Blog

SOA-C03 study guide: domains, format and a 6-week plan

· 8 min read

SOA-C03, the AWS Certified CloudOps Engineer – Associate exam, checks that you can deploy, manage and operate workloads on AWS: monitor them, keep them available, automate their provisioning, secure them and troubleshoot their networks. It replaced the AWS Certified SysOps Administrator – Associate (SOA-C02) exam. You sit 65 questions in 130 minutes, at a Pearson VUE test centre or online.

SOA-C03 at a glance

ProviderAmazon Web Services
LevelAssociate
Questions65 (50 scored, 15 unscored)
Duration130 minutes
Passing score720 on a scale of 100–1,000
Exam fee (USD)$150
LanguagesEnglish, Japanese, Korean, Simplified Chinese
DeliveryPearson VUE test centre or online proctored
Question formatsMultiple choice, multiple response

Details as of September 2026 — confirm on the official exam page before booking.

AWS has announced that the Korean and Simplified Chinese versions of the exam retire after 19 November 2026, so candidates planning to sit in either language should check the page before scheduling.

What changed from SOA-C02

The last day to take SOA-C02 was 29 September 2025, and SOA-C03 has been in use since 30 September 2025. AWS renamed the certification at the same time; the new name applies only to people who pass SOA-C03, so existing SysOps Administrator holders keep their original title. AWS's official comparison shows the old Cost and Performance Optimization domain folded into Domain 1, Reliability and Deployment each growing to 22%, and new content on the CloudWatch agent for ECS and EKS clusters, the AWS CDK, enforcing Region and service restrictions, and CloudWatch network monitoring. The SOA-C03 exam guide lists only multiple choice and multiple response questions, so there are no hands-on exam labs to prepare for.

Who this exam is for

The exam guide describes the target candidate as a CloudOps engineer with one year of experience with deployment, management, troubleshooting, networking and security on AWS, plus at least one year in a related operations role such as system administrator. It expects familiarity with a scripting language, a major operating system, container basics, CI/CD and Git, and working knowledge of the console, the AWS CLI, CloudFormation and infrastructure as code.

There is no prerequisite certification. The guide's out-of-scope list is just as useful: designing distributed architectures, designing CI/CD pipelines, designing hybrid and multi-VPC networks, developing software, and analysing total cost of ownership. The exam asks you to implement, operate and fix. If you want the design angle, the [SAA-C03 study guide](/blog/saa-c03-study-guide) covers the Solutions Architect exam; if you want to go further into pipelines and automation, the [DOP-C02 study guide](/blog/dop-c02-study-guide) covers the professional DevOps exam.

What the exam covers

The guide has five domains. The first three carry 22% each, so two-thirds of the scored content is monitoring, reliability and automation.

Domain 1: Monitoring, Logging, Analysis, Remediation, and Performance Optimization (22%)

This is CloudWatch in depth: metrics, logs, metric filters, composite alarms, cross-account and cross-Region dashboards, and the CloudWatch agent on EC2, ECS and EKS. Add CloudTrail, Amazon Managed Service for Prometheus, SNS notifications and EventBridge rules, including why a rule does not fire. The remediation half asks how to fix problems automatically with Systems Manager Automation runbooks, Lambda and auto scaling. The performance half covers choosing EBS volume types, S3 transfer options (DataSync, Transfer Acceleration, multipart upload), EFS and FSx, RDS Performance Insights and RDS Proxy, and EC2 placement groups. The judgement tested is reading a symptom and choosing the smallest change that fixes it.

Domain 2: Reliability and Business Continuity (22%)

Expect scaling in compute and managed databases (RDS read replicas, DynamoDB capacity), caching with CloudFront and ElastiCache, and highly available designs using Multi-AZ, Elastic Load Balancing and Route 53 health checks, including why a health check reports a healthy target as unhealthy. Backup and restore is a large part: AWS Backup plans, snapshots, point-in-time restore, versioning on S3 and FSx, and matching a restore method to a stated RTO, RPO and budget.

Domain 3: Deployment, Provisioning, and Automation (22%)

This domain covers AMIs and container images with EC2 Image Builder, stacks with CloudFormation and the AWS CDK, sharing resources across accounts and Regions with AWS Resource Access Manager and CloudFormation StackSets, deployment strategies, and third-party tools such as Terraform and Git. A recurring theme is troubleshooting a failed deployment: a subnet too small for the resources, a CloudFormation stack stuck in rollback, a missing permission. The automation task covers Systems Manager for routine operations and event-driven automation with Lambda and S3 Event Notifications.

Domain 4: Security and Compliance (16%)

Here the exam checks IAM features (roles, federation, MFA, password policies, resource policies and condition keys) and how to troubleshoot access with CloudTrail, IAM Access Analyzer and the IAM policy simulator. It covers multi-account strategy, enforcing Region and service restrictions, and remediating Trusted Advisor findings. The data-protection task asks about data classification, encryption at rest with AWS KMS, encryption in transit with AWS Certificate Manager, storing secrets, and acting on findings from Security Hub, GuardDuty, AWS Config and Amazon Inspector.

