Course curriculum
AWS Certified CloudOps Engineer Associate SOA-C03 [2026]
Curriculum
Modules and lessons
Module 01
AWS Certified CloudOps Engineer Associate SOA-C03 [2026]
- 01AWS Certified CloudOps Engineer Associate SOA-C03 Exam Guide and Domain BreakdownA practical study guide to the AWS Certified CloudOps Engineer Associate SOA-C03 exam format, scoring, domains, service scope, and preparation strategy.Open lesson →
- 02AWS Hands-On Practice: Free Tier Accounts vs. Sandbox Challenge LabsCompare AWS Free Tier accounts and sandbox challenge labs to choose a safe, effective hands-on practice environment for CloudOps study.Open lesson →
- 03AWS Account Overview: Root User, IAM, Authentication, and Regional ResourcesReview AWS account setup requirements, root-user security, IAM identities and policies, authentication methods, and the relationship between global IAM and regional AWS resources.Open lesson →
- 04AWS Account Creation: Free Plan, Paid Plan, Credits, and Safe SetupLearn how to choose and create an AWS Free Plan or Paid Plan account, understand credits and expiration, avoid unexpected charges, and complete the initial login setup safely.Open lesson →
- 05AWS Account Configuration and Budget Alerts for CloudOps LabsConfigure an AWS account alias, IAM billing access, billing notifications, free tier alerts, and a monthly AWS Budget to monitor lab costs.Open lesson →
- 06AWS IAM Deep Dive: Principals, Authentication, Authorization, Users, Groups, and RolesStudy AWS IAM principals, authentication methods, policies, users, groups, roles, programmatic access, and application authorization for the AWS Certified CloudOps Engineer Associate SOA-C03.Open lesson →
- 07AWS IAM User and Group Creation: Console Access and Permission InheritanceLearn how to create an AWS IAM group and user, assign administrator permissions through group membership, and sign in with the individual IAM user for lab work.Open lesson →
- 08AWS CLI, CloudShell, and Development Tool Setup for SOA-C03Set up Visual Studio Code, the AWS CLI, and AWS CloudShell, then verify command-line access and understand authentication and platform differences.Open lesson →
- 09Amazon VPC Fundamentals: Regions, Subnets, Routing, and EndpointsStudy the AWS VPC fundamentals tested in CloudOps operations, including regional isolation, Availability Zone subnets, CIDR blocks, route tables, internet gateways, and public versus private service access.Open lesson →
- 10Create a Custom AWS VPC: Wizard and Manual ConfigurationLearn how to create a custom AWS VPC with public and private subnets, route tables, an internet gateway, automatic public IP assignment, and basic connectivity testing.Open lesson →
- 11AWS Security Groups and Network ACLs: Stateful and Stateless VPC Traffic FilteringUnderstand how AWS Security Groups and Network ACLs differ in scope, rule behavior, state tracking, and traffic-filtering decisions within a VPC.Open lesson →
- 12AWS Security Groups and Network ACLs: Stateful and Stateless Traffic ControlStudy how AWS security groups and network ACLs control traffic, including statefulness, rule evaluation order, security group references, and troubleshooting techniques.Open lesson →
- 13Using IPv6 in an AWS VPC: Addressing, Routing, and Egress-Only Access | SOA-C03Study how IPv6 addressing, subnet allocation, route tables, internet gateways, and egress-only internet gateways work in an AWS VPC.Open lesson →
- 14AWS VPC Flow Logs: Configuration, IAM Permissions, Destinations, and TroubleshootingLearn how to configure AWS VPC Flow Logs at the VPC, subnet, or network-interface level, deliver records to CloudWatch Logs or Amazon S3, and validate IAM and traffic-generation requirements.Open lesson →
- 15Amazon EC2 Overview: Instances, Networking, Storage, and Workload SelectionStudy Amazon EC2 instance types, VPC networking, IP addresses, EBS and instance store, lifecycle states, and workload-selection tradeoffs for AWS CloudOps Engineer Associate preparation.Open lesson →
- 16Launching and Managing EC2 Instances and EBS Volumes: Console and CLI Lab GuideStudy guide to selecting AMIs and instance types, resizing EC2 instances, creating and mounting EBS volumes, using the AWS CLI, and cleaning up lab resources.Open lesson →
- 17AWS EC2 Instance Lifecycle: States, Stop/Start, Reboot, Hibernate, and TerminationStudy EC2 instance lifecycle states, including stop/start, hibernation, rebooting, termination, addressing behavior, storage costs, host migration, and recovery considerations for the AWS Certified CloudOps Engineer Associate exam.Open lesson →
