HomeRoadmaps › AWS SOA-C03
Active associate certification roadmap

AWS Certified CloudOps Engineer - Associate

A five-phase path for SOA-C03 across CloudWatch, Systems Manager, EventBridge, CloudFormation and CDK, IAM and multi-account operations, AWS Backup, Auto Scaling, databases, VPC troubleshooting, Route 53, CloudFront, security, cost, and recovery.

Exam code: SOA-C03Five official domainsSuggested plan: 10–14 weeksUpdated: August 19, 2026
Current exam: SOA-C03 replaced SOA-C02 on September 30, 2025. The active name is AWS Certified CloudOps Engineer - Associate, not AWS Certified SysOps Administrator - Associate. Verify the official AWS certification page, exam guide, revisions, in-scope list, and service documentation before scheduling because details can change.

Official SOA-C03 outline

AWS describes a CloudOps engineer who deploys, manages, operates, secures, monitors, troubleshoots, and recovers workloads. The target candidate has about one year of AWS deployment, management, troubleshooting, networking, and security experience plus a year in a related operations role. The exam uses multiple-choice and multiple-response questions, includes 50 scored and 15 unscored questions, and reports a scaled score from 100 to 1,000 with 720 as the minimum passing score.

Official content domainWeight
Monitoring, Logging, Analysis, Remediation, and Performance Optimization22%
Reliability and Business Continuity22%
Deployment, Provisioning, and Automation22%
Security and Compliance16%
Networking and Content Delivery18%

Do not study from the old SOA-C02 map

SOA-C02 ended September 29, 2025 and used six domains. In SOA-C03, the former Cost and Performance Optimization tasks moved into Domain 1, while Reliability and Deployment each increased to 22%. AWS added explicit coverage for CloudWatch agent management across EC2, ECS, and EKS; CloudFormation and AWS CDK resource management; enforcement of Region and service selections; and CloudWatch network monitoring. VPN content moved into networking, and S3 static website hosting was removed. Existing SOA-C02 knowledge remains useful only after remapping it to the current task statements.

1

Observe, analyze, optimize, and remediate

Weeks 1–3

Build evidence-driven diagnosis first. A CloudOps answer should connect customer symptoms to metrics, logs, traces, API events, network evidence, and safe remediation.

  • Configure default, detailed, custom, and high-resolution CloudWatch metrics deliberately
  • Deploy and troubleshoot the unified CloudWatch agent on EC2 and current container patterns
  • Use Logs Insights, metric filters, dashboards, alarms, composite alarms, SNS, and retention controls
  • Create cross-account observability with OAM sinks and source links
  • Distinguish CloudTrail API activity, Config history, service logs, application logs, and VPC Flow Logs
  • Route and troubleshoot events with EventBridge rules, buses, Pipes, Scheduler, retries, and DLQs
  • Run predefined and custom Systems Manager Automation runbooks with rate and permission controls
  • Diagnose EC2, EBS, S3 transfer/storage, EFS/FSx, RDS, connection, and placement performance
  • Measure cost with the performance signal instead of treating cost as a retired sixth domain
  • Inject CPU, memory, disk, connection, no-data, permission, and target-delivery failures
2

Engineer reliability and business continuity

Weeks 4–6

Separate elasticity, availability, and data recovery. They solve different failure modes and have different costs.

  • Configure EC2 Auto Scaling target tracking, scheduled actions, warm-up, health checks, and mixed capacity where appropriate
  • Use CloudFront or ElastiCache for justified caching and understand managed database scaling
  • Operate ALB/NLB health, target registration, connection draining, and Route 53 health checks
  • Implement Multi-AZ compute and database patterns and test actual failover behavior
  • Define RTO and RPO for each application dependency
  • Create AWS Backup plans, assignments, lifecycle, vault, copy, monitoring, and compliance controls
  • Protect supported recovery points across Regions and accounts and evaluate Vault Lock carefully
  • Use S3 and supported file-system versioning where requirements call for object/version recovery
  • Compare backup/restore, pilot light, warm standby, and active/active from RTO, RPO, and cost
  • Restore data and applications in isolation and measure end-to-end recovery, not only job completion
3

Provision, deploy, patch, and automate

Weeks 7–9

Make operations repeatable through versioned artifacts, infrastructure as code, controlled deployment, and fleet automation.

