dc dotCreds
AWS Certified CloudOps Engineer - Associate

AWS CloudOps Engineer Associate Practice Test

Start today's 10-question AWS CloudOps Engineer Associate set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 150 Verified Questions

Questions updated at Aug 12, 2026, 3:38 PM CDT

Go Pro - One Time Unlock

Unlock the full SOA-C03 bank

150 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 AWS CloudOps Engineer Associate questions

Use this AWS CloudOps Engineer Associate practice test to review AWS Certified CloudOps Engineer Associate. Questions rotate daily and each explanation links to the source used to validate the answer.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

150 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective SOA-C03-monitoring Monitoring and Logging

A central operations team needs to monitor Lambda error rates and ELB 5xx metrics from multiple application accounts, requiring a single pane of glass without switching between consoles. Which CloudWatch design effectively addresses this operational need?

Concept tested:
Question 2 of 10
Objective SOA-C03-reliability Reliability

An Auto Scaling group replaces EC2 instances only after EC2 status checks fail, but the application continues to return 500 errors while the instance remains healthy. What should the team improve to ensure optimal application availability?

Concept tested:
Question 3 of 10
Objective SOA-C03-cost Cost and Capacity

A team requires a budget guardrail to prevent new production (p-type) EC2 instance launches when spending exceeds a defined limit. Which AWS configuration best achieves this control?

Concept tested:
Question 4 of 10
Objective SOA-C03-automation Automation and Remediation

A managed instance repeatedly triggers an alarm due to a recurring issue. To ensure consistent and automated remediation, which AWS Systems Manager capability should the team implement to execute pre-approved cleanup steps?

Concept tested:
Question 5 of 10
Objective SOA-C03-networking Networking Operations

A cloud operations engineer is troubleshooting connectivity issues for instances in a private subnet. These instances require access to the internet but cannot reach external resources. After reviewing the architecture, the engineer discovers the NAT Gateway is deployed within the private subnet. Which action best explains this failure?

Concept tested:
Question 6 of 10
Objective SOA-C03-monitoring Monitoring and Logging

An application consistently writes ERROR lines to CloudWatch Logs. The on-call team requires immediate notification when the frequency of these errors exceeds 20 occurrences within a five-minute window. Which action should the cloud operations engineer take to establish this alerting mechanism?

Concept tested:
Question 7 of 10
Objective SOA-C03-automation Automation and Remediation

A post-patch workflow requires draining an instance from service, applying updates, running validation, and returning it to service, contingent on successful validation. Which AWS Systems Manager feature is best suited to enforce this ordered execution and validation process?

Concept tested:
Question 8 of 10
Objective SOA-C03-networking Networking Operations

Instances in two private subnets have routes to each other, but return traffic fails after a network ACL rule change. Which controls should be checked together?

Concept tested:
Question 9 of 10
Objective SOA-C03-reliability Reliability

An application should normally send DNS traffic to us-east-1 and fail over to us-west-2 when the primary health check fails. Which Route 53 configuration matches?

Concept tested:
Question 10 of 10
Objective SOA-C03-networking Networking Operations

A company is deploying a new application across multiple spoke VPCs and requires a centralized egress VPC for all internet-bound traffic. To achieve this routing model efficiently and at scale, what AWS networking solution should be implemented?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 140 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SOA-C03 Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question SOA-C03 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

AWS Cloud Bundle $9.99 one-time

Unlock all 6 active AWS Cloud Bundle practice banks in one permanent purchase.

What’s includedAWS Cloud Practitioner, AWS SAA-C03, AWS Developer Associate, AWS CloudOps Associate, AWS Data Engineer Associate, AWS DevOps Professional
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SOA-C03 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

150 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 140 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SOA-C03 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Official exam resources

Use these official AWS resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent AWS practice pages too? AWS practice hub.

Source-backed answer review

The free daily AWS CloudOps Engineer Associate set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A central operations team needs to monitor Lambda error rates and ELB 5xx metrics from multiple application accounts, requiring a single pane of glass without switching between consoles. Which CloudWatch design effectively addresses this operational need?

