Cert Notes/ Commute Study Notes
Roadmap
KOEN
CLF-C02 · FoundationalCloud Practitioner - Foundational
DVA-C02 · AssociateDeveloper - Associate
SAA-C03 · AssociateSolutions Architect - Associate
SOA-C02 · AssociateCloudOps Engineer - Associate
  • Week 1
    • 1.Query Health API for ongoing events
    • 2.GitHub Actions OIDC example
    • 3.Day 3
    • 4.AWS Organizations: How One Person Operates 100 Accounts
    • 5.Week 1 Consolidated Review: Revisiting the First Week Through Operator Scenarios
  • Week 2
    • 1.CloudWatch Metrics Internal Structure: Namespace, Dimension, Resolution, Cardinality
    • 2.CloudWatch Logs: Internal Structure of Log Groups and Subscription Patterns
    • 3.Logs Insights Query Language: Operator's Debugging SQL
    • 4.Metric Filter, EMF Deep-Dive, Anomaly Detection: Three Bridges Between Metrics and Logs
    • 5.Week 2 Integrated Review: CloudWatch 12 Scenario Problems
  • Week 3
    • 1.CloudWatch Alarms: M of N Evaluation Model and Composite Alarm Design Philosophy
    • 2.CloudWatch Dashboards: Cross-Account Aggregation, Variables, Observability Design
    • 3.CloudWatch Agent: Internal Operations, StatsD/collectd Integration, procstat Plugin
    • 4.Synthetics Canary, X-Ray Sampling, ServiceLens: User-Centric Monitoring Design
    • 5.Week 3 Review: CloudWatch Observability Stack Synthesis
  • Week 4
    • 1.CloudTrail: API Audit Logging Design Principles and Organization Trail
    • 2.CloudTrail Lake Advanced: SQL Audit Analysis, Insights Anomaly Detection, Cross-Account Queries
    • 3.AWS Config Advanced: Rule Evaluation Triggers, Custom Rule Lambda, Conformance Pack, Auto Remediation
    • 4.Audit Manager, License Manager, Resource Explorer: Audit Automation and Operational Visibility Design
    • 5.Week 4 Comprehensive Review: CloudTrail, Config, Audit Stack Integration
  • Week 5
    • 1.AWS Systems Manager: The Operator's Central Control Tower
    • 2.Run Command, State Manager, Maintenance Window: The SSM Automation Trio
    • 3.Patch Manager: Secure and Compliant Patching
    • 4.Parameter Store, Session Manager, Automation Runbook: SSM Advanced Automation
    • 5.Week 5 Review: Systems Manager Comprehensive Scenario
  • Week 6
    • 1.CloudFormation: Infrastructure as Code from the Operator's Perspective
    • 2.Change Set, Drift Detection, Rollback Trigger: Three Pillars of Safe CFn Operations
    • 3.Nested Stack, Cross-Stack Reference, StackSets: Large-Scale IaC Operations
    • 4.Service Catalog, AppConfig, AppRegistry: The Science of Governance and Dynamic Configuration
    • 5.Week 6 Comprehensive Review: Complete CloudFormation Operations Mastery
  • Week 7
    • 1.Elastic Beanstalk and Five Deployment Policies: The True Cost of Zero Downtime
    • 2.CodeDeploy: The Decision to Deploy Code Only and AppSpec's 13-Stage Lifecycle
    • 3.EC2 Image Builder: The Operational Virtue of Golden AMI
    • 4.OpsWorks EOL and Launch Template: Mixed Instances Policy's True Value
    • 5.Week 7 Comprehensive Review: Scenario-Based Deployment and Provisioning Decision-Making
  • Week 8
    • 1.VPC as a Virtual Data Center, and Five Common Operator Confusions
    • 2.Three Tools for Observing VPC Traffic, and the Limits of Metadata
    • 3.NAT Gateway, VPC Endpoint, PrivateLink — Three Ways VPC Meets the Outside
    • 4.Transit Gateway, VPN, Direct Connect, Route 53 — The Big Picture of Multi-VPC and Hybrid
    • 5.Week 8 Comprehensive Review and 12 Scenario Problems
  • Week 9
    • 1.KMS, Managing Keys Without Ever Seeing Them
    • 2.Secrets Manager, Rotating Live System Secrets Without Downtime
    • 3.IAM Access Analyzer and Trusted Advisor, Proving Permissions with Code
    • 4.Day 4
    • 5.Day 5
  • Week 10
    • 1.EBS Snapshot: How Incremental Backup Remembers Only Changed Blocks
    • 2.AWS Backup: Making Backups Undeletable Even by Administrators
    • 3.RDS Multi-AZ vs Read Replica: Choosing Between Synchronous and Asynchronous
    • 4.S3 Replication, Storage Gateway, Elastic Disaster Recovery: How to Move Files and Workloads
    • 5.Week 10 Comprehensive Review: Backup, DR, HA as One Picture
  • Week 11
    • 1.Compute Optimizer: How 14 Days of Metrics Resize Instances
    • 2.Database Failover, Performance and Scaling
    • 3.Data Migration, Replication, Cross-Region Backup
    • 4.Patching, Maintenance Windows, Availability
    • 5.Week 11 Database Operations Summary
  • Week 12
    • 1.AWS Organizations, Multi-Account Strategy
    • 2.Control Tower, Compliance as Code, Governance
    • 3.Tagging Strategy, Resource Organization
    • 4.Disaster Recovery Architecture, RTO/RPO
    • 5.Week 12 Enterprise Operations and SOA Exam Synthesis
SAP-C02 · ProfessionalSolutions Architect - Professional
DOP-C02 · ProfessionalDevOps Engineer - Professional
SCS-C03 · SpecialtySecurity - Specialty
MLA-C01 · AssociateMachine Learning Engineer - Associate
AIF-C01 · FoundationalAI Practitioner - Foundational
DEA-C01 · AssociateData Engineer - Associate
MLS-C01 · SpecialtyMachine Learning - Specialty
← SOA-C02/Week 1/Day 5
SOA-C02· AssociateWeek 1 · Day 5~41 min read

