The 3-Week Schedule for AWS Certified CloudOps Engineer - Associate
Week 1 — Monitoring and Reliability (44% of the exam)
Day 1 — CloudWatch fundamentals Metrics, namespaces, dimensions, statistics vs. percentiles. Default EC2 metrics vs. what needs the CloudWatch agent (memory and disk usage are not default — this shows up constantly). Custom metrics, resolution, retention.
Day 2 — Logs and audit trail CloudWatch Logs, log groups, retention settings, metric filters, subscription filters, Logs Insights query syntax. CloudTrail: management vs. data events, organization trails, log file validation. Know when the answer is CloudTrail vs. CloudWatch Logs vs. VPC Flow Logs.
Day 3 — Alarms and auto-remediation Alarm states, missing-data treatment, composite alarms. EventBridge rules and targets. SNS. Then the remediation side: Systems Manager Automation runbooks, Lambda targets, EC2 recovery actions. This is where domain 1 gets scenario-heavy.
Day 4 — Auto Scaling and load balancing Launch templates vs. launch configs, target tracking vs. step vs. scheduled scaling, cooldowns, lifecycle hooks, warm pools. ALB vs. NLB vs. GWLB, target groups, health check tuning, stickiness, cross-zone balancing.
Day 5 — High availability Multi-AZ vs. multi-Region. RDS Multi-AZ vs. read replicas (different purposes — the exam checks that you know which). Aurora failover. S3 Cross-Region Replication. Route 53 health checks and failover routing.
Day 6 — Backup and recovery AWS Backup plans and vaults, EBS snapshots and the incremental model, AMI lifecycle, Data Lifecycle Manager. RTO/RPO and matching the four DR strategies to them. S3 versioning, lifecycle policies, Object Lock.
Day 7 — Consolidate No new material. 50–60 practice questions on domains 1 and 2 only, then re-read the docs for everything you got wrong.
Week 2 — Automation, Security, Networking (56%)
Day 8 — CloudFormation
Template anatomy, intrinsic functions (Ref, GetAtt, Sub, FindInMap), parameters and mappings, conditions. Then the operational parts the exam loves: change sets, drift detection, DeletionPolicy, UpdateReplacePolicy, nested stacks, StackSets across accounts and Regions, and which update types cause replacement.
Day 9 — Systems Manager The single densest service on this exam. Parameter Store (Standard vs. Advanced, SecureString), Session Manager and why it beats bastion hosts, Patch Manager and patch baselines, Run Command, State Manager, Automation runbooks, Inventory. Know the SSM Agent prerequisites and the IAM instance profile it needs.
Day 10 — Deployment and containers Rolling, blue/green, canary, immutable. Elastic Beanstalk deployment policies. Then the SOA-C03 additions: ECR basics, EKS operational concepts, and where CDK and Terraform fit relative to CloudFormation.
Day 11 — IAM Policy evaluation logic and explicit deny. Identity vs. resource policies. Roles and cross-account access. Permission boundaries. SCPs and how they interact with IAM policies. IAM Identity Center. Practise reading a policy document and saying exactly what it allows.
Day 12 — Security services and cost KMS key types, rotation, grants. Secrets Manager vs. Parameter Store. GuardDuty, AWS Config with conformance packs and remediation, Inspector, Security Hub, Trusted Advisor — know which one answers which question. Then cost: Cost Explorer, Budgets, Savings Plans vs. Reserved Instances, S3 storage classes and Intelligent-Tiering, Compute Optimizer.
Day 13 — VPC Subnets and route tables, IGW vs. NAT Gateway, Security Groups vs. NACLs (stateful vs. stateless — reliably tested), VPC endpoints gateway vs. interface, peering and its limits, Transit Gateway, VPC Flow Logs and reading a rejected-traffic line. Expect multi-step troubleshooting scenarios here.
Day 14 — DNS and edge, then consolidate Route 53 routing policies — simple, weighted, latency, failover, geolocation, geoproximity, multivalue — and alias vs. CNAME. CloudFront behaviours, OAC, cache invalidation. Finish with 50–60 questions across domains 3, 4 and 5.
Week 3 — Mocks and repair
No new content this week. The whole point is finding your gaps while there's still time to close them.
Day 15 — Mock exam 1. Full 130 minutes, timed, no pausing, no looking anything up. Score it and note the per-domain breakdown.
Day 16 — Review every single wrong answer. Not just the right option — why each distractor is wrong. For anything you don't fully follow, read the actual AWS documentation page. Slower than it sounds; budget the full two hours.
Day 17 — Mock exam 2.
Day 18 — Review, then drill your weakest domain. By now a pattern is obvious. Mine was CloudFormation update behaviour and Route 53 routing policies.
Day 19 — Mock exam 3. You want to be consistently above 80% here. The real exam pass mark is 72%, but mock scores tend to run a little optimistic relative to it.
Day 20 — Read the official exam guide task statements end to end. Every bullet AWS lists is fair game. Anything you can't explain in a sentence, go look up. Flashcards for service limits and defaults.
Day 21 — Light review and stop. Skim your notes, confirm your Pearson VUE booking and ID, and finish early. Cramming the night before buys nothing on a scenario exam.
No comments:
Post a Comment