Answer choices

  1. A. Use CloudWatch cross-account observability and shared dashboards for the source accounts, as selected.
  2. B. Replace the application CloudFormation templates with dashboard widgets, within this design.
  3. C. Store root account credentials in CloudWatch so alarms can authenticate, as the recommended response to this scenario.
  4. D. Use monthly invoice reports as the operational dashboard, for the stated monitoring and logging requirement.

Correct answer

Use CloudWatch cross-account observability and shared dashboards for the source accounts, as selected.

CloudWatch cross-account observability lets a monitoring account view telemetry from source accounts and build shared operational dashboards. Templates, root credentials, and invoice reports do not provide centralized multi-account observability.

Wrong-answer review

  • B. Replace the application CloudFormation templates with dashboard widgets, within this design.: CloudFormation templates define infrastructure and do not replace monitoring dashboards.
  • C. Store root account credentials in CloudWatch so alarms can authenticate, as the recommended response to this scenario.: Root credentials should not be stored in CloudWatch or used for alarm authentication.
  • D. Use monthly invoice reports as the operational dashboard, for the stated monitoring and logging requirement.: Invoice reports are billing artifacts and are not an operational telemetry dashboard.

Extra learning features

Why candidates miss this

The desire for a single pane of glass often leads operators to conflate CloudFormation templates, which define infrastructure, with CloudWatch dashboards. CloudWatch dashboards are designed for visualization and analysis of metrics, not for infrastructure deployment. Cross-account observability provides the centralized view needed, while CloudFormation would only change how resources are built, not how they are monitored. Likely wrong answer: Replace the application CloudFormation templates with dashboard widgets Review focus: CloudWatch Cross-Account Observability

Interview question

Q: Let's say our operations team is struggling to quickly identify the root cause of performance issues in our application. We're seeing Lambda errors, high EC2 CPU utilization, and unusual patterns in our application logs. How would you design a monitoring solution to give them a clear, consolidated view of these different signals? Strong answer: The first thing I'd do is leverage CloudWatch to aggregate those different data sources into a single dashboard. We'd create custom dashboards that combine Lambda error counts, EC2 CPU utilization metrics, and parsed application log data. I'd also ensure the dashboard is easily accessible and understandable for the operations team, potentially using visualizations like graphs and heatmaps to highlight trends. We'd need to define appropriate thresholds and alarms to proactively alert the team to potential issues.

  • Ability to combine different data sources
  • Understanding of dashboard design principles
  • Proactive alerting and thresholding
  • Focus on operational usability

Caution: Simply stating 'use CloudWatch' without explaining how to combine and visualize the data. Focusing only on one data source (e.g., just Lambda errors).

Objective/domain: Monitoring and Logging

Source: Amazon CloudWatch documentation

Question 2 An Auto Scaling group replaces EC2 instances only after EC2 status checks fail, but the application continues to return 500 errors while the instance remains healthy. What should the team improve to ensure optimal application availability?

Answer choices

  1. A. Depend on a single instance because replacement creates noise, for the described technical objective and its associated operational control requirements, for consideration.
  2. B. Use application or load balancer health signals with alarms and scaling policies to replace failed capacity, for evaluation.
  3. C. Use only a monthly cost report to detect health failures, as the recommended implementation across the complete governed service lifecycle.
  4. D. Delete Auto Scaling policies after launch, as the proposed design for the complete governed operational workflow.

Correct answer

Use application or load balancer health signals with alarms and scaling policies to replace failed capacity, for evaluation.

Objective/domain: Reliability

Source: AWS Well-Architected Reliability Pillar

Question 3 A team requires a budget guardrail to prevent new production (p-type) EC2 instance launches when spending exceeds a defined limit. Which AWS configuration best achieves this control?

Answer choices

  1. A. Write a custom cron script in each EC2 instance that checks the billing API and executes a self-termination command, for the described technical objective and its associated operational control requirements, as the primary proposed approach.
  2. B. Configure AWS Cost Explorer to automatically delete any Auto Scaling group that launches p-type instances, for the described technical objective and its associated operational control requirements, as the primary proposed approach.
  3. C. Create an AWS Budget in the account and configure a Budget Action to apply a Service Control Policy (SCP) that denies `ec2:RunInstances` for p-type instances when the budgeted cost exceeds 100%, within the documented operational, security, ownership, and validation requirements.
  4. D. Deploy an Amazon CloudWatch Alarm that triggers a Systems Manager Automation runbook to delete the AWS Billing account, for the described technical objective and its associated operational control requirements, within the defined security and accountability boundaries.

