Official Bank 0/1109

SOA-C02 AWS Certified SysOps Administrator – Associate Exam (SOA-C02) - AWS Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
1109 Total Questions
1
Question
[Monitoring, Reporting, and Automation] A SysOps administrator is responsible for managing a fleet of Amazon EC2 instances. These EC2 instances upload build artifacts to a third-party service. The third-party service recently implemented a strict IP allow list that requires all build uploads to come from a single IP address.

What change should the systems administrator make to the existing build fleet to comply with this new requirement?
Options
A Move all of the EC2 instances behind an internet gateway and provide the gateway IP address to the service.
B Move all of the EC2 instances behind a NAT gateway and provide the gateway IP address to the
service.
C Move all of the EC2 instances to a peered VPC and provide the VPC IP address to the service.
D Move all of the EC2 instances into a single Availability Zone and provide the Availability Zone IP address to the service.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
[Monitoring, Reporting, and Automation] A company requires that all activity in its AWS account be logged using AWS CloudTrail. Additionally, a SysOps administrator must know when CloudTrail log files are modified or deleted.

How should the SysOps administrator meet these requirements?
Options
A Enable log file integrity validation. Use the AWS CloudTrail .Processing Library to validate the log files.
B Enable log file integrity validation Use the AWS CLI to validate the log files.
C Use Amazon CloudWatch Logs to monitor the log files for modifications.
D Use CloudTrail Insights to monitor the log files for modifications.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
[Monitoring, Reporting, and Automation] A company runs an application on hundreds of Amazon EC2 instances in three Availability Zones The application calls a third-parly API over the public internet A SysOps administrator must provide the third party with a list of static IP addresses so that the third party can allow traffic from the application

Which solution will meet these requirements?
Options
A Allocate one Elastic IP address in each Availability Zone. Associate the Elastic IP address with all the instances in the Availability Zone
B Add a NAT gateway in the public subnet of each Availability Zone. Make the NAT gateway the default route of all private subnets In those Availability Zones.
C Update the main route table to send the traffic to the internet through an Elastic IP address that is
assigned to each instance.
D Place the instances behind a Network Load Balancer (NLB). Send the traffic to the interne! through the private IP address of the NLB
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
[Monitoring, Reporting, and Automation] A SysOps administrator has set up a new Amazon EC2 instance as a web server in a public subnet. The instance uses HTTP port 80 and HTTPS port 443. The SysOps administrator has confirmed internet connectivity by downloading operating system updates and software from public repositories. However, the SysOps administrator cannot access the instance from a web browser on the internet.

Which combination of steps should the SysOps administrator take to troubleshoot this issue? (Select THREE.)
Select 3
Options
A Ensure that the outbound rules of the instance's security group allow traffic on ports 80 and 443.
B Ensure that the inbound rules of the instance's security group allow traffic on ports 80 and 443.
C Ensure that AWS WAF is turned on for the instance and is blocking web traffic.
D Ensure that the filtering rules for any firewalls that are running on the instance allow inbound traffic on ports 80 and 443.
E Ensure that ephemeral ports 1024-65535 are allowed in the inbound rules of the network ACL that is associated with the instance's subnet.
F Ensure that ephemeral ports 1024-65535 are allowed in the outbound rules of the network ACL that is associated with the instance's subnet.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
[Monitoring, Reporting, and Automation] A company is testing Amazon Elasticsearch Service (Amazon ES) as a solution for analyzing system logs from a fleet of Amazon EC2 instances. During the test phase, the domain operates on a single- node cluster. A SysOps administrator needs to transition the test domain into a highly available production-grade deployment.

Which Amazon ES configuration should the SysOps administrator use to meet this requirement?
Options
A Use a cluster of six data nodes across three Availability Zones. Use three dedicated master nodes.
B Use a cluster of four data nodes across two AWS Regions. Deploy four dedicated master nodes in each Region.
C Use a cluster of eight data nodes across two Availability Zones. Deploy four master nodes in a failover AWS Region.
D Use a cluster of six data nodes across three Availability Zones. Use six dedicated master nodes.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.