Skip to content

CloudOps Engineer - Associate Practice Questions

Prepare for SOA-C03 with more than an answer.

240 questions in the full set17 sample questionsUpdated Jan 28, 2026

Unlock the full exam and previous versions

  • v1AWS Certified CloudOps Engineer - Associate 240 questions Current
  • SOA-C01Legacy AWS Certified SysOps Administrator 54 questions Locked
  • SOA-C02Legacy AWS Certified SysOps Administrator - Associate 134 questions Locked
  • SOA-C02-2Legacy SysOps Administrator Associate - Extended 957 questions Locked
Exam fee
$150 USD
Time limit
130 minutes
Questions on the exam
65
Passing score
720 (scale 100-1000)
Level
Associate
Valid for
3 years
Domains covered on the exam 5
  1. Monitoring, Logging, Analysis, Remediation, and Performance Optimization22%
  2. Reliability and Business Continuity22%
  3. Deployment, Provisioning, and Automation22%
  4. Security and Compliance16%
  5. Networking and Content Delivery18%
  1. 1

    A CloudOps engineer is configuring an Auto Scaling group for an application that experiences rapid, short-term spikes in traffic followed by periods of calm. The goal is to scale out aggressively but scale in slowly to prevent 'thrashing'. Which scaling policy is most appropriate?

    Show answer details

    Correct answer: B

    Step Scaling allows you to define different scaling actions based on the magnitude of the alarm breach. Crucially, it allows you to set the 'Instance Warmup' time, which prevents new instances from being counted in metrics immediately, and you can control scale-in behavior more granularly than Target Tracking, helping to avoid thrashing.

  2. 2

    A global enterprise requires a Disaster Recovery (DR) solution for their mission-critical database which runs on Amazon Aurora PostgreSQL. They have a strict Recovery Time Objective (RTO) of less than 15 minutes and a Recovery Point Objective (RPO) of less than 1 second in case of a complete region failure. They want to adopt a 'Pilot Light' strategy where the DR region is active but minimal. Which architecture best fits these requirements?

    Show answer details

    Correct answer: C

    Aurora Global Database replicates data to the secondary region with typical latency of < 1 second (meeting RPO). Promoting a secondary cluster to primary typically takes less than 1 minute (meeting RTO). This fits the requirement perfectly.

    graph LR RegionA[Region A: Primary] --Replication RegionB[Region B: Secondary] AppA[App] --> RegionA AppB[App (Idle)] -.-> RegionB style RegionA fill:#cfc style RegionB fill:#fcc
  3. 3

    A company hosts a website on EC2 instances behind an Application Load Balancer in the primary region and a static maintenance page on S3 in a secondary region. They want to configure Amazon Route 53 to route traffic to the S3 bucket only if the primary region's ALB is unhealthy. Which routing policy and configuration should be used?

    Show answer details

    Correct answer: A

    Failover routing is designed for active-passive configurations. The primary record (ALB) is associated with a health check. If the health check fails, Route 53 automatically switches traffic to the secondary record (S3 bucket).

  4. 4

    A compliance officer requires that all EBS volumes and RDS snapshots are backed up daily and retained for 7 years. The backups must be copied to a separate, isolated AWS account for protection against ransomware. What is the most operationally efficient way to achieve this?

    Show answer details

    Correct answer: B

    AWS Backup supports cross-account backup copying within an AWS Organization. You can define a backup plan in the source account that takes the backup and copies it to a Backup Vault in the destination (isolated) account, handling encryption and retention automatically.

  5. 5

    A startup is launching a new marketing campaign. They expect traffic to the Amazon DynamoDB tables to be unpredictable, with potential spikes of 100x normal load followed by idle periods. They want to avoid throttling errors without paying for peak capacity 24/7. Which capacity mode should they choose?

    Show answer details

    Correct answer: A

    On-demand capacity mode instantly accommodates your workloads as they ramp up or down to any previously reached traffic level, without throttling. It is ideal for unpredictable workloads where you pay per request rather than provisioning throughput.

  6. 6

    A CloudOps team is managing a fleet of Amazon EC2 instances running a legacy Java application. The team needs to monitor the memory utilization of these instances to right-size the fleet. However, the default Amazon CloudWatch metrics do not provide this data. Which action should the team take to collect this specific metric?

    Show answer details

    Correct answer: B

    By default, Amazon EC2 sends metrics to CloudWatch for CPU, disk I/O, and network, but not memory. To collect memory utilization, the unified CloudWatch agent must be installed and configured on the instances to push custom metrics to CloudWatch.

  7. 7

    A financial institution requires a complex monitoring setup for their transaction processing system. They need to trigger an automated remediation workflow only when three distinct conditions are met simultaneously: High CPU on the web tier, High Database Connections on the RDS tier, and High Latency on the Application Load Balancer. Which CloudWatch feature should be used to minimize noise and trigger the workflow only when all conditions are true?

    Show answer details

    Correct answer: B

    CloudWatch Composite Alarms allow you to combine multiple metric alarms using boolean logic (AND, OR, NOT). This ensures that the action is only taken when the specific combination of conditions is met, reducing alarm fatigue and ensuring precise remediation triggers.

    graph TD A[CPU Alarm] --> D{Composite Alarm} B[DB Conn Alarm] --> D C[Latency Alarm] --> D D -->|AND Condition Met| E[Trigger Remediation]
  8. 8

    An organization manages multiple AWS accounts using AWS Organizations. The Operations Manager wants a single pane of glass to view critical metrics from all member accounts in the management account. What is the most efficient way to achieve this?

    Show answer details

    Correct answer: D

    CloudWatch cross-account observability allows a monitoring account to view metrics, logs, and traces from multiple source accounts. By setting up the link, the management account can display widgets from member accounts on a single dashboard without complex role assumption scripts.

Create an account to continue.