- 18AWS Nitro Instances and Nitro Enclaves: Performance, Architecture, and Security | SOA-C03Study AWS Nitro System architecture, Nitro instance performance characteristics, bare metal versus virtualized instances, and Nitro Enclave security capabilities for the SOA-C03 exam.Open lesson →
- 19AWS Serverless Services and Event-Driven Architecture | SOA-C03Study AWS Lambda, SQS, SNS, and event-driven serverless architectures, including decoupling patterns, scaling behavior, and service-selection decisions for SOA-C03.Open lesson →
- 20AWS Storage Fundamentals: S3, EFS, and FSxCompare Amazon S3 object storage with Amazon EFS and Amazon FSx file storage, including access methods, workload fit, connectivity, and key CloudOps decisions.Open lesson →
- 21AWS EFS: Mounting Shared Files on EC2 with NFS, IAM, and TLSLearn how to connect EC2 instances across Availability Zones to Amazon EFS, configure NFS security, enforce TLS, and choose the correct mount method.Open lesson →
- 22Working with Amazon S3 Objects Using the AWS CLI and Python SDKPractice creating S3 buckets and uploading, downloading, listing, updating, and deleting objects with the AWS CLI and Python Boto3 SDK.Open lesson →
- 23AWS Databases: RDS, Aurora, and ElastiCache Study GuideStudy RDS, Aurora, and ElastiCache architecture, scaling, availability, encryption, caching choices, and CloudOps decision points for AWS Certified CloudOps Engineer Associate.Open lesson →
- 24Amazon RDS Security: VPC Access, Encryption, KMS, and Read Replicas | AWS SOA-C03Study Amazon RDS security for SOA-C03, including VPC access, security groups, TLS, encryption at rest, KMS, snapshots, and read-replica encryption rules.Open lesson →
- 25AWS RDS MySQL: Create, Monitor, Back Up, and Delete a DatabaseStudy how to create and manage an Amazon RDS MySQL database, inspect connectivity and monitoring data, use backups and snapshots, evaluate replicas, and safely delete the instance.Open lesson →
- 26Amazon CloudWatch Overview: Metrics, Alarms, Logs, and Automated RemediationStudy Amazon CloudWatch metrics, monitoring intervals, agents, alarms, logs, events, and automated EC2 scaling actions for the AWS Certified CloudOps Engineer Associate SOA-C03 exam.Open lesson →
- 27AWS CloudWatch Metrics, Namespaces, Dimensions, and Statistics: SOA-C03 Study GuideStudy AWS CloudWatch metric structure, namespaces, dimensions, retention periods, statistics, timestamps, and metric API actions for the SOA-C03 exam.Open lesson →
- 28AWS Unified CloudWatch Agent: Installation, Metrics, Logs, and Systems ManagerStudy the AWS Unified CloudWatch Agent, including supported environments, metric and log collection, installation workflow, IAM requirements, configuration, and Systems Manager integration.Open lesson →
- 29Amazon CloudWatch Logs: Centralization, Retention, Analysis, and DeliveryStudy Amazon CloudWatch Logs for SOA-C03, including log sources, streams and groups, retention, metric filters, subscription filters, permissions, and analysis workflows.Open lesson →
- 30AWS CloudWatch Logs and Metric Filters: EC2 Monitoring and 404 AlarmsLearn how to stream EC2, CloudWatch agent, and Apache logs to CloudWatch Logs, create a 404 metric filter, and trigger an alarm.Open lesson →
- 31AWS CloudWatch Custom Dashboards: EC2 Metrics, Tags, and Logs InsightsBuild CloudWatch dashboards that filter EC2 metrics by tags or instance family and add CloudWatch Logs Insights results as dashboard widgets.Open lesson →
- 32Amazon SNS: Topics, Push Messaging, and SQS Fanout for AWS CloudOpsStudy Amazon SNS publisher-subscriber messaging, push-based delivery, endpoint integrations, and SNS-to-SQS fanout patterns for AWS CloudOps operations.Open lesson →
- 33Configure Amazon SNS Notifications with Amazon SQSLearn how to connect an Amazon SNS standard topic to an Amazon SQS standard queue, publish messages, verify delivery, and use fan-out processing patterns.Open lesson →
- 34AWS CloudTrail: Events, Retention, Trails, and Monitoring — SOA-C03 2026Study AWS CloudTrail auditing, event types, retention, trails, integrity validation, and integrations with Amazon S3, CloudWatch, EventBridge, SNS, and Lambda for the SOA-C03 exam.Open lesson →
- 35AWS EventBridge Event Sources, Rules, Event Patterns, and TargetsStudy how AWS EventBridge receives events from AWS services and CloudTrail, matches event patterns, and routes matching events to targets such as SNS, Lambda, and DynamoDB.Open lesson →
- 36Amazon EventBridge: Event Buses, Rules, Patterns, and Targets | AWS Certified CloudOps Engineer Associate SOA-C03Study how Amazon EventBridge routes AWS, custom, and SaaS events through event buses, rules, event patterns, and targets for monitoring and remediation workflows.Open lesson →
