AWS SOA-C03 Exam Complete Guide

A beginner-friendly breakdown of the SOA-C03 exam: structure, 5 domains, key services, and a step-by-step study strategy.

AWS Certified SysOps Administrator - Associate (SOA-C03) tests your ability to operate and manage AWS infrastructure. But what does that actually mean?

Imagine you are the facility manager of a large apartment complex. Your job is to watch the security cameras (monitoring), restore power when there is an outage (reliability), add new floors to the building (deployment), control who can enter each area (security), and keep the plumbing and communications running (networking). The SOA-C03 exam checks whether you can do all of this in the AWS cloud.

 

Exam at a Glance

Before you start studying, know the basic specs so you can plan your time wisely.

| Item | Details | |------|---------| | Exam Code | SOA-C03 | | Number of Questions | 65 (50 scored + 15 unscored) | | Time Limit | 130 minutes | | Passing Score | 720 / 1000 | | Question Types | Multiple choice + Multiple select + Lab (hands-on) | | Cost | $150 USD |

Two things stand out here. First, 15 of the 65 questions are unscored. AWS uses these to test new questions for future exams. You cannot tell which ones are unscored, so treat every question seriously.

Second, the Lab questions are unique to SOA-C03. Instead of just picking an answer, you log into a real AWS console and perform actual tasks. This means you must be comfortable navigating the AWS console, not just reading about it.

 

The 5 Domains and Their Weights

SOA-C03 is divided into 5 domains. Think of each domain as a chapter in the "AWS Operations Manual." Knowing the weight of each domain helps you spend study time where it counts most.

| Domain | Weight | What It Covers | |--------|--------|---------------| | D1: Monitoring, Logging, Troubleshooting | 22% | Watch your systems and fix problems when they arise | | D2: Reliability and Business Continuity | 22% | Keep services running even when things break | | D3: Deployment, Provisioning, Automation | 22% | Build and update infrastructure efficiently and automatically | | D4: Security and Compliance | 16% | Control access and protect data | | D5: Networking and Content Delivery | 18% | Connect servers, users, and services reliably |

!SOA-C03 exam domain weight breakdown

D1, D2, and D3 each carry 22%, which means these three domains together make up 66% of the exam. If you master these three areas, you are most of the way to passing.

Here is the apartment building analogy again: D1 is like the CCTV and sensor network — knowing what is happening at all times D2 is like the backup generator and evacuation plan — staying operational when things go wrong D3 is like construction and automation systems — building and expanding efficiently D4 is like access control — only letting authorized people into each area D5 is like the plumbing and cable infrastructure — making sure data flows where it needs to go

 

Key Services by Domain

Here are the AWS services you will encounter most in each domain. If you are new to AWS, just learn the names for now and come back to each service as you study deeper.

D1: Monitoring, Logging, Troubleshooting (22%)

CloudWatch is the centerpiece. It provides Metrics (numbers about your system), Alarms (alerts when something goes wrong), Dashboards (visual summaries), and Logs (text records of events). You also need to know CloudTrail (who did what and when), EventBridge (automated reactions to events), Systems Manager (operational automation), and X-Ray (tracing requests across services).

D2: Reliability and Business Continuity (22%)

Auto Scaling (automatically adjust the number of servers), ELB (distribute traffic across servers), Route 53 (DNS and traffic routing), AWS Backup (centralized backup management), EBS and RDS snapshots, Multi-AZ configurations, and Disaster Recovery strategies are the main topics.

D3: Deployment, Provisioning, Automation (22%)

CloudFormation (define infrastructure as code), Systems Manager components including Patch Manager, Run Command, and Parameter Store, AWS Config (track and enforce compliance), Service Catalog, and Elastic Beanstalk are what you need to focus on.

D4: Security and Compliance (16%)

IAM policies, roles, and Service Control Policies, KMS (encryption key management), Secrets Manager (securely store passwords and API keys), Config Rules, Security Hub, GuardDuty (threat detection), and Inspector (vulnerability scanning) are the key services.

D5: Networking and Content Delivery (18%)

VPC (your private network in AWS), subnets, NACLs (network-level firewall rules), security groups (instance-level firewall), VPN, Direct Connect (dedicated physical connection to AWS), CloudFront (content delivery network), Route 53, VPC Peering, and Transit Gateway are what this domain covers.

 

Study Strategy — Where to Begin

Here is a recommended step-by-step learning path, especially if you are new to AWS.

Step 1 — Start with CloudWatch. It is the foundation of D1 and shows up in all other domains too. Understanding CloudWatch metrics and alarms will make everything else click into place.

Step 2 — Learn Auto Scaling and ELB together. These two services work as a pair. Auto Scaling adjusts how many servers you have, and ELB distributes incoming traffic across them. This is the backbone of D2.

Step 3 — Learn the basics of CloudFormation. Understand how a CloudFormation template is structured and how it creates AWS resources. Lab questions in D3 may involve CloudFormation.

Step 4 — Practice reading IAM policy documents. An IAM policy is a JSON document that says "this user can or cannot do this action on this resource." You need to be able to read one and determine what permissions it grants.

Step 5 — Draw VPC diagrams. Be able to trace a request from the internet through a load balancer, through security groups and NACLs, to an EC2 instance, and back. Many questions ask where traffic is being blocked.

Practice tip: Create a free-tier AWS account and try things yourself. Setting up a CloudWatch alarm, launching an EC2 instance, and creating an IAM role hands-on will teach you more than hours of reading.

 

Exam Key Points

"AWS operations management certification" -- SOA-C03

"Highest-weight domains" -- D1, D2, D3 each at 22% (total 66%)

"Service that appears in every domain" -- CloudWatch

"Unique question type in SOA-C03" -- Lab (hands-on) questions

"Passing score" -- 720 out of 1000

"Number of unscored questions" -- 15 out of 65 total

Focus on D1+D2+D3 to cover two-thirds of the exam content

---

 

Domain Deep-Dive Series and Next Steps

With the big picture from this guide, continue with the deep-dive posts below to build service-level judgment for each domain.

| | Topic | |---|-------| | 2 | CloudWatch Monitoring Complete Guide | | 3 | Performance Analysis and Troubleshooting | | 4 | Auto Scaling and High Availability | | 5 | Backup and Disaster Recovery | | 6 | CloudFormation and IaC Deployment | | 7 | Systems Manager and Operations Automation | | 8 | Cross-Account and Resource Sharing | | 9 | IAM Policies and Identity Security | | 10 | Security Services & Compliance | | 11 | VPC Network Design | | 12 | Hybrid Network Connectivity | | 13 | DNS, CDN & Edge Services |

Ready to test where you stand? Try the SOA-C03 practice exam now.

Back to blog list