dc dotCreds
AWS Certified CloudOps Engineer - Associate

AWS CloudOps Engineer Associate Practice Test

Start today's 10-question AWS CloudOps Engineer Associate set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 150 Verified Questions

Questions updated at Jul 18, 2026, 1:30 PM CDT

Go Pro - One Time Unlock

Unlock the full SOA-C03 bank

150 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 AWS CloudOps Engineer Associate questions

Use this AWS CloudOps Engineer Associate practice test to review AWS Certified CloudOps Engineer Associate. Questions rotate daily and each explanation links to the source used to validate the answer.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

150 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective SOA-C03-cost Cost and Capacity

A production EC2 workload requires 3,000 IOPS for baseline performance. The current EBS volumes are provisioned as `gp2`. What is the most efficient volume change to meet this requirement without increasing the overall volume size?

Concept tested:
Question 2 of 10
Objective SOA-C03-automation Automation and Remediation

A production team needs to address an instance failure requiring diagnostics collection, service restart, and final instance reboot with administrator approval. To ensure consistent and auditable remediation, what documentation should the team create and maintain?

Concept tested:
Question 3 of 10
Objective SOA-C03-security Security Operations

An application role is denied when attempting to decrypt data with a customer-managed KMS key. The IAM role policy allows decrypt. Which KMS key policy configuration could be preventing the role from accessing the key?

Concept tested:
Question 4 of 10
Objective SOA-C03-networking Networking Operations

A network administrator is configuring two peered VPCs to allow private DNS name resolution across the peering connection. The administrator wants to ensure that instances in both VPCs can resolve internal hostnames using private DNS. Which setting within the VPC peering connection configuration must be verified to enable this functionality?

Concept tested:
Question 5 of 10
Objective SOA-C03-monitoring Monitoring and Logging

During a canary deployment, the release team needs a single view to monitor new 5xx errors, p95 latency, and alarm states for the service. Which CloudWatch design best enables this on-call review process?

Concept tested:
Question 6 of 10
Objective SOA-C03-security Security Operations

During an audit, management requests evidence that the CloudOps team implements controls for access restriction, change tracking, and managed instance maintenance. Which combination of practices best demonstrates compliance with this request?

Concept tested:
Question 7 of 10
Objective SOA-C03-reliability Reliability

A production service currently relies on a single EC2 instance. The team has not previously tested failover procedures. Which action most directly enhances the service's operational resilience?

Concept tested:
Question 8 of 10
Objective SOA-C03-networking Networking Operations

Traffic is failing to return to an application running in a private subnet after a custom route table change. Diagnostic troubleshooting is required. Which set of controls is most directly relevant to identifying the root cause of this issue?

Concept tested:
Question 9 of 10
Objective SOA-C03-monitoring Monitoring and Logging

An ECS service publishes error-rate and memory-utilization metrics. Operations teams require a single alarm notification that triggers only when *both* the error rate and memory utilization are simultaneously in the ALARM state. What is the optimal configuration to achieve this?

Concept tested:
Question 10 of 10
Objective SOA-C03-cost Cost and Capacity

A workload experiences daily spikes in demand alongside a consistent baseline. The team is evaluating Savings Plans to optimize costs while maintaining sufficient capacity for peak periods. Which operational practice best aligns with this scenario?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 140 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SOA-C03 Pro $4.99 one-time

Unlock all 150 AWS CloudOps Engineer Associate questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question SOA-C03 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SOA-C03 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

150 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 140 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SOA-C03 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Official exam resources

Use these official AWS resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent AWS practice pages too? AWS practice hub.

Source-backed answer review

The free daily AWS CloudOps Engineer Associate set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A production EC2 workload requires 3,000 IOPS for baseline performance. The current EBS volumes are provisioned as `gp2`. What is the most efficient volume change to meet this requirement without increasing the overall volume size?

Answer choices

  1. A. Modify the volumes from `gp2` to `gp3`. Provision the exact IOPS and throughput required (e.g., 3,000 IOPS) independently of the volume size
  2. B. Increase the volume size of the `gp2` volumes to 1,000 GiB to double the baseline IOPS to 3,000
  3. C. Modify the volumes to Provisioned IOPS SSD (`io2`) and specify 3,000 IOPS
  4. D. Attach a secondary `gp2` volume to the instance and configure software RAID 0 inside the operating system

Correct answer

Modify the volumes from `gp2` to `gp3`. Provision the exact IOPS and throughput required (e.g., 3,000 IOPS) independently of the volume size

Modify the volumes from `gp2` to `gp3`. Provision the exact IOPS and throughput required (e.g., 3,000 IOPS) independently of the volume size. gp3 separates size from provisioned performance, which avoids increasing capacity only to gain IOPS. Larger gp2 volumes, io2, or RAID can add cost or complexity beyond the stated need.

