DOP-C02 study guide: domains, format and a 6-week plan
· 8 min read
DOP-C02, the AWS Certified DevOps Engineer – Professional exam, tests whether you can provision, operate and manage distributed systems on AWS with automation doing the heavy lifting. You sit 75 questions in 180 minutes, at a Pearson VUE test centre or online, and most questions are long scenarios where several answers would work but only one fits every stated constraint.
DOP-C02 at a glance
| Provider | Amazon Web Services |
| Level | Professional |
| Questions | 75 (65 scored, 10 unscored) |
| Duration | 180 minutes |
| Passing score | 750 on a scale of 100–1,000 |
| Exam fee (USD) | $300 |
| Languages | English, Japanese, Korean, Simplified Chinese |
| Delivery | Pearson VUE test centre or online proctored |
| Question formats | Multiple choice, multiple response |
Details as of September 2026 — confirm on the official exam page before booking.
AWS has announced that the Korean version of the exam retires after 31 December 2026. AWS has not announced a successor or retirement date for DOP-C02 itself. The certification is valid for three years, and you recertify by passing the latest version of the exam.
Who this exam is for
AWS describes the target candidate as someone with two or more years of experience provisioning, operating and managing AWS environments, who also has experience with the software development lifecycle and with programming or scripting. The exam guide adds experience building highly automated infrastructure, administering operating systems, working with modern development and operations processes, and securing AWS infrastructure.
There is no prerequisite certification, but most candidates arrive with an associate-level background. If you are coming from operations, the [SOA-C03 study guide](/blog/soa-c03-study-guide) covers the CloudOps Engineer – Associate exam, which overlaps heavily with Domains 4 and 5 here.
The guide also lists what is out of scope: advanced networking such as routing algorithms, deep-level security recommendations for developers, designing and tuning databases, and writing full-stack application code.
What the exam covers
The exam guide has six domains. SDLC Automation is the largest single domain, but the other five are close in weight, so there is no domain you can safely skip.
Domain 1: SDLC Automation (22%)
Expect questions on AWS CodePipeline, CodeBuild and CodeDeploy; single- and multi-account pipeline patterns; managing build secrets with AWS Secrets Manager or Systems Manager Parameter Store; and placing the right tests (unit, integration, acceptance, security scans, load tests) at the right stage. It also covers artifact repositories (AWS CodeArtifact, Amazon S3, Amazon ECR), automated image builds with EC2 Image Builder, and deployment strategies across EC2, ECS, EKS and Lambda. The judgement tested is matching a deployment strategy to a stated risk tolerance.
Domain 2: Configuration Management and IaC (17%)
Here you compose and deploy templates with AWS CloudFormation, AWS SAM and the AWS CDK, roll them out across accounts and Regions with StackSets, and package governance into reusable components with AWS Service Catalog and CloudFormation modules. The second half is multi-account: AWS Organizations, AWS Control Tower, service control policies, cross-account roles, and automated account provisioning. The third task covers automating inventory, patching and desired-state configuration with Systems Manager, AWS Config and Lambda or Step Functions. The exam guide still names AWS OpsWorks, but AWS ended OpsWorks Stacks in May 2024 and points customers to Systems Manager, so learn Systems Manager State Manager and Application Manager as the current answer for configuration management.
Domain 3: Resilient Cloud Solutions (15%)
Know Multi-AZ and multi-Region patterns for compute and data, cross-Region features of DynamoDB, RDS, Aurora, Route 53, S3 and CloudFront, and how to remove single points of failure. Scaling questions cover auto scaling metrics, serverless and containers. Recovery questions tie RTO and RPO to a strategy: backup and restore, pilot light, warm standby or multi-site, implemented with AWS Backup, S3 replication and Route 53 failover.
Domain 4: Monitoring and Logging (15%)
Expect detailed Amazon CloudWatch questions: namespaces, dimensions and resolution; metric filters; metric streams to Amazon Data Firehose; the CloudWatch agent for custom metrics; log retention and S3 lifecycles; subscription filters to Kinesis, Lambda or Amazon OpenSearch Service; and CloudWatch Logs Insights. The analysis task adds anomaly detection alarms, AWS X-Ray tracing, Amazon Athena queries over logs, CloudTrail events and AWS Config rules. The automation task covers EventBridge rules, health checks, auto scaling for different services and installing agents at scale with SSM Agent.
Domain 5: Incident and Event Response (14%)
You need to know which services generate events (AWS Health, EventBridge, CloudTrail), how to build processing workflows with SQS, SNS, Kinesis, Lambda and Step Functions, and how to change configuration automatically in response to an event using Systems Manager, Auto Scaling and AWS Config remediation. The troubleshooting task is practical: reading why a CodePipeline stage, CodeBuild job, CodeDeploy deployment or CloudFormation stack failed, and finding the root cause of auto scaling, ECS or EKS failures, with tools such as Systems Manager OpsCenter and CloudWatch synthetic monitoring.
Domain 6: Security and Compliance (17%)
Identity at scale comes first: users, groups and roles; identity-based, resource-based and session policies; federation with AWS IAM Identity Center; permissions boundaries; SCPs; and role- and attribute-based access control. Data protection covers AWS KMS, CloudHSM, ACM, Amazon Macie, network controls (security groups, network ACLs, AWS Network Firewall, AWS WAF, Shield) and applying controls across accounts with Security Hub and Control Tower. Auditing covers CloudTrail, AWS Config, VPC Flow Logs, drift detection, GuardDuty, Amazon Inspector and IAM Access Analyzer, plus alerting on threats such as exposed access keys.
