C90.03 Exam Guide: How to Prepare for AWS Certified CloudOps Engineer – Associate (SOA-C03)
The catalogue label C90.03 most closely matches AWS Certified CloudOps Engineer – Associate, exam code SOA-C03. AWS uses this exam to validate the ability to deploy, manage, monitor, troubleshoot, secure, and operate workloads on AWS. It is aimed at CloudOps engineers and experienced operations professionals. This guide helps you make three practical decisions: whether your current experience matches the target profile, which domains deserve the most study time, and whether your preparation is strong enough to schedule the current exam version rather than rely on outdated SOA-C02 material.
What does C90.03 refer to?
The closest official match for “C90.03” is AWS Certified CloudOps Engineer – Associate, exam code SOA-C03. AWS identifies SOA-C03 as the current exam version and states that it replaced SOA-C02 beginning September 30, 2025. Confirm the exact code shown in your booking or training catalogue before paying for an appointment.
The name change matters when you search for preparation material. SOA-C03 was formerly called AWS Certified SysOps Administrator – Associate, so older resources may use the former title or SOA-C02 code. The official SOA-C03 exam guide should be your authority for the current objectives, while older material should be treated as supplementary rather than automatically current.
Do not assume that every page using “SOA,” “SysOps,” or “C90.03” describes the same blueprint. Check the code, domain names, task statements, and revision information together. If a resource still presents the old six-domain structure without explaining the change, it may not reflect SOA-C03.
What capability does the exam validate?
SOA-C03 validates whether a candidate can deploy, manage, and operate workloads on AWS. The emphasis is operational: supporting running environments, interpreting telemetry, responding to incidents, applying security controls, maintaining reliability, and carrying out changes through AWS tools. It is not simply a test of product definitions or console navigation.
AWS also connects the exam to support and maintenance according to the AWS Well-Architected Framework. The stated tasks include monitoring, logging, and troubleshooting systems; identifying, classifying, and remediating incidents; applying networking concepts such as DNS, TCP, IP, and firewalls; and performing business continuity and disaster recovery procedures.
The exam also expects candidates to implement architectural requirements such as high availability, performance, and capacity. That wording should shape your preparation: practise selecting and operating an appropriate solution under a stated constraint, not merely memorising what an individual service does.
Operations may be performed through the AWS Management Console and the AWS Command Line Interface. You should therefore understand the operational result of a command or console action, the conditions required for it to work, and the evidence you would inspect when it does not work.
Who is the intended candidate?
AWS identifies CloudOps engineers as the intended candidates for SOA-C03. Its target profile includes 1 year of experience with deployment, management, troubleshooting, networking, and security on AWS, plus at least 1 year in a related operations role such as system administrator.
Those experience statements are official target-candidate guidance, not a stated prerequisite that blocks registration. They are useful as a readiness test. Someone who has only watched demonstrations may need practical lab work before attempting scenario-based questions, while someone who regularly maintains AWS workloads can use the blueprint to locate gaps rather than start with introductory cloud theory.
The official recommended background includes monitoring, logging, and troubleshooting techniques; networking; high availability, performance, and capacity concepts; at least one scripting language; at least one major operating system; cloud computing; containerization and orchestration basics; CI/CD and Git.
AWS also recommends familiarity with the Well-Architected Framework, storage and container solutions, monitoring tools, the console, the AWS CLI, infrastructure as code, CloudFormation, networking and security services, financial management, hybrid and multi-VPC operations, databases such as Amazon RDS, Amazon DynamoDB, and Amazon ElastiCache, and compute services such as Amazon EC2, AWS Lambda, and Amazon ECS.
Use this profile to choose your starting point. If you lack networking or operating-system fundamentals, begin there. If those areas are familiar but your AWS troubleshooting is weak, move directly into domain-based labs and incident analysis.
How is the blueprint weighted?
Study allocation should follow the official scored-content weights, while still covering every domain. The three largest areas each account for 22% of scored content, followed by Networking and Content Delivery at 18% and Security and Compliance at 16%.
Content Domain 1: Monitoring, Logging, Analysis, Remediation, and Performance Optimization represents 22% of scored content. Prepare to interpret monitoring and logs, investigate operational symptoms, remediate faults, and improve performance rather than merely create alarms.
Content Domain 2: Reliability and Business Continuity represents 22% of scored content. Focus on resilient operation, recovery procedures, backup and restoration thinking, and choosing actions that protect workload continuity under failure conditions.