- 37Amazon EventBridge: Triggering Lambda from EC2 Stop EventsLearn how CloudTrail, Amazon EventBridge, Lambda, and CloudWatch Logs work together to detect and record EC2 StopInstances API events.Open lesson →
- 38AWS Config: Configuration Compliance, History, and RemediationStudy AWS Config for SOA-C03 by learning how to evaluate resource configurations, track drift and history, notify on changes, and automate remediation.Open lesson →
- 39AWS Systems Manager: Managed Nodes, Automation, Session Manager, and Parameter StoreStudy AWS Systems Manager capabilities for managed-node onboarding, automation, patching, compliance, secure access, and hierarchical parameter storage in the SOA-C03 CloudOps context.Open lesson →
- 40AWS Config Rules and SSM Automation Remediation for Public Security Group AccessLearn how to use AWS Config and Systems Manager Automation to detect and remediate unrestricted security group access while allowing authorized web traffic on TCP port 80.Open lesson →
- 41AWS Health API, Personal Health Dashboard, and Service Health DashboardUnderstand how the AWS Health API, Personal Health Dashboard, and Service Health Dashboard differ in personalization, notifications, resource impact, and remediation planning.Open lesson →
- 42AWS CloudOps Metric Analysis and Tracing: X-Ray, Prometheus, and GrafanaStudy AWS X-Ray, Amazon Managed Service for Prometheus, and Amazon Managed Grafana for tracing, container metrics, visualization, alerting, and operational analysis.Open lesson →
- 43Amazon Athena and AWS Glue: Querying, Cataloging, and Preparing Data for CloudOpsStudy Amazon Athena and AWS Glue for S3 analytics, data cataloging, ETL workflows, crawlers, supported formats, and Athena performance optimization.Open lesson →
- 44Querying Application Load Balancer Access Logs with Amazon Athena | AWS SOA-C03Learn how to enable Application Load Balancer access logging to Amazon S3 and query the resulting logs with Amazon Athena.Open lesson →
- 45AWS Kinesis Streaming Data: Data Streams, Firehose, Video Streams, and KCLStudy AWS Kinesis Data Streams, Kinesis Data Firehose, Kinesis Video Streams, partition-key ordering, scaling, and Kinesis Client Library processing patterns for SOA-C03.Open lesson →
- 46AWS Elasticity: Scaling Up vs. Scaling OutUnderstand AWS elasticity, vertical versus horizontal scaling, their resilience tradeoffs, and how EC2 capacity changes differ between scaling up and scaling out.Open lesson →
- 47AWS Auto Scaling: EC2 Scaling Groups, Policies, Health Checks, and Lifecycle ControlsStudy AWS Auto Scaling across EC2 and other services, including scaling policies, health checks, launch templates, lifecycle controls, and assessment-focused tradeoffs.Open lesson →
- 48Amazon Elastic Load Balancing: ALB, NLB, Health Checks, and Target RoutingStudy Amazon Elastic Load Balancing for SOA-C03, including ALB versus NLB selection, health checks, routing options, Auto Scaling integration, and target types.Open lesson →
- 49Create an Auto Scaling Group and Application Load Balancer with the AWS CLIA practical AWS CLI lab guide for building a launch template, Auto Scaling group, Application Load Balancer, listener, and target group integration.Open lesson →
- 50AWS Auto Scaling Lifecycle Hooks with SNS, Lambda, and EBS SnapshotsLearn how to use an EC2 Auto Scaling lifecycle hook with Amazon SNS and AWS Lambda to snapshot EBS root volumes before instances terminate.Open lesson →
- 51AWS Session State and Session Stickiness: Load Balancer Design for SOA-C03Understand how sticky sessions and external session-state storage affect authentication continuity, load balancing, availability, and AWS architecture decisions.Open lesson →
- 52Amazon RDS and Aurora Backup and Recovery | AWS SOA-C03Study automated backups, manual snapshots, point-in-time recovery, maintenance windows, cross-Region protection, and Aurora backup behavior for AWS CloudOps operations.Open lesson →
- 53AWS RDS and Aurora Read Replicas, Multi-AZ, Global Database, and ServerlessStudy RDS Multi-AZ, read replicas, Aurora replicas, cross-Region replication, Multi-Master, and Aurora Serverless for AWS Certified CloudOps Engineer Associate SOA-C03.Open lesson →
- 54Amazon RDS Proxy: Connection Pooling for Serverless ApplicationsLearn how Amazon RDS Proxy improves database connection management, scalability, fault tolerance, and security for rapidly scaling serverless applications using RDS or Aurora.Open lesson →