A 6-week study plan
The plan assumes eight to ten hours a week and some hands-on AWS access. Keep a running list of every question you get wrong, with the reason; you will use it in Week 6. The [study plan template](/blog/cloud-certification-study-plan-template) shows how to adapt this structure to your own schedule.
Week 1: Domain 1, pipelines. Build a pipeline end to end in a sandbox account: source, CodeBuild with a buildspec, a test stage and CodeDeploy to EC2 or ECS. Try a blue/green deployment with automatic rollback. Finish with a Domain 1 paper.
Week 2: Domain 1 continued, then Domain 2. Cover artifact repositories, EC2 Image Builder and Lambda deployment preferences in the first half. Then move to CloudFormation: change sets, stack policies, custom resources, helper scripts, StackSets and the CDK. Take a Domain 1 paper and a first Domain 2 paper.
Week 3: Domain 2 multi-account, and Domain 6 identity. Study Organizations, Control Tower, SCPs, Service Catalog and cross-account roles together with IAM policy evaluation, permissions boundaries and Identity Center, because the exam mixes them. Finish with papers for both domains.
Week 4: Domains 4 and 5. Work through CloudWatch metrics, alarms, logs, subscriptions and Logs Insights, then EventBridge patterns and automated remediation with AWS Config and Systems Manager Automation. Practise reading failure messages from each deployment service. Take a paper for each domain.
Week 5: Domain 3 and the rest of Domain 6. Map each disaster recovery strategy to its RTO, RPO and cost, and each data service to its cross-Region option. Then cover KMS key policies, Macie, GuardDuty, Security Hub and Inspector. Take your first full-length mock under exam conditions at the end of the week.
Week 6: Mocks and repair. Review the first mock option by option and use your wrong-answer list to fix the weakest topics. Sit a second mock mid-week and a third two or three days before the exam. See [how to use practice exams effectively](/blog/how-to-use-practice-exams-effectively) for a review method that turns wrong answers into study targets.
Common traps
- Answers that work but break a constraint. Professional questions add qualifiers such as "least operational overhead", "without downtime" or "most cost-effective". Two options often solve the problem; only one respects every qualifier.
- Choosing a custom Lambda script over a managed feature. If AWS Config remediation, a CodeDeploy rollback setting or a Systems Manager Automation runbook does the job, a hand-written function is usually the distractor.
- Mixing up deployment behaviour by platform. Canary and linear options differ between Lambda, ECS and EC2 in CodeDeploy, and in-place is not available for Lambda or ECS. Learn which configurations each platform supports.
- Confusing SCPs, permissions boundaries and identity policies. SCPs and boundaries only limit permissions; they never grant them. A question where a user still cannot act after an allow is added is often about one of these.
- Mismatching detection and audit services. CloudTrail records API calls, AWS Config records resource configuration, GuardDuty detects threats, Inspector scans for vulnerabilities, Macie finds sensitive data, Security Hub aggregates findings.
- Running out of time. 180 minutes for 75 long scenarios is just under two and a half minutes each. Flag anything that takes longer and come back to it; unanswered questions score as incorrect and there is no penalty for guessing.
How to practise
CertifyCloudx has original DOP-C02 practice questions written against the current exam guide, covering all six domains, with an explanation for every option. You can read [how our questions are written](/blog/how-certifycloudx-practice-questions-are-written) for the detail of our method.
- Domain papers of up to 25 questions (60 minutes per 25)
- Full-length timed mock exams, 75 questions in 180 minutes, the same as the real exam
- Progress tracked by domain and topic
- Free practice sets, up to 10 questions a day, with no card required
Start with the [DOP-C02 practice questions](/certifications/aws-devops-engineer-professional-dop-c02).
Frequently asked questions
How difficult is DOP-C02?
It is a professional-level AWS exam and is widely regarded as demanding. The difficulty comes from long multi-domain scenarios, options that differ by one detail, and three hours of sustained concentration.
How long should I prepare for DOP-C02?
With two or more years of hands-on AWS work and an associate certification, six weeks of steady study is a realistic plan. If CI/CD pipelines or multi-account governance are new to you, allow longer and spend the extra time building things rather than reading.
Do I need an associate certification first?
No. There is no prerequisite. AWS recommends two or more years of experience provisioning, operating and managing AWS environments, plus experience with the software development lifecycle and programming or scripting.
Is AWS replacing DOP-C02?
AWS has not announced a successor or retirement date for DOP-C02 as of September 2026. The Korean version of the exam retires after 31 December 2026, so Korean-language candidates should check the official page before booking.
Are CertifyCloudx questions real DOP-C02 exam questions?
No. Every CertifyCloudx question is original and written against the public exam guide. Using real exam content breaks the AWS candidate agreement and can cost you the certification. See [why exam dumps put your certification at risk](/blog/why-exam-dumps-put-your-certification-at-risk).
CertifyCloudx is independent and not affiliated with Amazon Web Services. AWS Certified DevOps Engineer – Professional is a trademark of its owner. All CertifyCloudx practice questions are original.