Correct answer

Create an AWS Budget in the account and configure a Budget Action to apply a Service Control Policy (SCP) that denies `ec2:RunInstances` for p-type instances when the budgeted cost exceeds 100%, within the documented operational, security, ownership, and validation requirements.

Objective/domain: Cost and Capacity

Source: AWS Budgets Cost Actions

Question 4 A managed instance repeatedly triggers an alarm due to a recurring issue. To ensure consistent and automated remediation, which AWS Systems Manager capability should the team implement to execute pre-approved cleanup steps?

Answer choices

  1. A. Use AWS Billing console reports as the remediation engine, for the required operational result and control objective.
  2. B. Use AWS Systems Manager Automation runbooks for repeatable remediation workflows, within the documented scope, ownership, and validation boundaries.
  3. C. Disable the runbook after its first successful run, for the stated automation and remediation requirement.
  4. D. Require an operator to SSH to every instance before each step, in this situation.

Correct answer

Use AWS Systems Manager Automation runbooks for repeatable remediation workflows, within the documented scope, ownership, and validation boundaries.

Objective/domain: Automation and Remediation

Source: AWS Systems Manager Automation

Question 5 A cloud operations engineer is troubleshooting connectivity issues for instances in a private subnet. These instances require access to the internet but cannot reach external resources. After reviewing the architecture, the engineer discovers the NAT Gateway is deployed within the private subnet. Which action best explains this failure?

Answer choices

  1. A. The EC2 instance does not have a public IP address assigned to its primary network interface, as the recommended response to this scenario.
  2. B. The NAT Gateway was deployed in the private subnet instead of a public subnet that has a route to the Internet Gateway, under the organization’s defined implementation and exception-management process.
  3. C. The NAT Gateway security group does not allow outbound traffic on port 80 and 443, for the described technical objective and its associated operational control requirements, under the stated decision criteria.
  4. D. The VPC does not have DNS Resolution (`enableDnsSupport`) enabled in its attributes, for the described technical objective and its associated operational control requirements, for review.

Correct answer

The NAT Gateway was deployed in the private subnet instead of a public subnet that has a route to the Internet Gateway, under the organization’s defined implementation and exception-management process.

Objective/domain: Networking Operations

Source: NAT Gateway Troubleshooting

Question 6 An application consistently writes ERROR lines to CloudWatch Logs. The on-call team requires immediate notification when the frequency of these errors exceeds 20 occurrences within a five-minute window. Which action should the cloud operations engineer take to establish this alerting mechanism?

Answer choices

  1. A. Create an S3 lifecycle rule to expire the log stream after each error, under end-to-end security-and-governance requirements.
  2. B. Open an AWS Support case whenever the application writes an error line, for the stated requirement.
  3. C. Create an AWS Config rule that evaluates each log event as a resource, for the stated security, delivery, and accountability requirements.
  4. D. Create a CloudWatch Logs metric filter for the error pattern and alarm on the resulting metric, under the described monitoring and logging criteria.

Correct answer

Create a CloudWatch Logs metric filter for the error pattern and alarm on the resulting metric, under the described monitoring and logging criteria.

Objective/domain: Monitoring and Logging

Source: Amazon CloudWatch documentation

Question 7 A post-patch workflow requires draining an instance from service, applying updates, running validation, and returning it to service, contingent on successful validation. Which AWS Systems Manager feature is best suited to enforce this ordered execution and validation process?

Answer choices

  1. A. AWS Systems Manager Session Manager requiring unordered manual commands, for this scenario.
  2. B. AWS Systems Manager Patch Manager creating Route 53 records, as selected.
  3. C. AWS Systems Manager Automation runbooks defining ordered execution steps, for the required automation and remediation outcome.
  4. D. AWS Systems Manager Explorer disabling operational history, for the stated automation and remediation requirement.

