AWS SOA-C03 Study Plan: CloudOps, Monitoring, Recovery, and Automation in 30, 60, and 90 Days

AWS SOA-C03 30-, 60-, and 90-day study plan for CloudOps, monitoring, recovery, automation, review loops, and final-week priorities.

Use this study plan when you want a structured route through AWS Certified CloudOps Engineer - Associate (SOA-C03). AWS formerly used the SysOps Administrator - Associate name for this certification family, but the current SOA-C03 exam awards the CloudOps Engineer - Associate credential.

SOA-C03 is an operations exam. It tests whether you can deploy, manage, operate, secure, troubleshoot, automate, monitor, and recover workloads on AWS. The strongest answers stay calm under incident pressure: read the right signal, choose the lowest-risk action, verify recovery, and avoid turning a day-two operations question into a full architecture redesign.

Current exam facts

I verified these current AWS exam facts on May 16, 2026.

Item Value
Exam AWS Certified CloudOps Engineer - Associate
Exam code SOA-C03
Former certification name AWS Certified SysOps Administrator - Associate
Category Associate
Questions 65 total
Scoring 50 scored + 15 unscored (unscored items are not identified)
Question types Multiple choice and multiple response
Time 130 minutes
Passing score 720, scaled 100-1000
Cost 150 USD
Target candidate About 1 year deploying, managing, and operating AWS workloads

The name change matters for content positioning, not for the URL. Keep thinking in SOA-C03 exam-code terms, but use CloudOps terminology when describing the role.

Weight-driven study allocation

Domain Weight How to allocate study time
Monitoring & Performance 22% Drill metrics, logs, CloudTrail, alarms, dashboards, EventBridge, remediation, runbooks, and performance tuning.
Reliability & Continuity 22% Practice scaling, elasticity, HA, load balancing, backups, restores, RTO/RPO, and disaster recovery.
Provisioning & Automation 22% Study images, CloudFormation, CDK, StackSets, deployment strategies, Systems Manager, patching, and automation troubleshooting.
Networking & Delivery 18% Cover VPC paths, DNS, Route 53, CloudFront, Global Accelerator, endpoints, NAT, VPN, Direct Connect, and network logs.
Security & Compliance 16% Drill IAM, auditing, multi-account controls, encryption, secrets, findings, and remediation workflows.

The top three domains are equal at 22% each, so do not treat this as only a monitoring exam. SOA-C03 often combines monitoring, automation, reliability, networking, and security in the same incident.

Pick the right timeline

Starting point Typical study time Best-fit timeline
You operate AWS workloads today 45-70 hours 30-60 days
You know AWS services but have less incident/automation depth 70-100 hours 60 days
You are stronger in networking or security than operations 80-120 hours 60-90 days
You are new to AWS operations and troubleshooting 120+ hours 90 days before scheduling

Choose the longer route if you still guess at CloudWatch vs CloudTrail, EventBridge vs Systems Manager Automation, scaling vs HA vs DR, CloudFormation failure diagnosis, or VPC connectivity troubleshooting order.

The SOA-C03 study loop

Use the same incident-oriented loop every week.

    flowchart LR
	  S["Signal"] --> C["Classify"]
	  C --> E["Evidence"]
	  E --> A["Action"]
	  A --> V["Verify"]
	  V --> R["Runbook rule"]
Step What to ask
Signal Is the first clue a metric, log, API event, alarm, health check, failed deployment, backup event, or network symptom?
Classify Is the problem monitoring, reliability, provisioning, security, networking, or performance?
Evidence What source proves the cause before you change anything?
Action What is the smallest safe remediation, rollback, scaling, restore, access, or routing change?
Verify Which signal confirms the workload is healthy again?
Runbook rule What one-line rule would prevent this miss next time?

