Understanding SOA-C03 Domains and Exam Guide
Explore the five core domains of the AWS Certified CloudOps Engineer Associate exam including monitoring, reliability, deployment automation, security, and networking. Understand how these areas reflect real-world operational responsibilities on AWS and prepare effectively for the exam’s structure and question types.
We'll cover the following...
Welcome to your starting point for mastering the AWS Certified CloudOps Engineer – Associate (SOA-C03) exam! If you’ve kept an AWS workload running smoothly, configured a CloudWatch alarm that caught a problem before it escalated, or automated a remediation step with Systems Manager, you’re already on your way. This certification validates a CloudOps engineer’s ability to deploy, manage, and operate workloads on AWS that are secure, reliable, and well instrumented.
The exam is structured around five core domains that mirror the real-world responsibilities of running AWS workloads in production: monitoring and remediation, reliability, deployment and automation, security, and networking.
Exam domains
The exam domains represent the key skill areas AWS expects every CloudOps engineer to master. Each domain corresponds to real-world responsibilities we’ll encounter when operating and supporting applications on AWS. Let’s take a quick look at the types of tasks and knowledge each domain covers before we explore further:
Monitoring, logging, analysis, remediation, and performance optimization: This domain focuses on keeping workloads observable and healthy. We’ll need to be familiar with how to:
Configure metrics, alarms, and log collection using CloudWatch, CloudTrail, and the CloudWatch agent across EC2, ECS, and EKS.
Route and act on alarms and events through EventBridge and Amazon SNS notifications.
Automate issue remediation using Systems Manager Automation runbooks and Lambda.
Analyze and optimize the performance of compute, storage, and database resources, including EBS, S3, EFS/FSx, and RDS.
Reliability and business continuity: This domain emphasizes keeping workloads available and recoverable. We should be comfortable with tasks such as:
Configure scaling mechanisms for compute and managed databases, and use caching to support dynamic scalability.
Configure and troubleshoot Elastic Load Balancing and Route 53 health checks for fault-tolerant, Multi-AZ environments.
Automate backups and snapshots using AWS Backup, and restore resources to meet RTO and RPO targets.
Follow disaster recovery procedures and implement versioning for storage services.
Deployment, provisioning, and automation: This covers provisioning cloud resources and automating their ongoing management. We are expected to:
Create and manage AMIs and container images, including through EC2 Image Builder.
Build and troubleshoot CloudFormation and AWS CDK stacks, including multi-account and multi-Region distribution with StackSets and AWS RAM.
Identify and remediate deployment issues such as subnet sizing, stack failures, or permissions errors.
Automate operational processes and event-driven workflows using Systems Manager, Lambda, and S3 event notifications.
Security and compliance: This domain emphasizes securing accounts, data, and infrastructure. We are expected to:
Implement IAM features such as MFA, roles, federated identity, and policy conditions, and troubleshoot access issues with CloudTrail and IAM Access Analyzer.
Apply multi-account security strategies and enforce compliance requirements, such as Region and service restrictions.
Implement encryption at rest and in transit using AWS KMS and ACM, and store secrets securely.
Remediate findings from Trusted Advisor, Security Hub, GuardDuty, Config, and Inspector.
Networking and content delivery: This domain covers building, securing, and troubleshooting network connectivity. We are expected to:
Configure VPC components such as subnets, route tables, security groups, and NAT gateways, and audit protective services like AWS WAF and Shield.
Configure DNS and Route 53 routing policies, and set up content distribution through CloudFront and Global Accelerator.
Troubleshoot VPC, hybrid, and private connectivity issues using flow logs, ELB access logs, and CloudWatch network monitoring.
The AWS Certified CloudOps Engineer – Associate exam guide consists of five domains. The table below shows the domains and the percentage of scored questions in each domain:
Domain | Weight |
Monitoring, Logging, Analysis, Remediation, and Performance Optimization | 22% |
Reliability and Business Continuity | 22% |
Deployment, Provisioning, and Automation | 22% |
Security and Compliance | 16% |
Networking and Content Delivery | 18% |
We won’t be asked to design distributed architectures, design CI/CD pipelines from scratch, design hybrid or multi-VPC networking, or develop software. Assessing and planning resource capacity and managing billing or total cost of ownership are also outside the expected scope. Our role is focused on operating, securing, and troubleshooting what’s already been architected.
Exam guide
Understanding how the exam is structured helps us better prepare and manage our time during the test. The exam consists of 65 questions: 50 scored and 15 unscored (used for future test development). You’ll have 130 minutes to complete it. The question types are:
Multiple choice (one correct response among four).
Multiple response (two or more correct answers from five or more choices).
The exam is pass/fail, with a scaled score range from 100 to 1,000. We need a minimum of 720 to pass. AWS uses a compensatory scoring model, meaning we don’t need to pass each domain individually; strong performance in one area can offset weaker performance in another.