AWS SOA-C03 30-, 60-, and 90-day study plan for CloudOps, monitoring, recovery, automation, review loops, and final-week priorities.
Use this study plan when you want a structured route through AWS Certified CloudOps Engineer - Associate (SOA-C03). AWS formerly used the SysOps Administrator - Associate name for this certification family, but the current SOA-C03 exam awards the CloudOps Engineer - Associate credential.
SOA-C03 is an operations exam. It tests whether you can deploy, manage, operate, secure, troubleshoot, automate, monitor, and recover workloads on AWS. The strongest answers stay calm under incident pressure: read the right signal, choose the lowest-risk action, verify recovery, and avoid turning a day-two operations question into a full architecture redesign.
I verified these current AWS exam facts on May 16, 2026.
| Item | Value |
|---|---|
| Exam | AWS Certified CloudOps Engineer - Associate |
| Exam code | SOA-C03 |
| Former certification name | AWS Certified SysOps Administrator - Associate |
| Category | Associate |
| Questions | 65 total |
| Scoring | 50 scored + 15 unscored (unscored items are not identified) |
| Question types | Multiple choice and multiple response |
| Time | 130 minutes |
| Passing score | 720, scaled 100-1000 |
| Cost | 150 USD |
| Target candidate | About 1 year deploying, managing, and operating AWS workloads |
The name change matters for content positioning, not for the URL. Keep thinking in SOA-C03 exam-code terms, but use CloudOps terminology when describing the role.
| Domain | Weight | How to allocate study time |
|---|---|---|
| Monitoring & Performance | 22% | Drill metrics, logs, CloudTrail, alarms, dashboards, EventBridge, remediation, runbooks, and performance tuning. |
| Reliability & Continuity | 22% | Practice scaling, elasticity, HA, load balancing, backups, restores, RTO/RPO, and disaster recovery. |
| Provisioning & Automation | 22% | Study images, CloudFormation, CDK, StackSets, deployment strategies, Systems Manager, patching, and automation troubleshooting. |
| Networking & Delivery | 18% | Cover VPC paths, DNS, Route 53, CloudFront, Global Accelerator, endpoints, NAT, VPN, Direct Connect, and network logs. |
| Security & Compliance | 16% | Drill IAM, auditing, multi-account controls, encryption, secrets, findings, and remediation workflows. |
The top three domains are equal at 22% each, so do not treat this as only a monitoring exam. SOA-C03 often combines monitoring, automation, reliability, networking, and security in the same incident.
| Starting point | Typical study time | Best-fit timeline |
|---|---|---|
| You operate AWS workloads today | 45-70 hours | 30-60 days |
| You know AWS services but have less incident/automation depth | 70-100 hours | 60 days |
| You are stronger in networking or security than operations | 80-120 hours | 60-90 days |
| You are new to AWS operations and troubleshooting | 120+ hours | 90 days before scheduling |
Choose the longer route if you still guess at CloudWatch vs CloudTrail, EventBridge vs Systems Manager Automation, scaling vs HA vs DR, CloudFormation failure diagnosis, or VPC connectivity troubleshooting order.
Use the same incident-oriented loop every week.
