Official SOA-C03 outline
AWS describes a CloudOps engineer who deploys, manages, operates, secures, monitors, troubleshoots, and recovers workloads. The target candidate has about one year of AWS deployment, management, troubleshooting, networking, and security experience plus a year in a related operations role. The exam uses multiple-choice and multiple-response questions, includes 50 scored and 15 unscored questions, and reports a scaled score from 100 to 1,000 with 720 as the minimum passing score.
| Official content domain | Weight |
|---|---|
| Monitoring, Logging, Analysis, Remediation, and Performance Optimization | 22% |
| Reliability and Business Continuity | 22% |
| Deployment, Provisioning, and Automation | 22% |
| Security and Compliance | 16% |
| Networking and Content Delivery | 18% |
Do not study from the old SOA-C02 map
SOA-C02 ended September 29, 2025 and used six domains. In SOA-C03, the former Cost and Performance Optimization tasks moved into Domain 1, while Reliability and Deployment each increased to 22%. AWS added explicit coverage for CloudWatch agent management across EC2, ECS, and EKS; CloudFormation and AWS CDK resource management; enforcement of Region and service selections; and CloudWatch network monitoring. VPN content moved into networking, and S3 static website hosting was removed. Existing SOA-C02 knowledge remains useful only after remapping it to the current task statements.
Observe, analyze, optimize, and remediate
Weeks 1–3Build evidence-driven diagnosis first. A CloudOps answer should connect customer symptoms to metrics, logs, traces, API events, network evidence, and safe remediation.
- Configure default, detailed, custom, and high-resolution CloudWatch metrics deliberately
- Deploy and troubleshoot the unified CloudWatch agent on EC2 and current container patterns
- Use Logs Insights, metric filters, dashboards, alarms, composite alarms, SNS, and retention controls
- Create cross-account observability with OAM sinks and source links
- Distinguish CloudTrail API activity, Config history, service logs, application logs, and VPC Flow Logs
- Route and troubleshoot events with EventBridge rules, buses, Pipes, Scheduler, retries, and DLQs
- Run predefined and custom Systems Manager Automation runbooks with rate and permission controls
- Diagnose EC2, EBS, S3 transfer/storage, EFS/FSx, RDS, connection, and placement performance
- Measure cost with the performance signal instead of treating cost as a retired sixth domain
- Inject CPU, memory, disk, connection, no-data, permission, and target-delivery failures
Engineer reliability and business continuity
Weeks 4–6Separate elasticity, availability, and data recovery. They solve different failure modes and have different costs.
- Configure EC2 Auto Scaling target tracking, scheduled actions, warm-up, health checks, and mixed capacity where appropriate
- Use CloudFront or ElastiCache for justified caching and understand managed database scaling
- Operate ALB/NLB health, target registration, connection draining, and Route 53 health checks
- Implement Multi-AZ compute and database patterns and test actual failover behavior
- Define RTO and RPO for each application dependency
- Create AWS Backup plans, assignments, lifecycle, vault, copy, monitoring, and compliance controls
- Protect supported recovery points across Regions and accounts and evaluate Vault Lock carefully
- Use S3 and supported file-system versioning where requirements call for object/version recovery
- Compare backup/restore, pilot light, warm standby, and active/active from RTO, RPO, and cost
- Restore data and applications in isolation and measure end-to-end recovery, not only job completion
Provision, deploy, patch, and automate
Weeks 7–9Make operations repeatable through versioned artifacts, infrastructure as code, controlled deployment, and fleet automation.
- Build and distribute tested AMIs and container images with EC2 Image Builder
- Create and update resources with CloudFormation and understand AWS CDK synthesis and deployment
- Review change sets, stack events, rollback, drift, imports, dependencies, and replacement behavior
- Deploy baselines across accounts and Regions with StackSets and share supported resources with AWS RAM
- Compare rolling, immutable, blue/green, canary, and instance-refresh deployment strategies
- Use Git and a reviewed Terraform plan/state workflow when third-party IaC is a stated requirement
- Onboard managed nodes through Systems Manager without routine inbound SSH
- Use Quick Setup patch policies, custom baselines, canaries, scan/install schedules, hooks, and compliance timestamps
- Automate existing-resource operations with Run Command, State Manager, Inventory, OpsCenter, and Automation
- Design every event-driven action for idempotency, least privilege, retries, timeouts, DLQs, and rollback
Secure identities, data, infrastructure, and compliance
Weeks 10–11Troubleshoot the complete authorization path and combine preventive, detective, and responsive controls across accounts.