- 55AWS Route 53 DNS, Hosted Zones, and Routing Policies Study GuideStudy AWS Route 53 domain management, public and private hosted zones, health checks, cross-account associations, and DNS routing policies for CloudOps operations.Open lesson →
- 56Route 53 Latency-Based Routing and Health Checks: Hands-On Lab GuideLearn how to deploy regional endpoints with CloudFormation and use Route 53 latency-based routing with health checks to direct traffic away from unhealthy applications.Open lesson →
- 57AWS RPO, RTO, and Disaster Recovery Strategies for SOA-C03Study RPO, RTO, replication techniques, AWS disaster recovery patterns, and the tradeoffs among backup and restore, pilot light, warm standby, and multi-site active-active designs.Open lesson →
- 58AWS Backup and Data Lifecycle Manager: Reliability and Business ContinuityStudy AWS Backup and Amazon Data Lifecycle Manager for centralized policy-based protection, EBS snapshot lifecycle automation, retention, encryption, and disaster recovery decisions.Open lesson →
- 59Using Amazon Data Lifecycle Manager (DLM) for Automated EBS SnapshotsLearn how to configure an AWS Data Lifecycle Manager EBS snapshot policy using EC2 tags, schedules, retention rules, and operational cleanup steps.Open lesson →
- 60Amazon S3 Durability, Availability, Storage Classes, Replication, and Lifecycle ManagementStudy Amazon S3 durability versus availability, storage-class tradeoffs, replication, encryption, and lifecycle transition and expiration rules for AWS Certified CloudOps Engineer Associate SOA-C03.Open lesson →
- 61AWS S3 Replication and Lifecycle Management: SOA-C03 Study GuideLearn how to configure Amazon S3 same-Region or cross-Region replication, required IAM permissions and versioning, lifecycle transitions, and version-aware deletion behavior.Open lesson →
- 62AWS DataSync: Online Data Migration and Transfer for CloudOpsStudy AWS DataSync for secure, automated data transfers between on-premises storage, AWS storage services, Snowcone, and S3 on Outposts.Open lesson →
- 63AWS CloudFormation: Templates, Stacks, StackSets, and Change SetsStudy AWS CloudFormation fundamentals, including template-driven provisioning, stacks, StackSets, change sets, benefits, and deployment decision points for the CloudOps Engineer Associate exam.Open lesson →
- 64AWS CloudFormation Stacks, Stack Sets, and Nested StacksLearn how AWS CloudFormation stacks, stack sets, and nested stacks support resource lifecycle management, multi-account and multi-Region deployment, and reusable infrastructure templates.Open lesson →
- 65Create a Nested AWS CloudFormation Stack Using the AWS CLILearn how to build, publish, deploy, verify, and delete a nested AWS CloudFormation stack using AWS CloudShell, Amazon S3, and the AWS CLI.Open lesson →
- 66AWS CloudFormation Template Deep Dive: Sections, Intrinsic Functions, and Stack DesignStudy AWS CloudFormation template structure, intrinsic functions, parameters, mappings, outputs, conditions, transforms, and key deployment decisions for the SOA-C03 exam.Open lesson →
- 67AWS CloudFormation Helper Scripts: cfn-init and cfn-signalStudy how AWS CloudFormation cfn-init and cfn-signal configure EC2 instances, report readiness, and support reliable stack and Auto Scaling deployments.Open lesson →
- 68AWS CloudFormation Creation and Deletion Policies, DependsOn, and WaitConditionsStudy AWS CloudFormation creation, deletion, update, and replacement policies, along with DependsOn and WaitCondition behavior for deployment decisions.Open lesson →
- 69AWS CloudFormation Rollbacks and Stack Creation Failures: SOA-C03 Study GuideUnderstand AWS CloudFormation stack creation failure options, update rollback behavior, and how to recover stacks in UPDATE_ROLLBACK_FAILED.Open lesson →
- 70AWS CloudFormation: Deploying Stacks and Reviewing Change SetsLearn how to deploy AWS CloudFormation stacks, use change sets to preview updates, apply mappings and parameters, configure security groups and user data, and clean up resources safely.Open lesson →
- 71AWS Resource Access Manager (RAM): Cross-Account Resource SharingUnderstand how AWS Resource Access Manager shares supported resources across AWS accounts, organizational units, and selected principals using the console, APIs, CLI, or SDKs.Open lesson →
- 72AWS EventBridge Scheduled Invocation of a Lambda FunctionLearn how to configure an Amazon EventBridge schedule that invokes a Lambda function with a JSON payload and verifies execution through CloudWatch Logs.Open lesson →
- 73Creating, Launching, and Managing Amazon Machine Images (AMIs)Learn how to bootstrap an EC2 instance, create an AMI, launch instances from it, and clean up the associated snapshots.Open lesson →
