Parameter Store - Unified agent (replaces old CloudWatch Logs and Monitoring agents) - πŸ“– CloudWatch Agent Guide - Installation and configuration - πŸ“– Agent Configuration - Configuration file reference - πŸ“– Metrics Collected - Available metrics

EventBridge - Event-driven automation - AWS service events + custom applications - Schedule-based rules (cron expressions) - Targets: Lambda, Step Functions, SQS, SNS, EC2 actions - πŸ“– EventBridge Documentation - πŸ“– Event Patterns - Pattern matching - πŸ“– Schedule Expressions - Cron and rate expressions - πŸ“– EventBridge Targets - Available targets

Systems Manager Automation - Runbooks for common operational tasks - AWS-managed automation documents (100+) - Custom automation with YAML/JSON - Approval steps for sensitive operations - Change Calendar for maintenance windows - πŸ“– SSM Automation - Runbook overview - πŸ“– Automation Documents - Document reference - πŸ“– Change Calendar - Maintenance windows

CloudTrail - API auditing for compliance - Management + data events - Insights for anomaly detection - Organization trails - πŸ“– CloudTrail Documentation - πŸ“– CloudTrail Events - Event types - πŸ“– CloudTrail Insights - Anomaly detection

Reliability & Business Continuity (16%)

High Availability - Multi-AZ deployments - Elastic Load Balancing (ALB, NLB, GWLB) - Auto Scaling groups with health checks - RDS Multi-AZ automatic failover - Aurora with read replicas - πŸ“– HA Architecture - Best practices - πŸ“– RDS Multi-AZ - Database HA - πŸ“– Aurora Read Replicas - Replication

Disaster Recovery - Backup & Restore: Lowest cost, RTO hours-days - Pilot Light: Core systems running, RTO 10s of minutes - Warm Standby: Scaled-down environment, RTO minutes - Multi-Region Active-Active: Highest cost, RTO seconds - πŸ“– DR Strategies - Comprehensive guide

AWS Backup - Centralized backup across 35+ services - Backup plans with lifecycle rules - Cross-region and cross-account copies - Backup vault with encryption - πŸ“– Backup Documentation

Auto Scaling - Dynamic scaling: Target tracking, step, simple - Scheduled scaling - Predictive scaling (ML-based) - Health checks: EC2, ELB - Lifecycle hooks for custom actions - πŸ“– Auto Scaling Documentation - πŸ“– Dynamic Scaling Policies - Scaling types - πŸ“– Lifecycle Hooks - Custom actions - πŸ“– Predictive Scaling - ML-based scaling

Deployment, Provisioning & Automation (18%)

CloudFormation - Infrastructure as Code (JSON/YAML) - Stacks for resource management - StackSets for multi-account/region - Change sets to preview updates - Drift detection - πŸ“– CloudFormation Documentation - πŸ“– StackSets - Multi-account deployment - πŸ“– Change Sets - Preview changes - πŸ“– Drift Detection - Configuration drift

Systems Manager - Session Manager: Secure shell without SSH keys - Run Command: Execute at scale - Patch Manager: Automated patching with maintenance windows - Parameter Store: Configuration management - State Manager: Enforce desired configuration - Inventory: Collect metadata from instances - πŸ“– Systems Manager Documentation - πŸ“– Session Manager - Secure shell access - πŸ“– Run Command - Remote execution - πŸ“– Patch Manager - OS patching - πŸ“– Parameter Store - Configuration data - πŸ“– State Manager - Desired state - πŸ“– Inventory - Instance metadata

Elastic Beanstalk - PaaS for applications - Deployment options: All-at-once, rolling, rolling with batch, immutable, blue/green - Configuration with .ebextensions - πŸ“– Elastic Beanstalk Documentation - πŸ“– Deployment Policies - Deployment strategies - πŸ“– .ebextensions - Configuration files

OpsWorks - Chef and Puppet managed configuration - Stacks, layers, instances - Lifecycle events with recipes - πŸ“– AWS OpsWorks - Configuration management - πŸ“– OpsWorks Stacks - Stack configuration

Security & Compliance (16%)

IAM - Users, groups, roles, policies - Least privilege principle - MFA enforcement - Access Analyzer for permission analysis - πŸ“– IAM Best Practices - πŸ“– IAM Policies - Policy syntax - πŸ“– IAM Roles - Role delegation - πŸ“– Access Analyzer - Permission analysis

Encryption - KMS for key management - EBS encryption (default per region) - S3 encryption (SSE-S3, SSE-KMS, SSE-C) - RDS/Aurora encryption at rest - In-transit via TLS/SSL - πŸ“– AWS KMS - Key management - πŸ“– EBS Encryption - Volume encryption - πŸ“– S3 Encryption - Encryption options

Patch Management - Systems Manager Patch Manager - Patch baselines (OS-specific) - Maintenance windows for scheduling - Patch compliance reporting - πŸ“– Patch Manager Guide - Patching workflow - πŸ“– Patch Baselines - Baseline rules - πŸ“– Maintenance Windows - Scheduling

AWS Config - Resource configuration tracking - Compliance rules (managed + custom) - Remediation actions - πŸ“– Config Documentation - πŸ“– Config Rules - Compliance evaluation - πŸ“– Remediation Actions - Automated fixes

Networking & Content Delivery (18%)

VPC - Subnets (public/private) - Route tables - Internet Gateway, NAT Gateway - Security Groups (stateful) - NACLs (stateless) - VPC Flow Logs - πŸ“– VPC Documentation - πŸ“– VPC Subnets - Subnet configuration - πŸ“– Security Groups - Instance firewall - πŸ“– Network ACLs - Subnet firewall - πŸ“– VPC Flow Logs - Traffic logging