Minimum operational baseline

You do not need a large lab, but you should be able to explain these paths without guessing:

Path What you should know
Alarm to action CloudWatch metric or log filter, alarm state, SNS/EventBridge routing, runbook choice, and verification
Incident triage Symptom, evidence source, likely root cause, first safe action, rollback path, and post-action validation
Backup and restore Snapshot, AWS Backup, PITR, versioning, restore target, RTO/RPO, and restore test
Provisioning failure CloudFormation event, dependency, permission, quota, rollback state, drift, and repeatable fix
Automation Systems Manager, Lambda, EventBridge, patching, schedules, target selection, permissions, and safety guardrails
VPC troubleshooting Route table, security group, NACL, endpoint, NAT, DNS, flow logs, load balancer logs, and intended path
Security remediation IAM/access evidence, CloudTrail, Access Analyzer, Config, Security Hub, GuardDuty, KMS, secrets, and finding workflow

30-day intensive plan

Use this route only if you already have AWS operations exposure and can study most days.

Week Focus What to produce
1 Monitoring, remediation, and performance A signal map covering CloudWatch, CloudTrail, alarms, dashboards, EventBridge, runbooks, compute/storage/database performance, and safe remediation.
2 Reliability and business continuity A continuity checklist covering scaling, cache offload, HA, load balancing, Multi-AZ, backups, restores, RTO/RPO, and DR drills.
3 Provisioning and automation A repeatability map covering AMIs, images, CloudFormation, CDK, StackSets, Systems Manager, patching, deployment strategies, and failure diagnosis.
4 Networking, security, and mixed incidents A troubleshooting matrix for VPC, DNS, CloudFront, Global Accelerator, IAM, KMS, secrets, findings, and network evidence.

30-day rule

Every day should create one operational artifact.

Artifact Why it matters
Signal map Prevents confusing metrics, logs, API audit events, traces, health checks, and deployment output.
First-action runbook Forces the lowest-risk remediation before broader changes.
Recovery checklist Keeps RTO, RPO, backup state, restore path, and validation explicit.
Provisioning failure log Turns stack and automation errors into repeatable troubleshooting rules.
Network path diagram Keeps route, filter, DNS, endpoint, and cache issues separate.
Security evidence matrix Separates audit, access control, encryption, secrets, and finding remediation.

60-day balanced plan

This is the best default route for most candidates.

Weeks Focus What to do
1-2 Monitoring & Performance Drill CloudWatch, CloudTrail, alarms, dashboards, EventBridge, remediation, runbooks, and compute/storage/database performance tuning.
3-4 Reliability & Continuity Practice scalability, elasticity, caching, HA, load balancing, backups, restores, RTO/RPO, and disaster recovery procedures.
5-6 Provisioning & Automation Study images, CloudFormation, CDK, StackSets, AWS RAM, deployment strategies, Systems Manager, patching, and event-driven automation.
7 Networking & Delivery Drill VPC connectivity, endpoints, NAT, VPN, Direct Connect, DNS, Route 53, CloudFront, Global Accelerator, and network logs.
8 Security & Compliance and final repair Review IAM, auditing, multi-account controls, encryption, secrets, findings, and run mixed timed sets.

90-day part-time plan

Use this route if you are building CloudOps depth while studying.

Phase Weeks Outcome
Monitoring and incident signals 1-3 You can choose the right metric, log, audit trail, alarm, dashboard, event, or runbook for a symptom.
Reliability and recovery 4-5 You can separate scaling, live availability, backup/restore, and DR by RTO/RPO and failure boundary.
Provisioning and automation 6-7 You can provision repeatably, troubleshoot stack failures, automate operations, and control rollout risk.
Networking and delivery 8-9 You can operate VPC, DNS, CloudFront, Global Accelerator, private/hybrid connectivity, and network evidence paths.
Security and compliance 10-11 You can implement access, audit, encryption, secrets, finding remediation, and multi-account controls operationally.
Exam execution 12 You can answer mixed incidents under time pressure and explain every repeated miss as an operational decision rule.

What to drill by domain

Domain Drill questions until you can answer…
Monitoring & Performance What signal proves the problem, what action is safe, and how do you verify recovery?
Reliability & Continuity Is the requirement scaling, HA, backup/restore, DR, RTO, RPO, or live traffic continuity?
Provisioning & Automation Is this a repeatable provisioning issue, rollout strategy issue, or day-two automation issue?
Security & Compliance Is the need access control, audit evidence, encryption, secrets, finding remediation, or guardrail enforcement?
Networking & Delivery Is the path public, private, hybrid, DNS-directed, CDN-backed, accelerated, filtered, or cached?