- 74AWS Storage Gateway: File, Volume, and Tape Gateway Decision GuideStudy AWS Storage Gateway architectures, gateway types, protocols, storage destinations, operating modes, and selection tradeoffs for the SOA-C03 CloudOps Engineer Associate exam.Open lesson →
- 75Amazon DynamoDB: Architecture, Features, APIs, Security, and Operational DecisionsStudy Amazon DynamoDB architecture, consistency, scaling, streams, DAX, global tables, APIs, table classes, backups, and IAM access control for the AWS Certified CloudOps Engineer Associate SOA-C03.Open lesson →
- 76Create and Query a DynamoDB Table with AWS CLI and LambdaLearn how to create a DynamoDB table, batch-load JSON data, grant Lambda read access, and test key-based and scan-based queries.Open lesson →
- 77Amazon ECS: Docker Images, Task Definitions, Clusters, and Launch TypesStudy Amazon ECS architecture, Docker images, ECR, task definitions, services, clusters, and the differences between Fargate and EC2 launch types.Open lesson →
- 78Amazon ECS Launch Types: EC2, Fargate, and ExternalCompare Amazon ECS EC2, Fargate, and external launch types, including infrastructure responsibility, pricing units, storage integration, image registries, and operational tradeoffs.Open lesson →
- 79Create an Amazon ECS Cluster with the EC2 Launch TypeStudy guide for creating an Amazon ECS cluster with EC2 capacity, including Auto Scaling, IAM roles, networking, CloudFormation deployment, and common setup issues.Open lesson →
- 80Launch an ECS EC2 Task with an Application Load BalancerStudy how to define, validate, and expose an Amazon ECS EC2 task running Engine X through an Application Load Balancer, including networking, roles, deployment, and cleanup.Open lesson →
- 81Amazon Elastic Container Registry (ECR): Architecture, Access, Image Workflows, and Automation DecisionsStudy Amazon ECR architecture, authentication, repository permissions, Docker image workflows, lifecycle management, scanning, and replication for AWS CloudOps Engineer Associate preparation.Open lesson →
- 82Amazon EKS: Managed Kubernetes, Scaling, Load Balancing, and Anywhere DeploymentsStudy Amazon EKS architecture, workload and cluster autoscaling, AWS load balancer integration, EKS Distro, and ECS or EKS Anywhere deployment options for the SOA-C03 exam.Open lesson →
- 83Deploying and Scaling Amazon EKS Clusters with eksctl and kubectlStudy guide to provisioning an Amazon EKS cluster, deploying an NGINX workload, exposing it through a load balancer, configuring horizontal pod autoscaling, and granting Kubernetes user access.Open lesson →
- 84AWS Step Functions: State Machines, Workflow Orchestration, and Decision LogicStudy AWS Step Functions state machines, Amazon States Language definitions, visual workflow execution, branching logic, waits, and Lambda orchestration for CloudOps operations.Open lesson →
- 85AWS Step Functions: Create and Test a Lambda-Based State MachineLearn how to provision Lambda functions, configure IAM permissions, import an AWS Step Functions state machine definition, and test Choice-based execution paths.Open lesson →
- 86AWS Service Catalog: Products, Portfolios, Constraints, and Cross-Account SharingStudy AWS Service Catalog administration, product and portfolio organization, launch and template constraints, permissions, and cross-account sharing decisions for the SOA-C03 exam.Open lesson →
- 87AWS IAM Advanced Access Control: RBAC, ABAC, and Policy EvaluationStudy AWS IAM role-based and attribute-based access control, identity and resource policies, policy elements, conditions, and deny-based restrictions for the SOA-C03 exam.Open lesson →
- 88AWS IAM Policy Evaluation: Explicit Denies, Policy Boundaries, SCPs, and SessionsLearn how AWS IAM evaluates requests across identity, resource, boundary, SCP, and session policies, including explicit-deny precedence and effective-permission rules.Open lesson →
- 89AWS Cross-Account S3 Access with IAM Roles and AWS STSLearn how to configure secure cross-account Amazon S3 access using IAM trust policies, identity policies, external IDs, AWS STS, and temporary credentials.Open lesson →
- 90AWS CLI MFA Authentication with AWS STS Session TokensLearn how to use a virtual MFA device with AWS STS to obtain temporary credentials for AWS CLI commands without relying on long-lived credentials stored in the credentials file.Open lesson →