  • Build and distribute tested AMIs and container images with EC2 Image Builder
  • Create and update resources with CloudFormation and understand AWS CDK synthesis and deployment
  • Review change sets, stack events, rollback, drift, imports, dependencies, and replacement behavior
  • Deploy baselines across accounts and Regions with StackSets and share supported resources with AWS RAM
  • Compare rolling, immutable, blue/green, canary, and instance-refresh deployment strategies
  • Use Git and a reviewed Terraform plan/state workflow when third-party IaC is a stated requirement
  • Onboard managed nodes through Systems Manager without routine inbound SSH
  • Use Quick Setup patch policies, custom baselines, canaries, scan/install schedules, hooks, and compliance timestamps
  • Automate existing-resource operations with Run Command, State Manager, Inventory, OpsCenter, and Automation
  • Design every event-driven action for idempotency, least privilege, retries, timeouts, DLQs, and rollback
4

Secure identities, data, infrastructure, and compliance

Weeks 10–11

Troubleshoot the complete authorization path and combine preventive, detective, and responsive controls across accounts.

  • Operate IAM roles, federation, MFA, password policies, resource policies, conditions, boundaries, and temporary credentials
  • Use CloudTrail, IAM Access Analyzer, and policy simulation to diagnose access rather than adding administrator access
  • Implement Organizations, SCPs, delegated administration, and IAM Identity Center permission sets safely
  • Enforce approved Region and service selections with tested exceptions and rollback
  • Record and assess compliance with Config rules, organization conformance packs, and read-only aggregators
  • Classify data and protect it with KMS, S3 controls, ACM/TLS, Secrets Manager, or Parameter Store as appropriate
  • Trace SSE-KMS access through identity, bucket, key, grant, condition, and explicit-deny layers
  • Review Trusted Advisor, Security Hub, GuardDuty, Inspector, Config, and current security finding workflows
  • Automate reversible quarantine or remediation while preserving evidence and human approval for impact
  • Audit root use, policy changes, key changes, backup changes, and failed authorization
5

Operate networks, incidents, recovery, and exam readiness

Weeks 12–14

Finish with end-to-end path troubleshooting and game days that combine all five domains.

  • Configure subnets, routes, internet/NAT/egress-only gateways, endpoints, PrivateLink, peering, security groups, and NACLs
  • Audit DNS Firewall, WAF, Shield, and Network Firewall configurations within the stated scope
  • Optimize NAT, endpoint, cross-AZ, cross-Region, and internet data paths for cost and reliability
  • Configure Route 53 public/private DNS, Resolver, routing policies, health, and query logging
  • Operate CloudFront and Global Accelerator from protocol, cache, routing, health, and performance requirements
  • Troubleshoot with VPC Flow Logs, ELB logs, WAF logs, CloudFront logs, container logs, and CloudWatch network monitoring
  • Diagnose hybrid and private connectivity without assuming the first observed deny is the root cause
  • Resolve stale CloudFront content with cache-key/TTL analysis, urgent invalidation, and versioned objects
  • Run patch, backup, restore, failover, alarm, runbook, IAM-denial, blocked-flow, DNS, and cache game days
  • Complete fresh mixed-domain scenarios and explain why every distractor fails the requirement

PrepKloud SOA-C03 study surfaces

Official AWS sources

Certification page

Verify active exam positioning, logistics, and official preparation links.

Open AWS Certification
SOA-C03 exam guide

Use the five domains, task statements, weights, target candidate, and scoring details.

Open the official guide
SOA-C02 comparison

Confirm additions, deletions, recategorizations, and transition dates.

Open the comparison
CloudWatch

Review agent collection, alarms, logs, dashboards, and cross-account observability.

Open CloudWatch documentation
Systems Manager

Review managed nodes, Automation, Patch Manager, Quick Setup, and operations tools.

Open Systems Manager documentation
AWS Backup

Review plans, copies, vault security, monitoring, compliance, and restore testing.

Open AWS Backup documentation

Frequently asked questions

Is SOA-C03 the active AWS operations exam?

Yes. It is active as of August 19, 2026. AWS states that SOA-C03 began September 30, 2025 and SOA-C02 ended the previous day. Always verify the official page before scheduling.

What are the domain weights?

Domains 1, 2, and 3 are each 22%; Security and Compliance is 16%; Networking and Content Delivery is 18%.

What changed from SOA-C02?

The name changed to CloudOps Engineer, six domains became five, former cost/performance work moved to Domain 1, several current operational skills were added, VPN moved into networking, and S3 static website hosting was removed.

How should practical readiness be measured?

Measure whether you can diagnose fresh failures, explain service trade-offs, safely automate remediation, restore within stated RTO/RPO, trace authorization and network paths, and perform consistently across new mixed-domain scenarios.

Are these materials exam dumps?

No. They are original educational materials based on public objectives and official AWS documentation. PrepKloud does not reproduce live or recalled questions and does not guarantee a pass or career outcome.

Integrity and independence: Use official documentation, original practice, and hands-on labs. Do not seek, share, or memorize recalled live-exam content. PrepKloud is independent and is not affiliated with or endorsed by Amazon Web Services. AWS service and certification names belong to their respective owner.

Turn the SOA-C03 blueprint into operating evidence

Diagnose gaps, retrieve key distinctions, then build and break both CloudOps projects.