High-yield CloudOps comparisons

Decision Choose by asking…
CloudWatch vs CloudTrail Do you need runtime telemetry and alarms, or API activity and change history?
EventBridge vs Systems Manager Automation Do you need event routing, or an approved operational action runbook?
Scaling vs HA vs DR Is the problem demand growth, live component failure, or recovery after disruption?
CloudFormation vs Systems Manager Are you declaring resource state, or operating existing resources?
StackSet vs repeated stack deployment Do you need governed multi-account or multi-Region rollout?
NAT gateway vs VPC endpoint Does a private subnet need internet-style egress or private access to an AWS service?
CloudFront vs Global Accelerator Is the need CDN/caching/content delivery, or global application entry-path performance?
Access Analyzer vs CloudTrail Do you need to detect broad/external access, or explain who made an API call?
KMS vs Secrets Manager Are you controlling encryption keys, or storing and rotating secret values?

Out-of-scope guardrails

Do not turn SOA-C03 into the wrong exam.

Do not over-study… Learn this instead
Distributed architecture design Operating, monitoring, remediating, and recovering existing AWS workloads
CI/CD pipeline design from scratch Deploying, provisioning, automating, and troubleshooting delivery paths
Hybrid and multi-VPC network design Operating and troubleshooting network paths, DNS, endpoints, delivery, and logs
Software development Scripting familiarity, operational automation, CLI use, and incident response logic
Security policy definition Implementing controls, auditing access, encrypting data, managing secrets, and remediating findings
Billing management Cloud financial awareness and cost/performance optimization, not invoice administration

Final-week checklist

Use the final week to tighten incident-classification speed.

Day Work
7 days out Reread the cheat sheet and summarize each domain as one operational decision problem.
6 days out Drill monitoring and performance: CloudWatch, CloudTrail, alarms, EventBridge, runbooks, and tuning evidence.
5 days out Drill reliability and continuity: scaling, HA, load balancing, backup, restore, RTO/RPO, and DR.
4 days out Drill provisioning and automation: images, CloudFormation, CDK, StackSets, Systems Manager, patching, and deployment troubleshooting.
3 days out Drill networking and delivery: VPC paths, endpoints, NAT, VPN, Direct Connect, Route 53, CloudFront, Global Accelerator, and network logs.
2 days out Drill security and compliance: IAM, auditing, multi-account controls, KMS, secrets, findings, GuardDuty, Config, Security Hub, and remediation.
1 day out Review only weak rules, domain weights, current facts, high-yield comparisons, and exam logistics.

Readiness signals

You are close to ready when:

  • You can classify a scenario into monitoring, reliability, provisioning, security, networking, or performance before reading every answer.
  • You can choose the evidence source before choosing a remediation.
  • You can separate signal collection, event routing, runbook execution, remediation, and recovery validation.
  • You can translate RTO/RPO into a backup, restore, or DR action.
  • You can troubleshoot VPC connectivity in intended-path order instead of randomly checking controls.
  • You can keep a steady pace across 65 questions in 130 minutes.

If you only have 48 hours

This is only reasonable if you are already near-ready.

  1. Read the cheat sheet twice: once before practice and once after reviewing misses.
  2. Drill one mixed timed block and classify every miss by operational lane.
  3. Spend one focused block on monitoring/reliability and one on provisioning/networking.
  4. Review security evidence, IAM, KMS, secrets, findings, EventBridge, Systems Manager, CloudFormation, VPC logs, CloudFront, and high-yield comparisons.
  5. Recheck the current official AWS page before scheduling or buying an exam attempt.

Booking signal

Schedule only when your misses are narrow and explainable. If you still jump to broad redesigns before identifying the signal, evidence, first safe action, and verification path, keep studying. SOA-C03 rewards CloudOps incident judgment under time pressure.

Revised on Monday, June 15, 2026