Day 5 - Week 1 Consolidated Review: Revisiting the First Week Through Operator Scenarios

The picture we built over the week had four parts: AWS's physical map (Region / AZ / Edge), who is responsible for what on top of it (Shared Responsibility), who gets to allow whom to do what (IAM's 6-step evaluation algorithm), and how to bind dozens or hundreds of accounts under one governance model (Organizations / SCP / Identity Center). These four pictures are the backdrop for every SOA-C02 scenario. When you're solving an exam question and the answer isn't immediately obvious, build the habit of first classifying "which of the four is this scenario asking about" — the correct answer will surface naturally from the options.

This week's content needs to be settled in your head for next week's CloudWatch, Config, and CloudTrail to layer naturally on top. When an alarm fires, the operator's daily work is tracing backwards: "in which region and which AZ, who (which IAM principal), through which permission evaluation path, in which account, within which SCP/boundary limits" did the work happen. The infrastructure that makes that trace possible was this week's subject.

The Operator's Mental Map: One Page, One More Look

┌─────────────────────────────────────────────────────────┐
│         [AWS Global Infrastructure]                     │
│  Region > AZ > Edge / Local Zones / Outposts            │
│  - Control plane often tied to us-east-1 (IAM/R53/CF)   │
│  - AZ is the minimum isolation unit. NAT GW / EBS /     │
│    RDS Standby are per-AZ                               │
│  - Only ZoneId (apne2-az1) matches across accounts;     │
│    ZoneName is shuffled                                 │
├─────────────────────────────────────────────────────────┤
│         [Shared Responsibility]                         │
│  AWS: Security OF the Cloud                             │
│  Customer: Security IN the Cloud                        │
│  - Abstraction level↑ ⇒ responsibility line↑            │
│    (EC2 < ECS < Fargate < Lambda)                       │
│  - Data classification, IAM, and encryption key policy  │
│    are always the customer's                            │
├─────────────────────────────────────────────────────────┤
│         [IAM Evaluation 6-step]                         │
│  Explicit Deny → Org SCP → Resource Policy →            │
│   Identity Policy → Permission Boundary →               │
│   Session Policy → final Allow/Deny                     │
│  - A single Deny anywhere blocks immediately            │
│  - Cross-account requires Allow on both sides           │
├─────────────────────────────────────────────────────────┤
│         [Multi-Account Governance]                      │
│  Organizations / SCP / RAM / Control Tower / IdC        │
│  - SCPs don't apply to the Management Account           │
│    (don't put workloads there)                          │
│  - Centralize security services via Delegated Admin     │
│  - Identity Center + IdP federation = ops without       │
│    IAM Users                                            │
└─────────────────────────────────────────────────────────┘

The operator's daily debugging flow runs over this map in the following order.

  1. Catch the symptom: CloudWatch alarm / Health Dashboard / user complaints
  2. Narrow down the cause candidates: write API events from the previous 5-30 minutes in CloudTrail
  3. Suspect a permission problem: IAM Policy Simulator + Access Analyzer + read the errorMessage carefully
  4. Suspect an infrastructure problem: AWS Health (SHD/PHD) + Service Quotas
  5. Suspect an account-level security violation: Config + GuardDuty + Security Hub findings
  6. Post-recovery follow-up: TAM/support case / RCA documentation / strengthen Config rules

With this flow in your head, one line saying "there's an outage" automatically determines "which console screen to open within 5 minutes." Exam questions like "which tool do you check first?" are almost always answered from this table.