Correct answer

AWS Systems Manager Automation runbooks defining ordered execution steps, for the required automation and remediation outcome.

Objective/domain: Automation and Remediation

Source: AWS Systems Manager Automation

Question 8 Instances in two private subnets have routes to each other, but return traffic fails after a network ACL rule change. Which controls should be checked together?

Answer choices

  1. A. S3 lifecycle policies and Cost Explorer filters, within the proposed design.
  2. B. IAM password policy and Reserved Instance terms, for the described technical objective.
  3. C. Security groups and network ACLs, along with the subnet route tables, within the proposed design.
  4. D. CloudFormation stack tags only, for the described technical objective and its associated operational control requirements, as configured.

Correct answer

Security groups and network ACLs, along with the subnet route tables, within the proposed design.

Objective/domain: Networking Operations

Source: Amazon VPC documentation

Question 9 An application should normally send DNS traffic to us-east-1 and fail over to us-west-2 when the primary health check fails. Which Route 53 configuration matches?

Answer choices

  1. A. Create an Active-Active Latency routing record for both regions, configuring the TTL to 0 seconds so clients bypass DNS caches, for the described technical objective and its associated operational control requirements, for the described technical objective and its associated operational control requirements, in practice.
  2. B. Create a Weighted routing record with weight 100 for us-east-1 and weight 0 for us-west-2, relying on the internal JVM DNS cache to route traffic during failure, for the described technical objective and its associated operational control requirements, under the organization’s defined implementation and exception-management process.
  3. C. Create a Primary routing policy record pointing to us-east-1 and associate it with an active Route 53 health check. Create a Secondary routing policy record pointing to us-west-2. Set both to use Failover routing, under the stated technical, operational, and governance constraints.
  4. D. Create a Geolocation routing record that routes all international traffic to us-east-1 and national traffic to us-west-2, for the described technical objective and its associated operational control requirements, under the documented operational and governance requirements.

Correct answer

Create a Primary routing policy record pointing to us-east-1 and associate it with an active Route 53 health check. Create a Secondary routing policy record pointing to us-west-2. Set both to use Failover routing, under the stated technical, operational, and governance constraints.

Objective/domain: Reliability

Source: Amazon Route 53 Active-Passive Failover

Question 10 A company is deploying a new application across multiple spoke VPCs and requires a centralized egress VPC for all internet-bound traffic. To achieve this routing model efficiently and at scale, what AWS networking solution should be implemented?

Answer choices

  1. A. Establish a full-mesh VPC Peering topology between all 15 VPCs, and enable route propagation on each peering connection, for the described technical objective and its associated operational control requirements, as the selected approach for the stated technical and business outcome, within the described operational context.
  2. B. Configure a Site-to-Site VPN from each spoke VPC directly to the NAT Gateways in the egress VPC, for the described technical objective and its associated operational control requirements, for the described technical objective and its associated operational control requirements, within the defined security and accountability boundaries.
  3. C. Create an AWS Transit Gateway. Connect all VPCs to the Transit Gateway. Configure the route tables of the spoke VPCs to route `0.0.0.0/0` to the Transit Gateway attachment, and configure the Transit Gateway route table to route internet-bound traffic to the central egress VPC
  4. D. Use an AWS Client VPN endpoint in each VPC to tunnel traffic directly to the centralized NAT Gateway interface, for the described technical objective and its associated operational control requirements, for the described technical objective and its associated operational control requirements, for the stated networking operations requirement.

Correct answer

Create an AWS Transit Gateway. Connect all VPCs to the Transit Gateway. Configure the route tables of the spoke VPCs to route `0.0.0.0/0` to the Transit Gateway attachment, and configure the Transit Gateway route table to route internet-bound traffic to the central egress VPC

Objective/domain: Networking Operations

Source: AWS Transit Gateway Centralized Egress

Where to go after the daily web set

How are AWS CloudOps Engineer Associate questions generated?

dotCreds builds AWS CloudOps Engineer Associate practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS CloudOps Engineer Associate practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.