Content Domain 3: Deployment, Provisioning, and Automation represents 22% of scored content. Practise controlled provisioning, deployment changes, infrastructure as code, automation, and verification after a change.
Content Domain 4: Security and Compliance represents 16% of scored content. Study identity, permissions, encryption-related operational decisions, security controls, logging, and compliance enforcement in the context of an existing workload.
Content Domain 5: Networking and Content Delivery represents 18% of scored content. Concentrate on connectivity, routing, DNS, firewalls, VPN-related operations, and diagnosing how traffic reaches or fails to reach a workload.
The weights describe scored content, not a promise about the number of questions in each domain. Use them to prioritise study time, but do not neglect the 16% Security and Compliance domain simply because it has the smallest listed share. Security decisions often affect deployment, reliability, and networking scenarios as well.
What changed from SOA-C02?
Candidates moving from SOA-C02 should rebuild their study map around SOA-C03 rather than carry forward the old blueprint unchanged. The official comparison identifies added, removed, and recategorised material, including changes that affect monitoring, automation, compliance, and networking preparation.
SOA-C03 added configuring and managing the CloudWatch agent to collect metrics and logs from EC2 instances, Amazon ECS clusters, or Amazon EKS clusters in Task 1.1. Your lab notes should distinguish the agent from other CloudWatch collection and analysis capabilities, including what data is being collected and where you would inspect it.
Task 3.1 added creating and managing stacks of resources by using CloudFormation and the AWS CDK. If your older preparation focused only on manually provisioning resources, add repeatable infrastructure changes, stack lifecycle management, and post-deployment verification.
Task 4.1 added enforcing compliance requirements, including Region and service selections. Practise reading a requirement precisely and identifying the control or operational setting that enforces it, rather than choosing a broad security action that does not address the stated constraint.
Task 5.3 added configuring and analyzing CloudWatch network monitoring services. This makes network observability a deliberate study item, not merely a routing or security-group topic.
The comparison states that configuring S3 static website hosting was removed from Task 5.2. It also states that VPNs moved from Task 4.2 to Task 5.1, and that Tasks 6.1 and 6.2 from SOA-C02 moved to Task 1.3 in SOA-C03. Use the comparison page to audit any legacy course or notes before spending significant time on them.
What is the exam format and delivery?
The official AWS certification page states that SOA-C03 contains 65 questions using multiple-choice or multiple-response formats. It also states that the exam duration is 130 minutes. Treat the number of questions and the time limit as planning facts, but check the official page again when scheduling because certification information can change.
The exam includes 50 questions that affect your score and 15 unscored questions that do not affect your score. Because you cannot identify unscored items while working, answer every question using the same careful process and do not dismiss an unfamiliar item as irrelevant.
AWS reports results as a scaled score of 100–1,000, and the minimum passing score is 720. This is not a percentage-correct guarantee. Avoid converting the scaled score into an assumed raw percentage or treating practice-test percentages as an official prediction.
The listed exam languages are English, Japanese, Korean, and Simplified Chinese. SOA-C03 is offered through Pearson VUE testing centers or as an online-proctored exam. Review the official AWS certification page for current appointment, identification, equipment, and delivery requirements before you select a format.
The listed exam cost is 150 USD, subject to additional pricing information such as foreign-exchange rates. Verify the amount and any applicable regional details at checkout rather than relying on a third-party listing.
How should you study the five domains?
A useful approach is to study each domain through an operational loop: establish the intended state, observe the workload, diagnose the deviation, choose the least risky corrective action, and verify the result. This mirrors the decisions the blueprint describes more closely than memorising isolated service summaries.
For Monitoring, Logging, Analysis, Remediation, and Performance Optimization, build a symptom-to-evidence table. For each scenario, record what the symptom suggests, which metric or log could confirm it, what alternative explanations remain, and which remediation is reversible or least disruptive. Include EC2, ECS, EKS, application logs, alarms, and network monitoring in that exercise.
For Reliability and Business Continuity, write failure scenarios before reading solutions. Consider an unavailable instance, an impaired dependency, a bad deployment, lost data, or a regional problem. Then identify detection, recovery objective implications where provided by the scenario, backup or replication considerations, restoration steps, and the validation that confirms service recovery. Do not invent requirements that the question does not state.
For Deployment, Provisioning, and Automation, compare manual changes with repeatable changes. Practise reading CloudFormation or CDK intent, identifying dependency or configuration problems, planning a safe update, and checking whether the resulting resources match the required state. Include rollback and drift-oriented reasoning where relevant to the task statement.
