SOA-C03 Exam Details

  • Exam Code
    :SOA-C03
  • Exam Name
    :AWS Certified CloudOps Engineer - Associate (SOA-C03)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :263 Q&As
  • Last Updated
    :Jul 14, 2026

Amazon SOA-C03 Online Questions & Answers

  • Question 71:

    A company uses an Auto Scaling group with target tracking based on CPU utilization. During traffic spikes, application latency increases before scaling occurs. The workload processes messages from an Amazon SQS queue.

    Which change will MOST EFFECTIVELY improve scaling responsiveness?

    A. Reduce the Auto Scaling cooldown period.
    B. Switch from target tracking to simple scaling.
    C. Use CloudWatch metric math to scale on SQS backlog per instance.
    D. Increase the maximum capacity of the Auto Scaling group.

  • Question 72:

    A company runs an application on Amazon EC2 instances behind an Elastic Load Balancer (ELB) in an Auto Scaling group. The application performs well except during a 2-hour period of daily peak traffic, when performance slows.

    A CloudOps engineer must resolve this issue with minimal operational effort.

    What should the engineer do?

    A. Adjust the minimum capacity of the Auto Scaling group to the size required to meet the increased demand during the 2-hour period.
    B. Adjust the launch template that is associated with the Auto Scaling group to be more sensitive to increases in user traffic.
    C. Create a scheduled scaling action to scale out the number of EC2 instances shortly before the increase in user traffic occurs.
    D. Manually add a few more EC2 instances to the Auto Scaling group to support the increase in user traffic. Enable instance scale-in protection on the Auto Scaling group.

  • Question 73:

    A company requires the rotation of administrative credentials for production workloads on a regular basis. A CloudOps engineer must implement this policy for an Amazon RDS DB instance's master user password.

    Which solution will meet this requirement with the LEAST operational effort?

    A. Create an AWS Lambda function to change the RDS master user password. Create an Amazon EventBridge scheduled rule to invoke the Lambda function.
    B. Create a new SecureString parameter in AWS Systems Manager Parameter Store. Encrypt the parameter with an AWS Key Management Service (AWS KMS) key. Configure automatic rotation.
    C. Create a new String parameter in AWS Systems Manager Parameter Store. Configure automatic rotation.
    D. Create a new RDS database secret in AWS Secrets Manager. Apply the secret to the RDS DB instance. Configure automatic rotation.

  • Question 74:

    A company must ensure that any new IAM policy granting public access to resources is detected quickly and investigated. The CloudOps engineer needs near real-time visibility into policy changes and the identity that made the change.

    Which solution will meet these requirements?

    A. Enable AWS CloudTrail and monitor IAM policy-related API calls; send notifications when specific events occur.
    B. Use VPC Flow Logs to detect policy changes.
    C. Enable Amazon Inspector to scan IAM policies continuously.
    D. Use EC2 instance recovery to restore prior IAM state.

  • Question 75:

    A company's security policy requires incoming SSH traffic to be restricted to a defined set of addresses. The company is using an AWS Config rule to check whether security groups allow unrestricted incoming SSH traffic.

    A CloudOps engineer discovers a noncompliant resource and fixes the security group manually. The CloudOps engineer wants to automate the remediation of other noncompliant resources.

    What is the MOST operationally efficient solution that meets these requirements?

    A. Create a CloudWatch alarm for the AWS Config rule and invoke a Lambda function to remediate.
    B. Configure an automatic remediation via AWS Config rule using AWS- DisableIncomingSSHOnPort22.
    C. Create an EventBridge rule for AWS Config events and invoke a Lambda function.
    D. Run a scheduled Lambda function to inspect and remediate security groups.

  • Question 76:

    A user working in the Amazon EC2 console increased the size of an Amazon Elastic Block Store (Amazon EBS) volume attached to an Amazon EC2 Windows instance. The change is not reflected in the file system.

    What should a CloudOps engineer do to resolve this issue?

    A. Extend the file system with operating system-level tools to use the new storage capacity.
    B. Reattach the EBS volume to the EC2 instance.
    C. Reboot the EC2 instance that is attached to the EBS volume.
    D. Take a snapshot of the EBS volume. Replace the original volume with a volume that is created from the snapshot.

  • Question 77:

    A CloudOps engineer must optimize storage performance for an Amazon EC2 Linux instance. The instance uses an Amazon EBS gp3 volume, and the workload experiences sustained high IOPS demand at predictable times each day. The engineer wants to avoid changing instance type.

    Which solution will MOST directly address the bottleneck?

    A. Enable EC2 hibernation to reduce disk usage.
    B. Increase the gp3 volume's provisioned IOPS and throughput settings.
    C. Convert the gp3 volume to magnetic storage for cost savings.
    D. Create an AMI of the instance and relaunch it in a different Availability Zone.

  • Question 78:

    A CloudOps engineer needs to detect a recurring application error pattern in Amazon CloudWatch Logs and reduce alert noise.

    The engineer must send only one notification if the error occurs across multiple log groups within a short time window.

    Which solution will meet this requirement?

    A. Create a CloudWatch Logs subscription filter for each log group and send all matches to email.
    B. Create one CloudWatch alarm per log group and configure all alarms to send notifications directly to Amazon SNS.
    C. Create metric filters for each log group, create CloudWatch alarms for the derived metrics, and use a CloudWatch composite alarm to notify only when multiple alarms are in ALARM.
    D. Enable VPC Flow Logs and alert when traffic increases.

  • Question 79:

    A company wants to monitor the p95 latency of an application based on log data.

    Which CloudWatch feature should be used?

    A. Contributor Insights
    B. Metric filters
    C. Subscription filters
    D. Anomaly detection

  • Question 80:

    An errant process is known to use an entire processor and run at 100% CPU. A CloudOps engineer wants to automate restarting an Amazon EC2 instance when the problem occurs for more than 2 minutes.

    How can this be accomplished?

    A. Create an Amazon CloudWatch alarm for the EC2 instance with basic monitoring. Add an action to restart the instance.
    B. Create an Amazon CloudWatch alarm for the EC2 instance with detailed monitoring. Add an action to restart the instance.
    C. Create an AWS Lambda function to restart the EC2 instance, invoked on a scheduled basis every 2 minutes.
    D. Create an AWS Lambda function to restart the EC2 instance, invoked by EC2 health checks.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SOA-C03 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.