Wrong-answer review

  • B. Increase the volume size of the `gp2` volumes to 1,000 GiB to double the baseline IOPS to 3,000: Growing gp2 just for IOPS adds unnecessary capacity.
  • C. Modify the volumes to Provisioned IOPS SSD (`io2`) and specify 3,000 IOPS: io2 can provision IOPS but may be more than needed for the stated gp2-to-gp3 optimization.
  • D. Attach a secondary `gp2` volume to the instance and configure software RAID 0 inside the operating system: RAID across extra gp2 volumes adds operational complexity and is not the direct gp3 optimization.

Extra learning features

Why candidates miss this

Operators frequently conflate volume size and IOPS in `gp2` volumes, assuming a direct correlation. They believe increasing the volume size will automatically increase IOPS. However, `gp2` IOPS are tied to volume size, and this approach wastes storage capacity. The correct answer, migrating to `gp3`, allows independent IOPS provisioning. Likely wrong answer: Increase the volume size of the `gp2` volumes to 1,000 GiB to double the baseline IOPS to 3,000 Review focus: Amazon EBS gp3 Volumes

Interview question

Q: Our team is experiencing performance bottlenecks with an EC2 workload. We need to increase IOPS on the EBS volume without increasing its size. How would you approach this, and what are the tradeoffs involved? Strong answer: The first thing I'd do is evaluate whether switching to a `gp3` volume would meet the requirements. `gp3` allows independent scaling of IOPS and throughput, so we can provision exactly 3,000 IOPS without increasing the volume size. The tradeoff is that `gp3` volumes can be slightly more expensive than `gp2` volumes, but the ability to optimize performance without increasing capacity often makes it worthwhile. We'd also monitor the volume performance after the change to ensure it's meeting the needs of the application.

  • Understanding of EBS volume types and their performance characteristics
  • Ability to identify and evaluate tradeoffs between cost and performance
  • Problem-solving approach to performance bottlenecks
  • Awareness of monitoring and optimization

Caution: Recommending increasing the volume size as the default solution. Candidates who don't mention the tradeoffs or monitoring are missing key considerations.

Objective/domain: Cost and Capacity

Source: Amazon EBS gp3 Volumes

Question 2 A production team needs to address an instance failure requiring diagnostics collection, service restart, and final instance reboot with administrator approval. To ensure consistent and auditable remediation, what documentation should the team create and maintain?

Answer choices

  1. A. A spreadsheet that tells operators to improvise commands
  2. B. A Systems Manager Automation runbook with the required actions and approval step
  3. C. A CloudWatch dashboard with no action procedure
  4. D. An S3 bucket policy that grants administrator access to everyone

Correct answer

A Systems Manager Automation runbook with the required actions and approval step

Objective/domain: Automation and Remediation

Source: AWS Systems Manager Automation

Question 3 An application role is denied when attempting to decrypt data with a customer-managed KMS key. The IAM role policy allows decrypt. Which KMS key policy configuration could be preventing the role from accessing the key?

Answer choices

  1. A. The KMS Key Policy does not explicitly grant permission to the IAM role or delegate authority to the AWS account IAM policies
  2. B. The application IAM role has not been registered in the KMS client side cache config file on the EC2 instance
  3. C. The key's alias has not been mapped to the application's local environmental variable configuration
  4. D. KMS customer managed keys do not support decryption privileges outside of the AWS root account

Correct answer

The KMS Key Policy does not explicitly grant permission to the IAM role or delegate authority to the AWS account IAM policies

Objective/domain: Security Operations

Source: AWS KMS Key Policies

Question 4 A network administrator is configuring two peered VPCs to allow private DNS name resolution across the peering connection. The administrator wants to ensure that instances in both VPCs can resolve internal hostnames using private DNS. Which setting within the VPC peering connection configuration must be verified to enable this functionality?