- 91AWS IAM Access Evaluation Tools: Access Analyzer, Credential Reports, Policy Simulator, and Policy GenerationA practical SOA-C03 study guide to using IAM Access Analyzer, credential reports, Policy Simulator, and CloudTrail-based policy generation to evaluate and refine AWS access.Open lesson →
- 92AWS Organizations and Control Tower: Multi-Account Governance for SOA-C03Study AWS Organizations and Control Tower account structures, SCP inheritance, consolidated billing, guardrails, landing zones, and governance decisions for the SOA-C03 exam.Open lesson →
- 93AWS Organizations: Create an Organization and Add an Account (SOA-C03)Study how AWS Organizations creates a management account, adds member accounts, applies service control policies, and enables role-based administration for SOA-C03 preparation.Open lesson →
- 94AWS Organizations Service Control Policies (SCPs): Creating and Applying a Deny PolicyLearn how to create an AWS Organizations Service Control Policy that prevents member-account administrators from modifying a protected IAM role.Open lesson →
- 95AWS Directory Services and Federation: CloudOps Engineer Associate Study GuideStudy AWS Managed Microsoft AD, AD Connector, SAML and web identity federation, and IAM Identity Center for CloudOps security and compliance scenarios.Open lesson →
- 96AWS IAM Identity Center in Action: Organizations, Permission Sets, and Access PortalStudy how AWS IAM Identity Center integrates with AWS Organizations to assign permission sets, groups, MFA, and console or command-line access through the access portal.Open lesson →
- 97Amazon Inspector and AWS Trusted Advisor: Security, Vulnerability, and Optimization DecisionsStudy Amazon Inspector network and host assessments alongside AWS Trusted Advisor guidance for security, cost, performance, fault tolerance, and service limits.Open lesson →
- 98AWS Encryption Primer: Transit, Rest, Symmetric, and Asymmetric Encryption | SOA-C03Review the AWS encryption fundamentals needed to distinguish encryption in transit, encryption at rest, symmetric encryption, and asymmetric encryption.Open lesson →
- 99AWS KMS: Key Types, Encryption Workflows, Rotation, and Key Policies for SOA-C03Study AWS KMS key types, data encryption keys, external and custom key stores, rotation behavior, key policies, grants, and common CloudOps assessment traps.Open lesson →
- 100AWS KMS Customer-Managed Keys: Creation, Key Policies, and Service-Restricted UsageLearn how to create AWS KMS customer-managed symmetric keys, configure administrators and key users, and restrict one key to EC2 and RDS with kms:ViaService conditions.Open lesson →
- 101AWS KMS API, CLI Commands, Throttling, and Data Key CachingStudy AWS KMS API and CLI operations, data key workflows, quota errors, retry strategies, service quota increases, and data key caching for the SOA-C03 exam.Open lesson →
- 102AWS CloudHSM: Architecture, Security Controls, Use Cases, and KMS IntegrationStudy AWS CloudHSM architecture, customer-controlled keys, FIPS validation, common use cases, and when to combine CloudHSM with AWS KMS.Open lesson →
- 103AWS Certificate Manager (ACM): CloudOps Security and Compliance Study GuideStudy AWS Certificate Manager concepts, certificate types, integrations, and how ACM differs from KMS and AWS CloudHSM for CloudOps security decisions.Open lesson →
- 104AWS ACM SSL/TLS Certificate with CloudFront and S3: Complete Lab WorkflowLearn how to validate an ACM public certificate with Route 53 and use it with CloudFront to securely serve an S3-hosted website over HTTPS.Open lesson →
- 105AWS Secrets Management: Secrets Manager vs. SSM Parameter Store | SOA-C03Compare AWS Secrets Manager and Systems Manager Parameter Store for storing credentials, configuration data, rotation, encryption, hierarchy, and cost decisions in SOA-C03 scenarios.Open lesson →
- 106AWS Secrets Manager with RDS and Lambda: MySQL Integration LabA practical AWS CloudOps study guide for connecting a Lambda function to an RDS MySQL database with Secrets Manager, IAM permissions, a PyMySQL layer, testing, and cleanup.Open lesson →
- 107AWS Security Hub and GuardDuty: Security Posture and Threat Detection for SOA-C03Study AWS Security Hub and GuardDuty for SOA-C03, including posture checks, threat detection, findings, integrations, data sources, and operational tradeoffs.Open lesson →
- 108Amazon Macie: Sensitive Data Discovery in Amazon S3Study Amazon Macie’s role in discovering sensitive data, monitoring S3 security posture, and generating findings for security and compliance workflows.Open lesson →
- 109AWS Private Subnets and NAT Gateways: Routing, Bastion Access, and Multi-AZ DesignLearn how AWS public and private subnets differ, how NAT gateways provide outbound internet access, and how to design bastion and multi-AZ connectivity patterns.Open lesson →
