AWS SOA-C03 Multiple choice 65 questions 130 minutes

AWS Certified CloudOps Engineer - Associate

Running workloads on AWS: monitoring and automated remediation, reliability and backups, deployment and automation with CloudFormation and Systems Manager, security controls, and VPC networking and content delivery. Formerly the SysOps Administrator - Associate exam.

The blueprint

A mock exam here has 65 questions in 130 minutes, split across the domains in the same proportions as the official exam guide. The official pass mark is 720 of 1,000 (scaled). FixOps scores practice against a target of 75%.

  1. 01

    Monitoring, Logging, Analysis, Remediation, and Performance Optimization

    22%

  2. 02

    Reliability and Business Continuity

    22%

  3. 03

    Deployment, Provisioning, and Automation

    22%

  4. 04

    Security and Compliance

    16%

  5. 05

    Networking and Content Delivery

    18%

Sample questions

Three of the 10 questions in the free diagnostic. Open one to see the answer and why.

An operations team wants a CloudWatch alarm on the memory utilisation of its EC2 instances, but finds no such metric. What is needed?
  • A CloudTrail trail with data events turned on
  • An AWS Config rule for the instance type
  • Detailed monitoring on the instances, which adds memory and disk space metrics at one-minute intervals
  • The CloudWatch agent on the instances, configured to publish memory metrics

Answer: The CloudWatch agent on the instances, configured to publish memory metrics. EC2 publishes what the hypervisor can see: CPU, network, disk operations and status checks. Memory and disk space are inside the operating system, so the CloudWatch agent has to collect them. Detailed monitoring only changes the period of the standard metrics from five minutes to one.

A security group rule was changed overnight. Which service shows who made the API call and from which IP address?
  • AWS CloudTrail
  • AWS Trusted Advisor
  • Amazon CloudWatch metrics
  • Amazon Inspector

Answer: AWS CloudTrail. CloudTrail records API activity in the account: the identity, time, source IP address and parameters of each call. CloudWatch metrics are numbers about performance, Trusted Advisor gives recommendations, and Inspector scans for software vulnerabilities.

An Auto Scaling group should keep its average CPU utilisation near 50% without the team defining alarms and step sizes. Which policy type does this?
  • Manual scaling
  • Scheduled scaling
  • Simple scaling with a 300-second cooldown and a fixed adjustment of one instance
  • Target tracking scaling

Answer: Target tracking scaling. A target tracking policy takes a metric and a target value, creates the alarms itself and adds or removes capacity to keep the metric near the target, much as a thermostat does. Scheduled scaling acts at set times, whatever the load.

Revision notes: Monitoring, Logging, Analysis, Remediation, and Performance Optimization

The notes for one domain, free to read here and in the app. FixOps Pro has them for all 5 domains.

Collecting metrics and logs with CloudWatch and CloudTrail, alarming and notifying, remediating automatically with EventBridge and Systems Manager, and tuning compute, storage and databases.

Metrics, logs and trails

  • EC2 does not publish memory or disk space metrics; the CloudWatch agent collects them from inside the instance.
  • Basic monitoring sends EC2 metrics every five minutes; detailed monitoring sends them every minute.
  • The CloudWatch agent needs an IAM role that allows it to publish, and its configuration is commonly kept in Parameter Store.
  • CloudTrail records who made which API call; Event history keeps 90 days of management events without a trail.
  • S3 object-level calls and Lambda invocations are data events and are logged only when enabled on a trail.
  • Log file integrity validation proves that CloudTrail logs were not altered; an organization trail covers every account.
  • A new log group never expires its events until a retention period is set.
  • A metric filter turns a log pattern into a metric; Logs Insights answers ad hoc questions with queries.
  • Amazon Managed Service for Prometheus stores Prometheus metrics and is queried with PromQL; Container Insights covers ECS and EKS.

Alarms, dashboards and notifications

  • An alarm is in OK, ALARM or INSUFFICIENT_DATA; the last means there is not enough data to decide.
  • Datapoints to alarm and evaluation periods express M out of N, such as 3 breaches in the last 5 periods.
  • How an alarm treats missing data is a setting: missing, not breaching, breaching or ignore.
  • A composite alarm combines other alarms with AND, OR and NOT to reduce noise.
  • The recover action on StatusCheckFailed_System moves an instance to healthy hardware and keeps its ID and addresses.
  • Anomaly detection alarms on a band of expected values instead of a fixed threshold.
  • Cross-account observability links source accounts to a monitoring account; a dashboard can show several Regions.
  • A service can publish to an SNS topic only if the topic's access policy allows it.
  • An encrypted topic needs a customer managed key whose policy lets the publishing service use it.
  • Email subscriptions deliver nothing until they are confirmed.

Automated remediation

  • EventBridge rules match events exactly, including case, and send them to targets such as Lambda and Automation runbooks.
  • A dead-letter queue on a target keeps events that could not be delivered after retries.
  • A central event bus accepts events from other accounts only if its resource-based policy allows them.
  • A Systems Manager Automation runbook is a document of steps; it runs with the permissions of the role it assumes.
  • An approval step pauses an automation until approvers respond.
  • AWS Health events, such as scheduled maintenance, arrive through EventBridge.

Compute and storage performance

  • A burstable instance with no CPU credits left is held to its baseline in standard mode.
  • Compute Optimizer recommends instance types from utilisation history; it sees memory only if the agent publishes it.
  • gp2 bursts on credits and scales with size; gp3 gives 3,000 IOPS on any size, with more available independently.
  • A high VolumeQueueLength means the workload asks for more I/O than the volume delivers.
  • Elastic Volumes changes size, type and IOPS while the volume stays attached.
  • Multipart upload retries only failed parts; Transfer Acceleration speeds up long-distance uploads through edge locations.
  • Lifecycle rules move ageing objects to colder storage classes; DataSync moves files between on-premises storage and AWS.

Shared storage, databases and placement

  • EFS is NFS for Linux, mounted from every Availability Zone; its lifecycle management moves untouched files to cheaper storage.
  • FSx for Windows File Server provides SMB with Active Directory; FSx for Lustre gives high throughput over data in S3.
  • Performance Insights shows database load by wait event and SQL statement.
  • Enhanced Monitoring reports operating system metrics of an RDS instance, including processes.
  • RDS Proxy pools connections, which helps when many Lambda functions connect.
  • A read replica takes read traffic off the primary; a Multi-AZ standby cannot be queried.
  • A cluster placement group gives the lowest latency in one zone; spread puts each instance on distinct hardware, up to seven per zone.
  • A partition placement group separates groups of instances by rack, for systems such as Kafka and HDFS.

Easy to mix up

  • CloudTrail answers who did it; CloudWatch answers how the system is behaving.
  • A metric filter creates a metric from logs; a subscription filter streams log events elsewhere.
  • A failed system status check is the host (recover); a failed instance status check is inside the instance (reboot).
  • gp2 performance depends on size; gp3 performance is set independently of size.
  • Cluster packs instances together for speed; spread and partition keep them apart for resilience.
  • Performance Insights looks at database load; Enhanced Monitoring looks at the operating system.

Practice questions written by FixOps from the public SOA-C03 exam guide. They are not real exam questions. FixOps is not affiliated with or endorsed by Amazon Web Services.

Your pager is ready.

Free, instant, and it works on your phone. No signup: start as a guest and save your progress later.