SOA-C03 EXAM — 2026/2027 | 65 QUESTIONS AND
CORRECT ANSWERS | GRADED A+ | 100% VERIFIED
AWS Certified CloudOps Engineer - Associate (SOA-C03) Certification Examination | Core
Domains: Monitoring, Logging, Analysis, Remediation, Performance Optimization, Reliability,
Business Continuity, Deployment, Provisioning, Automation, Security, Compliance, Networking, and
Content Delivery.
Exam Structure
AWS Certified CloudOps Engineer - Associate (SOA-C03) Examination is commonly structured as
follows:
65 total questions (50 scored, 15 unscored experimental items)
Multiple-choice questions (one correct answer) and multiple-response questions (two or more
correct answers)
Additional question formats may include ordering, matching, and case study items
Computer-based testing at Pearson VUE testing centers or online with remote proctoring
130 minutes (2 hours 10 minutes) to complete the exam
Passing score: 720 out of 1000 (scaled score)
Exam fee: $150 USD
Validity: 3 years
Domain Weight Distribution:
Domain 1: Monitoring, Logging, Analysis, Remediation, and Performance Optimization – 22%
Domain 2: Reliability and Business Continuity – 22%
Domain 3: Deployment, Provisioning, and Automation – 22%
Domain 4: Security and Compliance – 16%
Domain 5: Networking and Content Delivery – 18%
Introduction
This AWS Certified CloudOps Engineer - Associate SOA-C03 Exam preparation resource for the
2026/2027 academic cycle reflects the latest Amazon Web Services certification standards for cloud
operations professionals. Formerly known as the AWS Certified SysOps Administrator - Associate, the
certification was renamed in September 2025 to better reflect modern operational responsibilities
including multi-account governance, automation/IaC, and containers. The examination validates
expertise in deploying, operating, maintaining, monitoring, securing, and optimizing workloads on AWS
according to the AWS Well-Architected Framework.
,Answer Format
All questions must be presented in bold text for clear distinction and readability.
All correct answers must be presented in bold and lime green, followed by clearly defined, technically
accurate rationales in italic format that reinforce cloud operations principles, monitoring and logging
best practices, automation strategies, security controls, networking concepts, and professional judgment
required for SOA-C03 certification success.
Section A: Domain 1 - Monitoring, Logging, and Remediation
1. A company operates a website using Amazon EC2 instances in an Auto Scaling
group. When website traffic increases, the user data script that installs software takes
several minutes to complete, delaying new instances from becoming available. A
CloudOps engineer needs to reduce the time required for new instances to become
available. Which action should the engineer take to meet this requirement?
A. Lower the scaling threshold to add instances before traffic increases.
B. Use EC2 Image Builder to prepare an Amazon Machine Image (AMI) with software pre-installed.
C. Update the Auto Scaling group to launch instances with storage-optimized instance types.
D. Purchase Reserved Instances covering 100% of the Auto Scaling group's maximum capacity.
Correct Answer: B
Rationale: The root cause is software installation time during instance launch. Using a pre-
installed AMI eliminates this installation time, reducing instance readiness from minutes to
seconds. EC2 Image Builder automates creating and maintaining custom AMIs with pre-installed
software. Lowering scaling thresholds (A) only triggers scaling earlier but doesn't fix installation
delay. Storage-optimized instance types (C) improve disk I/O but don't eliminate software
installation. Reserved Instances (D) provide cost savings but don't affect launch speed.
2. A company hosts a critical legacy application on two Amazon EC2 instances in a
single Availability Zone behind an Application Load Balancer (ALB). CloudWatch
alarms send SNS notifications when ALB health checks detect an unhealthy instance,
and engineers manually restart the unhealthy instance. A CloudOps engineer must
configure the application to be highly available and more resilient to failures. Which
solution meets these requirements?
A. Create an Amazon EventBridge rule to automatically restart unhealthy instances.
B. Configure an Auto Scaling group with a minimum of two instances across two Availability Zones.
C. Migrate the application to AWS Fargate with a target of two tasks.
D. Replace the ALB with a Network Load Balancer and enable cross-zone load balancing.
Correct Answer: B
, Rationale: For high availability, instances must span multiple Availability Zones. An Auto Scaling
group with minimum two instances across two AZs automatically replaces failed instances and
distributes load across zones. EventBridge (A) can automate restarts but doesn't add multi-AZ
resilience. Fargate (C) provides container orchestration but requires application refactoring. NLB
with cross-zone load balancing (D) improves distribution but doesn't add multi-AZ instance
redundancy.
3. A company has a VPC with a public subnet and a private subnet. An EC2 instance
with Amazon Linux and SSM Agent installed runs in the private subnet. The
instance's security group allows only outbound traffic. A CloudOps engineer must
give privileged administrators the ability to connect to the instance through SSH
without exposing the instance to the internet. Which solution meets this requirement?
A. Create a VPC endpoint for Systems Manager Session Manager and use IAM policies to grant
access.
B. Assign a public IP address to the instance and restrict SSH access to corporate IP ranges.
C. Deploy a bastion host in the public subnet and configure SSH forwarding.
D. Create a VPN connection to the VPC and allow SSH from the VPN CIDR block.
Correct Answer: A
Rationale: Systems Manager Session Manager allows secure shell access without opening inbound
ports, requiring no bastion hosts or public IPs. VPC endpoints provide private connectivity to SSM.
IAM policies control user access. Public IP assignment (B) exposes the instance to the internet.
Bastion host (C) requires management overhead and open inbound ports. VPN (D) adds
complexity and doesn't address the requirement to avoid internet exposure.
4. A financial services company stores customer images in an S3 bucket in us-east-1.
To comply with regulations, the company must ensure all existing objects are
replicated to an S3 bucket in a second AWS Region. If an object replication fails, the
company must be able to retry replication for the object. Which solution meets these
requirements?
A. Configure same-region replication and enable S3 Versioning on both buckets.
B. Configure cross-region replication (CRR) with S3 Versioning enabled and S3 Replication Time
Control (RTC).
C. Use S3 Batch Operations to copy existing objects and configure CRR for new objects.
D. Enable S3 Transfer Acceleration and use AWS DataSync for initial copy.
Correct Answer: B
Rationale: Cross-region replication (CRR) replicates objects to another region. S3 Replication
Time Control (RTC) provides SLA-backed replication within 15 minutes and alerts for replication
failures, enabling retry capability. Same-region replication (A) doesn't meet cross-region
requirement. S3 Batch Operations (C) copies existing objects but doesn't provide ongoing