AWS Certified SysOps Administrator Associate - Exam Guide
AWS Certified SysOps Administrator Associate - Exam Guide
Introduction
The AWS Certified SysOps Administrator - Associate (SOA-C02) exam is intended for
system administrators in a cloud operations role. The exam validates a candidate’s
ability to deploy, manage, and operate workloads on AWS.
The exam also validates a candidate’s ability to complete the following tasks:
The target candidate should have the following general IT knowledge and experience:
The target candidate should have the following AWS knowledge and experience:
Job tasks that are out of scope for the target candidate
The following list contains job tasks that the target candidate is not expected to be
able to perform. This list is non-exhaustive. These tasks are out of scope for the exam:
Refer to the Appendix for a list of in-scope AWS services and features and a list of
out-of-scope AWS services and features.
Exam content
Response types
As of March 28, 2023, the exam will consist of two types of questions until further
notice:
Multiple choice: Has one correct response and three incorrect responses
(distractors)
Multiple response: Has two or more correct responses out of five or more
response options
Multiple choice and multiple response: Select one or more responses that best
complete the statement or answer the question. Distractors, or incorrect answers, are
response options that a candidate with incomplete knowledge or skill might choose.
Distractors are generally plausible responses that match the content area.
Exam lab: Has a scenario that is composed of a set of tasks to perform in the
AWS Management Console or AWS CLI
Exam labs: Complete the required tasks for a given scenario in the AWS Management
Console or AWS CLI in the provided AWS account.
When you begin your exam, you will receive notification about the number of
questions in the multiple-choice and multiple-response section, and the number of
exam labs in the exam lab section. You will also learn the percentage of your score
that will be determined by your work in the exam labs. Plan to allocate 20 minutes to
complete each exam lab.
Finish all work on an exam lab before you move to the next exam lab. You will NOT
be able to return to a prior exam lab. You are welcome to use the virtual machine
notepad or AWS CLI while working on your exam labs.
There might be more than one way to perform an exam lab. In those cases, you will
receive full credit if you achieve the correct end state to the scenario. You will receive
partial credit for partial completion of exam labs. However, exam content and the
associated scoring are confidential, so you will receive no further information
regarding partial credit that is awarded for an exam lab.
Tip: If you take your exam through online proctoring, you can use an external
monitor as your ONLY display. Set your screen resolution to 1280 pixels x 1024
pixels or greater for a PC, and 1440 pixels x 900 pixels or greater for a Mac. Set
the scaling to 100%. Other settings might result in a need to scroll within the
console.
On the exam, unanswered questions are scored as incorrect. There is no penalty for
guessing. The exam includes 50 questions that affect your score. These questions
Unscored content
The exam includes 15 unscored questions that do not affect your score. AWS collects
information about performance on these unscored questions to evaluate these
questions for future use as scored questions. These unscored questions are not
identified on the exam.
Exam results
The AWS Certified SysOps Administrator - Associate (SOA-C02) exam has a pass or
fail designation. The exam is scored against a minimum standard established by AWS
professionals who follow certification industry best practices and guidelines.
Your results for the exam are reported as a scaled score of 100–1,000. The minimum
passing score is 720. Your score shows how you performed on the exam as a whole
and whether you passed. Scaled scoring models help equate scores across multiple
exam forms that might have slightly different difficulty levels.
Your score report could contain a table of classifications of your performance at each
section level. The exam uses a compensatory scoring model, which means that you do
not need to achieve a passing score in each section. You need to pass only the overall
exam.
Each section of the exam has a specific weighting, so some sections have more
questions than other sections have. The table of classifications contains general
information that highlights your strengths and weaknesses. Use caution when you
interpret section-level feedback.
This exam guide includes weightings, content domains, and task statements for the
exam. This guide does not provide a comprehensive list of the content on the exam.
However, additional context for each task statement is available to help you prepare
for the exam.
Task Statement 1.1: Implement metrics, alarms, and filters by using AWS monitoring
and logging services.