For Security and Compliance, start with the requirement and its scope. Ask whether the issue concerns identity, access, data protection, network exposure, logging, Region selection, or service use. Then choose a control that enforces that requirement at the correct layer. A control that is generally secure but does not satisfy the stated scope is not the best answer.
For Networking and Content Delivery, draw traffic paths. Mark DNS resolution, entry points, routing, subnets, security groups, network ACLs, load balancing, endpoints, and application listeners as applicable. When a path fails, isolate the first boundary at which the expected traffic cannot proceed. Add VPN operations and CloudWatch network monitoring to the same troubleshooting map.
What practical labs are worth building?
Build small, disposable labs that force you to observe and repair a known problem. The goal is not to reproduce an enterprise platform; it is to practise evidence-led operations, safe changes, and verification across the services and concepts named in the blueprint.
Create a monitoring lab with an EC2 workload and a deliberate fault such as a stopped process or unhealthy application endpoint. Collect the relevant metrics and logs, create or inspect an alarm, identify the failure from evidence, apply a fix, and confirm that the signal returns to the expected state. Keep a record of the misleading symptoms you encountered.
Create a deployment lab that provisions a small set of resources through CloudFormation or the AWS CDK. Change one property, observe the update behavior, inspect failures, and verify the final state. Compare the template or code with the deployed resources. This exercise gives you a practical basis for questions about stacks, dependencies, configuration, and repeatability.
Create a network troubleshooting lab with separated subnets and a controlled workload. Test name resolution, route reachability, security-group behavior, network ACL behavior, and listener or endpoint configuration one variable at a time. Capture the test result and the layer that caused the failure. Avoid changing several controls at once, because that prevents you from learning which action resolved the problem.
Create a security lab that tests least-privilege access and a compliance condition such as a permitted Region or service choice. Document the requirement, the control that enforces it, and the audit evidence you would inspect. The exercise should teach you to connect policy intent with operational verification.
Use cost controls while labbing. Destroy resources when the exercise ends, set appropriate account safeguards, and avoid leaving workloads running unattended. Cost management is a practical recommendation here; the official exam guide’s target profile separately lists cloud financial management among the AWS knowledge areas.
How can you turn the blueprint into a study roadmap?
A four-stage roadmap works well: establish the baseline, learn by domain, troubleshoot integrated scenarios, and verify readiness. Move forward when you can explain both the correct action and why the plausible alternatives fail. Do not schedule solely because you have completed a video course or memorised a glossary.
Stage one is a gap assessment. Read the official exam guide and list every task under its five domains. Mark each task as familiar, partly familiar, or unpractised. For every “familiar” item, write one example from an actual lab or work-like exercise; if you cannot do that, classify it as partly familiar instead.
Stage two is domain construction. Study the three 22% domains first or distribute them across your available time, then cover Networking and Content Delivery at 18% and Security and Compliance at 16%. These percentages are study-priority signals, not permission to skip the smaller domain. For each task, create a short note containing purpose, inputs, observable outputs, failure modes, and recovery actions.
Stage three is integration. Combine domains in scenarios: a deployment that causes a monitoring alert, a security control that blocks a required network path, a capacity issue that requires a reliability decision, or a recovery event that depends on correctly configured storage and permissions. Explain the sequence aloud or in writing, including what you would inspect before making a change.
Stage four is readiness verification. Use legitimate practice questions that test reasoning rather than recalled wording. After each answer, record the domain, task, evidence in the scenario, and reason each distractor is unsuitable. Revisit weak tasks until you can solve a new scenario without relying on memorised phrases.
A practical scheduling decision follows from this process. Schedule when your evidence shows consistent understanding across the blueprint, you can work within the official 130-minute duration in practice, and you have reviewed the current SOA-C03 comparison. If your preparation depends on SOA-C02 material, pause and update it first.
How should you approach multiple-choice and multiple-response items?
Read the requirement before examining the answer choices. Identify the workload, the failure or objective, constraints such as availability or compliance, and the requested outcome. Then eliminate choices that solve a different problem, introduce unnecessary operational risk, or require information the scenario does not provide.
For multiple-response items, determine how many choices the question requires and assess each option independently. Do not select an answer merely because it is partly true in another context. A technically valid service can still be wrong when it does not meet the stated constraint or operational objective.