Answer choices

  1. A. The VPC Peering connection settings must have 'Allow active resolution of DNS queries' (enableDnsHostnames/enableDnsSupport) enabled for both the requester and accepter VPCs
  2. B. An active Route 53 Resolver outbound endpoint must be deployed in both subnets to forward peering DNS traffic
  3. C. The DNS server addresses in the DHCP options set of VPC A must be updated to include the IP address of the VPC B DNS server
  4. D. VPC Peering does not support private DNS hostname resolution; clients must use public Route 53 zones

Correct answer

The VPC Peering connection settings must have 'Allow active resolution of DNS queries' (enableDnsHostnames/enableDnsSupport) enabled for both the requester and accepter VPCs

Objective/domain: Networking Operations

Source: VPC Peering DNS Resolution

Question 5 During a canary deployment, the release team needs a single view to monitor new 5xx errors, p95 latency, and alarm states for the service. Which CloudWatch design best enables this on-call review process?

Answer choices

  1. A. Purchase Reserved Instances for the application servers
  2. B. Store the application source branch in a CloudWatch log group
  3. C. Build a CloudWatch dashboard that combines relevant metrics, log-derived metrics, and alarms
  4. D. Replace the application IAM role with a metric filter

Correct answer

Build a CloudWatch dashboard that combines relevant metrics, log-derived metrics, and alarms

Objective/domain: Monitoring and Logging

Source: Amazon CloudWatch documentation

Question 6 During an audit, management requests evidence that the CloudOps team implements controls for access restriction, change tracking, and managed instance maintenance. Which combination of practices best demonstrates compliance with this request?

Answer choices

  1. A. Least privilege, audit logging, patch management, and controlled access
  2. B. One shared password for every administrator
  3. C. Manual deletion of logs before handoff
  4. D. Ignoring operating system updates on customer-managed instances

Correct answer

Least privilege, audit logging, patch management, and controlled access

Objective/domain: Security Operations

Source: AWS Identity and Access Management documentation

Question 7 A production service currently relies on a single EC2 instance. The team has not previously tested failover procedures. Which action most directly enhances the service's operational resilience?

Answer choices

  1. A. Remove monitoring to reduce operational noise
  2. B. Keep the single instance and add only a name tag
  3. C. Introduce health checks, alarms, tested recovery steps, and Multi-AZ design where justified
  4. D. Disable scaling because failures should be handled manually

Correct answer

Introduce health checks, alarms, tested recovery steps, and Multi-AZ design where justified

Objective/domain: Reliability

Source: AWS Well-Architected Reliability Pillar

Question 8 Traffic is failing to return to an application running in a private subnet after a custom route table change. Diagnostic troubleshooting is required. Which set of controls is most directly relevant to identifying the root cause of this issue?

Answer choices

  1. A. Check route symmetry, security groups, network ACLs, and endpoint or gateway configuration
  2. B. Check whether budgets are named after the subnet
  3. C. Check whether Route 53 registered the instance password
  4. D. Check whether CloudTrail stores packet payloads

Correct answer

Check route symmetry, security groups, network ACLs, and endpoint or gateway configuration

Objective/domain: Networking Operations

Source: Amazon VPC documentation

Question 9 An ECS service publishes error-rate and memory-utilization metrics. Operations teams require a single alarm notification that triggers only when *both* the error rate and memory utilization are simultaneously in the ALARM state. What is the optimal configuration to achieve this?

Answer choices

  1. A. An EventBridge schedule that runs every five minutes regardless of alarm state
  2. B. A Cost Anomaly Detection monitor for the ECS service
  3. C. A Route 53 health check that ignores CloudWatch alarm state
  4. D. A CloudWatch composite alarm based on the two underlying CloudWatch alarms

Correct answer

A CloudWatch composite alarm based on the two underlying CloudWatch alarms

Objective/domain: Monitoring and Logging

Source: Amazon CloudWatch documentation

Question 10 A workload experiences daily spikes in demand alongside a consistent baseline. The team is evaluating Savings Plans to optimize costs while maintaining sufficient capacity for peak periods. Which operational practice best aligns with this scenario?

Answer choices

  1. A. Disable alarms and hope fewer notifications reduce cost
  2. B. Analyze usage, right-size the baseline, use scaling for spikes, and apply budget or Savings Plans guardrails where appropriate
  3. C. Run peak capacity permanently on every workload
  4. D. Use only a support case to decide sizing

Correct answer

Analyze usage, right-size the baseline, use scaling for spikes, and apply budget or Savings Plans guardrails where appropriate

Objective/domain: Cost and Capacity

Source: AWS Cost Management documentation

Where to go after the daily web set

How are AWS CloudOps Engineer Associate questions generated?

dotCreds builds AWS CloudOps Engineer Associate practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS CloudOps Engineer Associate practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.