Identify, collect, analyze, and export logs (for example, Amazon CloudWatch
Logs, CloudWatch Logs Insights, AWS CloudTrail logs).
Collect metrics and logs by using the CloudWatch agent.
Create CloudWatch alarms.
Create metric filters.
Create CloudWatch dashboards.
Configure notifications (for example, Amazon Simple Notification Service
[Amazon SNS], Service Quotas, CloudWatch alarms, AWS Health events).
Task Statement 1.2: Remediate issues based on monitoring and availability metrics.
Configure Elastic Load Balancing (ELB) and Amazon Route 53 health checks.
Differentiate between the use of a single Availability Zone and Multi-AZ
deployments (for example, Amazon EC2 Auto Scaling groups, ELB, Amazon
FSx, Amazon RDS).
Implement fault-tolerant workloads (for example, Amazon Elastic File System
[Amazon EFS], Elastic IP addresses).
Implement Route 53 routing policies (for example, failover, weighted, latency
based).
Automate snapshots and backups based on use cases (for example, RDS
snapshots, AWS Backup, RTO and RPO, Amazon Data Lifecycle Manager,
retention policy).
Restore databases (for example, point-in-time restore, promote read replica).
Implement versioning and lifecycle rules.
Configure Amazon S3 Cross-Region Replication (CRR).
Perform disaster recovery procedures.
Task Statement 4.1: Implement and manage security and compliance policies.
Configure a VPC (for example, subnets, route tables, network ACLs, security
groups, NAT gateway, internet gateway).
Configure private connectivity (for example, Systems Manager Session
Manager, VPC endpoints, VPC peering, VPN).
Configure AWS network protection services (for example, AWS WAF, AWS
Shield).
Task Statement 5.2: Configure domains, DNS services, and content delivery.
Interpret VPC configurations (for example, subnets, route tables, network ACLs,
security groups).
Collect and interpret logs (for example, VPC Flow Logs, ELB access logs, AWS
WAF web ACL logs, CloudFront logs).
Identify and remediate CloudFront caching issues.
Troubleshoot hybrid and private connectivity issues.
The following list contains AWS services and features that are in scope for the exam.
This list is non-exhaustive and is subject to change. AWS offerings appear in
categories that align with the offerings’ primary functions:
Analytics:
Application Integration:
Amazon EventBridge
Amazon Simple Notification Service (Amazon SNS)
Amazon Simple Queue Service (Amazon SQS)
Compute:
Database:
Amazon Aurora
Amazon DynamoDB
Amazon ElastiCache
Amazon RDS
AWS CLI
AWS CloudFormation
AWS CloudTrail
Amazon CloudWatch
AWS Compute Optimizer
AWS Config
AWS Control Tower
AWS Health Dashboard
AWS License Manager
AWS Management Console
AWS Organizations
AWS Service Catalog
AWS Systems Manager
AWS Trusted Advisor
AWS DataSync
AWS Transfer Family
Amazon CloudFront
Elastic Load Balancing (ELB)
AWS Global Accelerator
Amazon Route 53
AWS Transit Gateway
Amazon VPC
AWS VPN
Storage:
AWS Backup
Amazon Elastic Block Store (Amazon EBS)
Amazon Elastic File System (Amazon EFS)
Amazon FSx
Amazon S3
Amazon S3 Glacier
AWS Storage Gateway
The following list contains AWS services and features that are out of scope for the
exam. This list is non-exhaustive and is subject to change. AWS offerings that are
entirely unrelated to the target job roles for the exam are excluded from this list:
Analytics:
Amazon EMR
Amazon Chime
Amazon Connect
Amazon WorkDocs
Amazon WorkMail
Compute:
Amazon Lightsail
Containers:
Database:
Amazon Redshift
Developer Tools:
AWS CodeBuild
AWS CodeCommit
AWS CodeDeploy
AWS CodeStar
AWS X-Ray
Game Tech:
Amazon GameLift
Machine Learning:
Media Services:
Storage:
AWS Snowmobile
Survey
How useful was this exam guide? Let us know by taking our survey.