Route 53 - DNS service - Routing policies: Simple, weighted, latency, failover, geolocation, geoproximity, multivalue - Health checks with failover - πŸ“– Route 53 Documentation - πŸ“– Routing Policies - Policy types - πŸ“– Health Checks - Failover configuration

CloudFront - Global CDN - Origin: S3, ALB, custom HTTP - Edge caching with TTL - Signed URLs/cookies for private content - πŸ“– CloudFront Documentation - πŸ“– Cache Behavior - Caching configuration - πŸ“– Signed URLs - Private content

Elastic Load Balancing - ALB: Layer 7, HTTP/HTTPS, host/path routing - NLB: Layer 4, TCP/UDP, ultra-low latency, static IPs - Health checks - Target groups - Cross-zone load balancing - πŸ“– ELB Documentation - πŸ“– ALB Guide - Application Load Balancer - πŸ“– NLB Guide - Network Load Balancer - πŸ“– Health Checks - Target health

Cost & Performance Optimization (12%)

Cost Management - Cost Explorer: Analyze spending - Budgets: Set alerts - Savings Plans: Up to 72% savings - Reserved Instances: 1 or 3 year - Spot Instances: Up to 90% savings - πŸ“– Cost Management Documentation - πŸ“– Cost Explorer - Cost analysis - πŸ“– AWS Budgets - Budget alerts - πŸ“– Savings Plans - Flexible pricing

Rightsizing - Compute Optimizer recommendations - CloudWatch metrics analysis - AWS Trusted Advisor checks - πŸ“– Compute Optimizer Documentation - πŸ“– Trusted Advisor - Best practice checks - πŸ“– Rightsizing Guide - Instance resizing

S3 Optimization - Storage classes: Standard, IA, One Zone-IA, Glacier, Deep Archive - Intelligent-Tiering for automatic optimization - Lifecycle policies - Request metrics for optimization - πŸ“– S3 Storage Classes - Class comparison - πŸ“– S3 Lifecycle - Lifecycle rules - πŸ“– S3 Intelligent-Tiering - Automatic optimization

Performance Monitoring - CloudWatch metrics for bottlenecks - X-Ray for distributed tracing - VPC Flow Logs for network analysis - EBS IOPS and throughput optimization - πŸ“– X-Ray - Application tracing - πŸ“– EBS Performance - Volume types and performance

Common SysOps Tasks

Instance Management

  • Launch instances with user data
  • Configure CloudWatch Agent for detailed monitoring
  • Implement auto-recovery for instance failures
  • Schedule instance start/stop with Lambda + EventBridge
  • Apply patches with Systems Manager

Backup Strategy

  • Automated EBS snapshots with lifecycle policies
  • S3 versioning and lifecycle rules
  • RDS automated backups and manual snapshots
  • AWS Backup for centralized management
  • Cross-region backup copies for DR

Security Hardening

  • Enable EBS encryption by default
  • Enforce S3 encryption with bucket policies
  • Implement least privilege IAM policies
  • Enable MFA for privileged users
  • Regular security audits with Config and Security Hub

Network Troubleshooting

  • VPC Flow Logs to analyze traffic
  • Reachability Analyzer for path testing
  • Security Group and NACL rule verification
  • Route table configuration check
  • DNS resolution with Route 53 query logging

Monitoring & Alerting

  • CloudWatch alarms for critical metrics
  • SNS notifications for alerts
  • EventBridge rules for automated responses
  • CloudWatch Logs Insights for log analysis
  • Custom metrics for application monitoring

Exam Tips

Hands-On Focus

  • SOA-C02 includes lab-based questions
  • Must demonstrate actual AWS console/CLI skills
  • Practice in real AWS environment essential

Common Scenarios

  • Troubleshoot failing Auto Scaling groups
  • Restore from backups after data loss
  • Optimize costs for EC2 and storage
  • Configure CloudWatch alarms and dashboards
  • Implement automated patching
  • Resolve network connectivity issues
  • Set up cross-region DR

Question Keywords

  • "Automate" β†’ Systems Manager, EventBridge, Lambda
  • "Monitor" β†’ CloudWatch, X-Ray, VPC Flow Logs
  • "Cost-effective" β†’ Savings Plans, Spot, rightsizing, S3 lifecycle
  • "High availability" β†’ Multi-AZ, Auto Scaling, ELB
  • "Secure" β†’ Encryption, IAM roles, least privilege
  • "Troubleshoot" β†’ CloudWatch Logs, VPC Flow Logs, CloudTrail

Essential Documentation

Core Resources

Hands-On Labs

Final Checklist

Knowledge

  • Configure CloudWatch monitoring and alarms
  • Implement Auto Scaling with health checks
  • Design backup and DR strategies
  • Troubleshoot networking issues
  • Optimize costs using various AWS tools
  • Automate operations with Systems Manager
  • Implement security best practices
  • Deploy with CloudFormation

Skills

  • AWS Console proficiency
  • AWS CLI experience
  • Systems administration experience
  • Networking fundamentals
  • Scripting (Python, Bash, PowerShell)

Preparation

  • 1+ year AWS SysOps experience
  • Hands-on with all core services
  • Practiced lab scenarios
  • Completed practice exams (80%+)

Pro Tip: SOA-C02 is the most hands-on AWS Associate exam. You MUST have practical experience - you'll need to perform tasks in a live AWS environment during the exam. Focus on automation, monitoring, and troubleshooting!

Good luck! πŸš€