- 110AWS Private Subnet Internet Access with a NAT GatewayLearn how to provide outbound internet access to an EC2 instance in a private subnet by deploying a NAT Gateway in a public subnet and updating the private route table.Open lesson →
- 111AWS VPC Connectivity Options: VPN, Direct Connect, Transit Gateway, Peering, and PrivateLinkStudy the AWS VPC connectivity architectures used for hybrid networking, multi-VPC communication, cross-region routing, private service access, and remote client access.Open lesson →
- 112AWS VPC Peering Across Regions: Configure, Test, and Clean UpA practical AWS CloudOps study guide for creating cross-region VPC peering, updating routes and security groups, testing private connectivity, and cleaning up the lab.Open lesson →
- 113AWS VPC Endpoints: Interface vs. Gateway Endpoints for SOA-C03Study the differences between AWS interface and gateway VPC endpoints, including supported services, routing, security groups, DNS, prefix lists, and endpoint policies.Open lesson →
- 114Amazon S3 Gateway and Interface VPC Endpoints: Architecture, Selection, and DeploymentUnderstand the differences between Amazon S3 gateway and interface VPC endpoints, including routing, DNS, cross-network access, cost, policies, and gateway endpoint deployment.Open lesson →
- 115AWS Client VPN: Architecture, Authentication, and Access ControlStudy AWS Client VPN architecture, authentication methods, subnet associations, authorization rules, client connectivity, and key SOA-C03 decision points.Open lesson →
- 116AWS Site-to-Site VPN: Architecture, Routing, and Tunnel ConfigurationStudy AWS Site-to-Site VPN architecture, gateways, routing modes, tunnel options, route propagation, and virtual private gateway path selection for the SOA-C03 exam.Open lesson →
- 117AWS Transit Gateway: Architecture, Routing Patterns, and Operations for SOA-C03Study AWS Transit Gateway connectivity, route-table isolation, Direct Connect, SD-WAN, multicast, monitoring, and deployment best practices for CloudOps Engineer Associate preparation.Open lesson →
- 118AWS Route 53 Resolver: Inbound and Outbound DNS Resolution | SOA-C03Understand how Route 53 Resolver connects AWS VPC DNS resolution with on-premises DNS servers using outbound and inbound endpoints.Open lesson →
- 119Amazon CloudFront Origins, Distributions, Edge Locations, and BehaviorsStudy how Amazon CloudFront uses origins, distributions, edge locations, caching behaviors, and policies to improve global content delivery performance.Open lesson →
- 120CloudFront Signed URLs, Signed Cookies, OAI, and OACStudy how CloudFront signed URLs, signed cookies, Origin Access Identity, and Origin Access Control restrict content access and when to choose each option.Open lesson →
- 121Create an Amazon S3 Static Website: Configuration, Public Access, and CloudFront ConsiderationsLearn how to configure an Amazon S3 static website, publish public objects with a bucket policy, and understand why CloudFront is required for HTTPS.Open lesson →
- 122Configure a Protected Amazon S3 Origin with Amazon CloudFrontLearn how to protect an Amazon S3 origin with CloudFront Origin Access Control, HTTPS, ACM, Route 53, and a default root object.Open lesson →
- 123AWS Networking and Content Delivery: Collect and Interpret LogsStudy how to enable, scope, store, and interpret Amazon S3, VPC Flow Logs, ELB access logs, CloudFront logs, and edge-function logs for AWS CloudOps operations.Open lesson →
- 124AWS WAF: Web ACLs, Rule Actions, Match Statements, and Protected ResourcesStudy AWS WAF concepts for the SOA-C03 exam, including web ACLs, rule groups, match statements, actions, and integrations with CloudFront, ALB, API Gateway, and AppSync.Open lesson →
- 125AWS Shield: Standard vs. Advanced DDoS Protection for SOA-C03Study AWS Shield Standard and Advanced, including DDoS protection capabilities, CloudFront integration, pricing context, and selection decisions for the SOA-C03 exam.Open lesson →
- 126AWS WAF Rate-Based Web ACL for CloudFront: Configuration, Testing, and CleanupConfigure an AWS WAF rate-based web ACL for a CloudFront distribution, test IP-based blocking with CloudShell, and clean up the associated resources safely.Open lesson →
- 127AWS Network Firewall and Route 53 Resolver DNS Firewall: Architecture, Routing, and Centralized ManagementStudy AWS Network Firewall and Route 53 Resolver DNS Firewall, including subnet placement, bidirectional routing, DNS exfiltration prevention, and centralized management with Firewall Manager.Open lesson →