- Operate IAM roles, federation, MFA, password policies, resource policies, conditions, boundaries, and temporary credentials
- Use CloudTrail, IAM Access Analyzer, and policy simulation to diagnose access rather than adding administrator access
- Implement Organizations, SCPs, delegated administration, and IAM Identity Center permission sets safely
- Enforce approved Region and service selections with tested exceptions and rollback
- Record and assess compliance with Config rules, organization conformance packs, and read-only aggregators
- Classify data and protect it with KMS, S3 controls, ACM/TLS, Secrets Manager, or Parameter Store as appropriate
- Trace SSE-KMS access through identity, bucket, key, grant, condition, and explicit-deny layers
- Review Trusted Advisor, Security Hub, GuardDuty, Inspector, Config, and current security finding workflows
- Automate reversible quarantine or remediation while preserving evidence and human approval for impact
- Audit root use, policy changes, key changes, backup changes, and failed authorization
Operate networks, incidents, recovery, and exam readiness
Weeks 12–14Finish with end-to-end path troubleshooting and game days that combine all five domains.
- Configure subnets, routes, internet/NAT/egress-only gateways, endpoints, PrivateLink, peering, security groups, and NACLs
- Audit DNS Firewall, WAF, Shield, and Network Firewall configurations within the stated scope
- Optimize NAT, endpoint, cross-AZ, cross-Region, and internet data paths for cost and reliability
- Configure Route 53 public/private DNS, Resolver, routing policies, health, and query logging
- Operate CloudFront and Global Accelerator from protocol, cache, routing, health, and performance requirements
- Troubleshoot with VPC Flow Logs, ELB logs, WAF logs, CloudFront logs, container logs, and CloudWatch network monitoring
- Diagnose hybrid and private connectivity without assuming the first observed deny is the root cause
- Resolve stale CloudFront content with cache-key/TTL analysis, urgent invalidation, and versioned objects
- Run patch, backup, restore, failover, alarm, runbook, IAM-denial, blocked-flow, DNS, and cache game days
- Complete fresh mixed-domain scenarios and explain why every distractor fails the requirement
PrepKloud SOA-C03 study surfaces
Diagnose gaps with 25 original, weighted, current-domain scenarios. Flashcards
Retrieve operational distinctions without relying on answer recognition. Portfolio projects
Build multi-account observability and automated incident, patch, backup, and recovery operations. Cloud operations jobs
Compare current role requirements with practical evidence; job results are not guaranteed. SOA-C03 study guide
Read domain strategy, service decisions, transition notes, and readiness guidance. Career paths
Connect CloudOps skills to platform, SRE, cloud support, operations, and infrastructure roles.
Official AWS sources
Verify active exam positioning, logistics, and official preparation links.
Open AWS CertificationUse the five domains, task statements, weights, target candidate, and scoring details.
Open the official guideConfirm additions, deletions, recategorizations, and transition dates.
Open the comparisonReview agent collection, alarms, logs, dashboards, and cross-account observability.
Open CloudWatch documentationReview managed nodes, Automation, Patch Manager, Quick Setup, and operations tools.
Open Systems Manager documentationReview plans, copies, vault security, monitoring, compliance, and restore testing.
Open AWS Backup documentationFrequently asked questions
Is SOA-C03 the active AWS operations exam?
Yes. It is active as of August 19, 2026. AWS states that SOA-C03 began September 30, 2025 and SOA-C02 ended the previous day. Always verify the official page before scheduling.
What are the domain weights?
Domains 1, 2, and 3 are each 22%; Security and Compliance is 16%; Networking and Content Delivery is 18%.
What changed from SOA-C02?
The name changed to CloudOps Engineer, six domains became five, former cost/performance work moved to Domain 1, several current operational skills were added, VPN moved into networking, and S3 static website hosting was removed.
How should practical readiness be measured?
Measure whether you can diagnose fresh failures, explain service trade-offs, safely automate remediation, restore within stated RTO/RPO, trace authorization and network paths, and perform consistently across new mixed-domain scenarios.
Are these materials exam dumps?
No. They are original educational materials based on public objectives and official AWS documentation. PrepKloud does not reproduce live or recalled questions and does not guarantee a pass or career outcome.
Turn the SOA-C03 blueprint into operating evidence
Diagnose gaps, retrieve key distinctions, then build and break both CloudOps projects.