flowchart LR
S["Signal"] --> C["Classify"]
C --> E["Evidence"]
E --> A["Action"]
A --> V["Verify"]
V --> R["Runbook rule"]
| Step | What to ask |
|---|---|
| Signal | Is the first clue a metric, log, API event, alarm, health check, failed deployment, backup event, or network symptom? |
| Classify | Is the problem monitoring, reliability, provisioning, security, networking, or performance? |
| Evidence | What source proves the cause before you change anything? |
| Action | What is the smallest safe remediation, rollback, scaling, restore, access, or routing change? |
| Verify | Which signal confirms the workload is healthy again? |
| Runbook rule | What one-line rule would prevent this miss next time? |
You do not need a large lab, but you should be able to explain these paths without guessing:
| Path | What you should know |
|---|---|
| Alarm to action | CloudWatch metric or log filter, alarm state, SNS/EventBridge routing, runbook choice, and verification |
| Incident triage | Symptom, evidence source, likely root cause, first safe action, rollback path, and post-action validation |
| Backup and restore | Snapshot, AWS Backup, PITR, versioning, restore target, RTO/RPO, and restore test |
| Provisioning failure | CloudFormation event, dependency, permission, quota, rollback state, drift, and repeatable fix |
| Automation | Systems Manager, Lambda, EventBridge, patching, schedules, target selection, permissions, and safety guardrails |
| VPC troubleshooting | Route table, security group, NACL, endpoint, NAT, DNS, flow logs, load balancer logs, and intended path |
| Security remediation | IAM/access evidence, CloudTrail, Access Analyzer, Config, Security Hub, GuardDuty, KMS, secrets, and finding workflow |
Use this route only if you already have AWS operations exposure and can study most days.
| Week | Focus | What to produce |
|---|---|---|
| 1 | Monitoring, remediation, and performance | A signal map covering CloudWatch, CloudTrail, alarms, dashboards, EventBridge, runbooks, compute/storage/database performance, and safe remediation. |
| 2 | Reliability and business continuity | A continuity checklist covering scaling, cache offload, HA, load balancing, Multi-AZ, backups, restores, RTO/RPO, and DR drills. |
| 3 | Provisioning and automation | A repeatability map covering AMIs, images, CloudFormation, CDK, StackSets, Systems Manager, patching, deployment strategies, and failure diagnosis. |
| 4 | Networking, security, and mixed incidents | A troubleshooting matrix for VPC, DNS, CloudFront, Global Accelerator, IAM, KMS, secrets, findings, and network evidence. |
Every day should create one operational artifact.
| Artifact | Why it matters |
|---|---|
| Signal map | Prevents confusing metrics, logs, API audit events, traces, health checks, and deployment output. |
| First-action runbook | Forces the lowest-risk remediation before broader changes. |
| Recovery checklist | Keeps RTO, RPO, backup state, restore path, and validation explicit. |
| Provisioning failure log | Turns stack and automation errors into repeatable troubleshooting rules. |
| Network path diagram | Keeps route, filter, DNS, endpoint, and cache issues separate. |
| Security evidence matrix | Separates audit, access control, encryption, secrets, and finding remediation. |
This is the best default route for most candidates.
| Weeks | Focus | What to do |
|---|---|---|
| 1-2 | Monitoring & Performance | Drill CloudWatch, CloudTrail, alarms, dashboards, EventBridge, remediation, runbooks, and compute/storage/database performance tuning. |
| 3-4 | Reliability & Continuity | Practice scalability, elasticity, caching, HA, load balancing, backups, restores, RTO/RPO, and disaster recovery procedures. |
| 5-6 | Provisioning & Automation | Study images, CloudFormation, CDK, StackSets, AWS RAM, deployment strategies, Systems Manager, patching, and event-driven automation. |
| 7 | Networking & Delivery | Drill VPC connectivity, endpoints, NAT, VPN, Direct Connect, DNS, Route 53, CloudFront, Global Accelerator, and network logs. |
| 8 | Security & Compliance and final repair | Review IAM, auditing, multi-account controls, encryption, secrets, findings, and run mixed timed sets. |
Use this route if you are building CloudOps depth while studying.