- 128AWS Compute Optimizer: Right-Sizing EC2, EBS, and Lambda ResourcesLearn how AWS Compute Optimizer uses historical CloudWatch utilization data to recommend cost-saving and performance-improving configurations for EC2, EBS, and Lambda.Open lesson →
- 129AWS Cost Allocation Tags: Tracking Resource Costs by Department and Creator (SOA-C03)Learn how to enable AWS-generated and user-defined cost allocation tags and use Cost Explorer to attribute resource costs by department or resource creator.Open lesson →
- 130AWS Cost Management Tools: Cost Explorer, CUR, and Price List APIsStudy Cost Explorer, the AWS Cost and Usage Report, and Price List APIs for analyzing spending, exporting detailed billing data, and querying AWS service prices.Open lesson →
- 131AWS Cost Management Tools: Cost Explorer, Billing Reports, and Cost AttributionLearn how to use AWS Cost Explorer, Cost and Usage Reports, Bills, filters, and linked-account views to analyze and attribute cloud costs.Open lesson →
- 132Amazon EC2 Pricing Options and Billing Decisions for AWS CloudOps Engineer AssociateStudy Amazon EC2 pricing models, billing rules, Reserved Instances, Savings Plans, Spot capacity, Dedicated Hosts, and capacity reservations for the AWS Certified CloudOps Engineer Associate exam.Open lesson →
- 133EC2 Placement Groups: Cluster, Partition, and Spread Selection GuideLearn how to choose AWS EC2 cluster, partition, and spread placement groups based on latency, throughput, hardware isolation, and workload resilience requirements.Open lesson →
- 134AWS S3 Multipart Upload and Transfer Acceleration: CloudOps Optimization GuideLearn when to use Amazon S3 multipart uploads or Transfer Acceleration, how they work, and how to evaluate performance, cost, and operational tradeoffs.Open lesson →
- 135AWS Certified CloudOps Engineer Associate: EC2 and Lambda Exam ScenariosStudy common SOA-C03 scenarios for EC2 maintenance, capacity errors, networking, pricing models, monitoring, auto scaling, and Lambda scheduling.Open lesson →
- 136AWS SOA-C03 Exam Scenarios: Elastic Load Balancing and Auto ScalingStudy AWS SOA-C03 scenarios covering ALB security, health checks, access logs, CloudWatch metrics, Network Load Balancers, and EC2 Auto Scaling decisions.Open lesson →
- 137AWS Storage Exam Scenarios: Amazon EBS, EFS, and AWS Storage GatewayStudy guide for choosing and operating Amazon EBS, EFS, and AWS Storage Gateway in AWS Certified CloudOps Engineer Associate scenarios.Open lesson →
- 138AWS Systems Manager and OpsWorks Exam Scenarios | SOA-C03Review SOA-C03 scenarios involving Systems Manager Parameter Store, Patch Manager, Session Manager, Automation, IAM access keys, and AWS OpsWorks Stacks.Open lesson →
- 139AWS CloudFormation: Templates, Stacks, StackSets, and Change SetsStudy AWS CloudFormation fundamentals, including template-driven provisioning, stacks, StackSets, change sets, benefits, costs, and scenario-based feature selection for the SOA-C03 exam.Open lesson →
- 140Amazon VPC Exam Scenarios: NAT Gateways, Endpoints, Routing, VPNs, and Network ControlsStudy guide for AWS VPC scenarios involving NAT gateways, VPC endpoints, routing, VPN connectivity, flow logs, security groups, and network ACLs.Open lesson →
- 141Amazon Route 53 Exam Scenarios: Health Checks, Geolocation, and Alias RecordsStudy Route 53 scenario decisions involving HTTP health checks, response-string matching, geolocation routing, domain apex records, and cross-account Application Load Balancer aliases.Open lesson →
- 142AWS S3 and CloudFront Exam Scenarios: Access, Versioning, Logging, and DeliveryStudy guide for AWS Certified CloudOps Engineer Associate scenarios involving S3 website hosting, versioning, access control, CloudFront caching, logging, and geographic restrictions.Open lesson →
- 143AWS SOA-C03 Exam Scenarios: Amazon RDS and ElastiCacheStudy guide for AWS Certified CloudOps Engineer Associate scenarios involving RDS, Aurora, read replicas, Multi-AZ, backups, encryption, and ElastiCache scaling.Open lesson →
- 144AWS SOA-C03 Management, Governance, and Billing Exam ScenariosStudy guide to AWS Organizations, SCPs, CloudWatch, CloudTrail, AWS Config, Service Catalog, Cost Explorer, Budgets, Trusted Advisor, and AWS Health scenarios for the SOA-C03 exam.Open lesson →
- 145AWS Security and Compliance Exam Scenarios: IAM, KMS, Inspector, WAF, Shield, and FederationStudy guide to AWS security and compliance scenarios involving IAM policies, KMS rotation, Inspector, WAF, Shield Advanced, Artifact, federation, and shared responsibility.Open lesson →