Domain 5: Networking and Content Delivery (18%)

Know VPC building blocks thoroughly: subnets, route tables, network ACLs, security groups, NAT gateways, internet and egress-only internet gateways, private connectivity and transit gateways. You also audit network protection services (Route 53 Resolver DNS Firewall, AWS WAF, AWS Shield, AWS Network Firewall), configure Route 53 routing policies and query logging, and distribute content with CloudFront and AWS Global Accelerator. The troubleshooting task is the heart of the domain: reading VPC flow logs, ELB access logs, WAF and CloudFront logs to find why traffic is blocked, why content is stale, or why a hybrid link is failing.

A 6-week study plan

The plan follows the weights and puts troubleshooting practice in every week, because most questions describe a broken or inefficient setup.

Week 1: Domain 1, monitoring and logging. Build alarms, metric filters and a dashboard in a practice account. Install the CloudWatch agent on an instance and send custom metrics and logs. Write an EventBridge rule that triggers a Lambda function, then break it deliberately and fix it.

Week 2: Domain 1, remediation and performance. Run a Systems Manager Automation runbook, compare EBS volume types, and learn when to reach for DataSync, Transfer Acceleration, EFS or FSx. Study RDS Performance Insights and RDS Proxy. Finish with a Domain 1 paper and read every explanation.

Week 3: Domain 2. Configure an Auto Scaling group behind a load balancer and watch it scale. Set up Route 53 health checks and failover. Create an AWS Backup plan, restore a database to a point in time, and write down the RTO and RPO each method gives. Take a Domain 2 paper.

Week 4: Domain 3. Deploy the same small stack with CloudFormation and the CDK, then share it across accounts with StackSets. Build an AMI with EC2 Image Builder. Collect the CloudFormation error messages you meet and what caused each. Take a Domain 3 paper.

Week 5: Domains 4 and 5. Split the week between IAM troubleshooting with the policy simulator and Access Analyzer, KMS and ACM, and the VPC. Build a VPC by hand with public and private subnets, then diagnose connectivity from flow logs. Take a paper for each domain.

Week 6: Full mocks. Sit a full-length mock under exam conditions, review it thoroughly, fix the weakest topics, and sit a second mock two or three days later. Our guide on [using practice exams effectively](/blog/how-to-use-practice-exams-effectively) explains how to review a mock so it improves your next score.

Common traps

  • Choosing a design answer on an operations exam. When one option rebuilds the architecture and another changes a setting, the question usually wants the operational fix. Re-read the constraint.
  • Confusing security groups and network ACLs. Security groups are stateful and allow only; network ACLs are stateless, evaluated in rule-number order, and need return traffic allowed explicitly. Many connectivity questions turn on that difference.
  • Treating CloudTrail and CloudWatch as interchangeable. CloudTrail records who called which API; CloudWatch holds metrics and logs; AWS Config records resource configuration over time. Distractors often put a real service on the wrong job.
  • Missing the automation angle. If a question says a fix must happen every time or without manual steps, look for EventBridge, Systems Manager Automation or Lambda rather than a one-off console change.
  • Misreading RTO and RPO. RPO is how much data you can lose; RTO is how long you can be down. Snapshots every 24 hours cannot meet a one-hour RPO, however cheap they are.
  • Partial answers on multiple response. Read how many options the question asks for and check each one; a multiple response question counts as a single scored opportunity.

How to practise

CertifyCloudx has original SOA-C03 practice questions written against the current exam guide, with every option explained. You can read [how our questions are written](/blog/how-certifycloudx-practice-questions-are-written) for the details of our method.

  • Full-length timed mock exams, 65 questions in 130 minutes, the same as the real exam
  • Domain papers of up to 25 questions each (60 minutes per 25)
  • A free plan with practice sets for every certification, up to 10 questions a day, no card needed

Start with the [SOA-C03 practice questions](/certifications/aws-cloudops-engineer-associate-soa-c03).

Frequently asked questions

How difficult is SOA-C03?

It is an associate exam, but many candidates find it demanding because questions describe a working environment with a problem and ask for the precise fix. AWS recommends a year of hands-on experience on AWS plus a year in an operations role, and the questions reward that experience.

Does SOA-C03 have exam labs?

No. The exam guide lists two question types, multiple choice and multiple response, across 65 questions. Hands-on practice still helps, because questions assume you know how services behave.

How long should I prepare for SOA-C03?

With a year of operations work on AWS, six weeks of regular study is a realistic range. If you are new to CloudWatch, Systems Manager or VPC troubleshooting, allow longer and spend the extra time in a practice account.

I hold the SysOps Administrator certification. Does it become CloudOps Engineer?

No. AWS has said the new name applies only to people who pass SOA-C03; existing SysOps Administrator holders keep their original title. The certification is valid for three years.

Is there a penalty for guessing?

No. AWS scores unanswered questions as incorrect and applies no penalty for guessing, so answer every question. Fifteen of the 65 questions are unscored and are not identified.

CertifyCloudx is independent and not affiliated with Amazon Web Services. AWS Certified CloudOps Engineer – Associate is a trademark of its owner. All CertifyCloudx practice questions are original.

Practise for this exam
AWS Certified CloudOps Engineer – Associate (SOA-C03)
See practice papers
SOA-C03 study guide: domains, format and a 6-week plan · CertifyCloudx