| Phase | Weeks | Outcome |
|---|---|---|
| Monitoring and incident signals | 1-3 | You can choose the right metric, log, audit trail, alarm, dashboard, event, or runbook for a symptom. |
| Reliability and recovery | 4-5 | You can separate scaling, live availability, backup/restore, and DR by RTO/RPO and failure boundary. |
| Provisioning and automation | 6-7 | You can provision repeatably, troubleshoot stack failures, automate operations, and control rollout risk. |
| Networking and delivery | 8-9 | You can operate VPC, DNS, CloudFront, Global Accelerator, private/hybrid connectivity, and network evidence paths. |
| Security and compliance | 10-11 | You can implement access, audit, encryption, secrets, finding remediation, and multi-account controls operationally. |
| Exam execution | 12 | You can answer mixed incidents under time pressure and explain every repeated miss as an operational decision rule. |
| Domain | Drill questions until you can answer… |
|---|---|
| Monitoring & Performance | What signal proves the problem, what action is safe, and how do you verify recovery? |
| Reliability & Continuity | Is the requirement scaling, HA, backup/restore, DR, RTO, RPO, or live traffic continuity? |
| Provisioning & Automation | Is this a repeatable provisioning issue, rollout strategy issue, or day-two automation issue? |
| Security & Compliance | Is the need access control, audit evidence, encryption, secrets, finding remediation, or guardrail enforcement? |
| Networking & Delivery | Is the path public, private, hybrid, DNS-directed, CDN-backed, accelerated, filtered, or cached? |
| Decision | Choose by asking… |
|---|---|
| CloudWatch vs CloudTrail | Do you need runtime telemetry and alarms, or API activity and change history? |
| EventBridge vs Systems Manager Automation | Do you need event routing, or an approved operational action runbook? |
| Scaling vs HA vs DR | Is the problem demand growth, live component failure, or recovery after disruption? |
| CloudFormation vs Systems Manager | Are you declaring resource state, or operating existing resources? |
| StackSet vs repeated stack deployment | Do you need governed multi-account or multi-Region rollout? |
| NAT gateway vs VPC endpoint | Does a private subnet need internet-style egress or private access to an AWS service? |
| CloudFront vs Global Accelerator | Is the need CDN/caching/content delivery, or global application entry-path performance? |
| Access Analyzer vs CloudTrail | Do you need to detect broad/external access, or explain who made an API call? |
| KMS vs Secrets Manager | Are you controlling encryption keys, or storing and rotating secret values? |
Do not turn SOA-C03 into the wrong exam.
| Do not over-study… | Learn this instead |
|---|---|
| Distributed architecture design | Operating, monitoring, remediating, and recovering existing AWS workloads |
| CI/CD pipeline design from scratch | Deploying, provisioning, automating, and troubleshooting delivery paths |
| Hybrid and multi-VPC network design | Operating and troubleshooting network paths, DNS, endpoints, delivery, and logs |
| Software development | Scripting familiarity, operational automation, CLI use, and incident response logic |
| Security policy definition | Implementing controls, auditing access, encrypting data, managing secrets, and remediating findings |
| Billing management | Cloud financial awareness and cost/performance optimization, not invoice administration |
Use the final week to tighten incident-classification speed.
| Day | Work |
|---|---|
| 7 days out | Reread the cheat sheet and summarize each domain as one operational decision problem. |
| 6 days out | Drill monitoring and performance: CloudWatch, CloudTrail, alarms, EventBridge, runbooks, and tuning evidence. |
| 5 days out | Drill reliability and continuity: scaling, HA, load balancing, backup, restore, RTO/RPO, and DR. |
| 4 days out | Drill provisioning and automation: images, CloudFormation, CDK, StackSets, Systems Manager, patching, and deployment troubleshooting. |
| 3 days out | Drill networking and delivery: VPC paths, endpoints, NAT, VPN, Direct Connect, Route 53, CloudFront, Global Accelerator, and network logs. |
| 2 days out | Drill security and compliance: IAM, auditing, multi-account controls, KMS, secrets, findings, GuardDuty, Config, Security Hub, and remediation. |
| 1 day out | Review only weak rules, domain weights, current facts, high-yield comparisons, and exam logistics. |
You are close to ready when:
This is only reasonable if you are already near-ready.
Schedule only when your misses are narrow and explainable. If you still jump to broad redesigns before identifying the signal, evidence, first safe action, and verification path, keep studying. SOA-C03 rewards CloudOps incident judgment under time pressure.