For troubleshooting questions, separate observation from assumption. A high error rate, for example, does not by itself prove a specific network, permissions, or application cause. Look for the evidence supplied by the scenario and choose the next diagnostic or corrective action that best narrows the problem.
For architecture and reliability questions, prefer the option that meets the stated requirement with an appropriate operational trade-off. Do not add unrequested complexity. Conversely, do not choose a simple option if the scenario explicitly requires high availability, recovery capability, compliance enforcement, or controlled deployment.
If two options appear plausible, compare their scope and timing. One may prevent recurrence while another only treats the immediate symptom; one may apply to a single resource while another enforces the requirement broadly. The wording usually indicates whether the question asks for diagnosis, remediation, prevention, or validation.
Which preparation mistakes cause avoidable gaps?
The most damaging mistake is studying the former exam version without checking the SOA-C03 comparison. That can leave you underprepared for CloudWatch agent work, CloudFormation and CDK stack management, compliance enforcement through Region or service selections, and CloudWatch network monitoring.
Another mistake is learning services in isolation. CloudOps decisions cross boundaries: a permission can prevent a deployment, a route can prevent monitoring, a failed dependency can appear as an application fault, and a recovery procedure can fail because of access or configuration. Use integrated scenarios after each domain rather than postponing them until the end.
Do not treat the console as the whole skill. The exam covers operations through both the AWS Management Console and the AWS CLI, and the recommended knowledge includes infrastructure as code and CloudFormation. Practise identifying the intended result and validating it, even when you use a different interface in the lab.
Do not over-focus on memorising service limits, command syntax, or product descriptions without understanding the decision context. Syntax can support an operation, but the question is more likely to test which evidence, control, or operational action fits the stated problem.
Do not infer that section-level feedback precisely diagnoses every weakness. AWS explicitly advises caution when interpreting section-level feedback. Use it as a signal, then return to the domain tasks and review the underlying concepts.
Finally, do not use exam dumps, leaked questions, or memorisation claims as a substitute for preparation. They do not establish operational competence, may be inaccurate or outdated, and cannot guarantee a passing result. Work from the official guide, legitimate learning resources, and hands-on reasoning instead.
What should you check before booking?
Before booking, verify that the appointment is for AWS Certified CloudOps Engineer – Associate, SOA-C03, rather than an older SOA-C02 listing or an unrelated certification that happens to use the SOA abbreviation. The official AWS page is the final reference for the current code, delivery choices, languages, and registration information.
Check your study notes against all five current domain names and weights. Confirm that the added SOA-C03 topics are represented, that removed S3 static website hosting content is not receiving disproportionate attention, and that VPN material is placed under the current networking task structure.
Confirm that you can explain your operational method: how you detect a problem, gather evidence, select a safe action, apply it through an AWS tool, and verify the outcome. If you can identify products but cannot describe that sequence, continue practising before scheduling.
Choose a Pearson VUE testing center or online-proctored delivery only after reviewing the current official requirements for that format. Make sure your identity and appointment details are consistent, and leave time before the appointment to resolve any delivery-specific uncertainty.
Finally, consider credential maintenance. AWS certification credentials are valid for three years from the date earned, after which recertification is required to keep them active. Treat recertification as a later planning obligation, not as a reason to rush an exam attempt before your SOA-C03 preparation is complete.
What should you do next?
Start with the official SOA-C03 exam guide and comparison page, then convert the task statements into a personal checklist. Build one small lab for monitoring, one for deployment automation, and one for network or security troubleshooting. After each exercise, write the evidence, action, and verification step you would use in an operational incident.
Next, audit every study resource for the SOA-C03 code and current domain names. Mark obsolete or unclear material, especially resources that retain the former six-domain structure. Use the official AWS certification page to confirm delivery and registration details immediately before booking.
If your checklist shows repeated gaps in a domain, study that domain and retest it with new scenarios rather than rereading the same notes. Schedule only when your preparation demonstrates transferable reasoning across the blueprint, not merely recognition of familiar service names.
Conclusion
C90.03 should be verified against the official AWS naming, but the evidence supplied here points to SOA-C03, AWS Certified CloudOps Engineer – Associate. Prepare for the work the exam represents: operating AWS workloads, interpreting evidence, making controlled changes, protecting reliability and security, and recovering from faults. Anchor your plan to the current five-domain blueprint, update any SOA-C02 material, practise through the console and CLI, and use the official AWS pages for final scheduling and policy checks.