Pitfall Collection: 6 Mistakes Operators Keep Repeating

Synthesizing the week's content, these six are the patterns where operators repeat the same incidents.

  1. Putting workloads in the Management Account: SCPs don't apply to this account, so running EC2/RDS there leaves you defenseless if the root key leaks. The AWS Landing Zone standard: management = billing and org management only; workloads go in member accounts in separate OUs.
  2. A single-AZ NAT GW / Single-AZ RDS / NLB registered in a single AZ: You try to save money, and when one AZ wobbles, everything goes down. A NAT GW is an AZ-scoped resource with no automatic failover.
  3. IAM Users + permanently issued access keys: Missed rotation and missed offboarding are the #1 cause of incidents. Capital One in 2019 and Uber in 2022 were both failures of credential management. The answer is Identity Center + IdP federation.
  4. Ignoring the us-east-1 dependency: Writes to IAM, Route 53 public zones, CloudFront, and Organizations depend on the us-east-1 control plane. Feel safe because "it's a global service" and you get swept up in an outage like December 2021.
  5. Not explicitly disabling IMDSv1: Even for new EC2 instances, unless you enforce it via launch templates / SCPs / Config, an operator can accidentally launch v1. It's the entry point for SSRF attacks.
  6. Managing CloudTrail / Config individually in member accounts: The self-referential problem of having to check who disabled it — using that same account's trail. The answer is Organization Trail + Log Archive Account + S3 Object Lock.

Avoiding all six of these is the operator's starting line. The exam asks about these pitfalls, transformed into scenarios.

The Operator's One-Line Command Card: One More Pass Before the Exam

Commands you've actually typed once in the CLI — not just clicked in the console — are the ones you remember in the exam room. Here's the Week 1 core CLI collected onto one card.

# 1) Check ZoneId — the starting point for cross-account cost optimization
aws ec2 describe-availability-zones --region ap-northeast-2 \
  --query 'AvailabilityZones[*].[ZoneName,ZoneId,State]' --output table
 
# 2) Health events — both in-progress and upcoming
aws health describe-events \
  --filter "eventStatusCodes=open,upcoming" --region us-east-1
aws health describe-events \
  --filter "eventStatusCodes=open,upcoming" --region us-west-2
 
# 3) IAM recent usage — find access keys unused for 90+ days
aws iam generate-credential-report
aws iam get-credential-report --query 'Content' --output text \
  | base64 --decode
 
# 4) IAM Access Analyzer — check externally exposed resources
aws accessanalyzer list-analyzers
aws accessanalyzer list-findings --analyzer-arn arn:aws:access-analyzer:...
 
# 5) View the Organizations structure
aws organizations list-roots
aws organizations list-organizational-units-for-parent --parent-id r-xxxx
aws organizations list-accounts-for-parent --parent-id ou-xxxx-yyyy
 
# 6) Check SCP effects — all policies applied to a specific account
aws organizations list-policies-for-target \
  --target-id 123456789012 --filter SERVICE_CONTROL_POLICY
 
# 7) Query Identity Center Permission Set assignments
aws sso-admin list-permission-sets --instance-arn arn:aws:sso:::instance/...
 
# 8) Policy Simulator — validate in advance
aws iam simulate-principal-policy \
  --policy-source-arn arn:aws:iam::111:user/alice \
  --action-names s3:PutObject \
  --resource-arns arn:aws:s3:::my-bucket/key

The most frequently forgotten item here is that generate-credential-report → get-credential-report is a two-step process. The first call is an asynchronous generation trigger; the second call is the actual download.

🔍 Going deeper: simulate-principal-policy evaluates SCPs, Permission Boundaries, and Resource Policies all at once, finding the cause of permission denials in real operations. The friendliest case is when CloudTrail's errorMessage prints "explicit deny from SCP"; when it doesn't, you have to narrow it down step by step with the simulator. The simulator can also mimic conditions like MFA and SourceIp via --context-entries, so it's also used for debugging IP allowlist conditions.

💡 Memorization tip: The operator's "first-pass permission diagnosis 3-hit combo" is ① CloudTrail's errorCode / errorMessage → ② simulate-principal-policy → ③ Access Analyzer "Reachable from outside." With this order fixed in your head, you can solve any IAM scenario question.

Week 1 Self-Assessment Checklist

You should be able to answer "yes" to all 11 of the following questions before moving on to Week 2 comfortably.

  • Can you explain the difference between Region / AZ / Edge, and the fact that a NAT GW is an AZ-scoped resource?
  • Can you explain why the us-east-1 control plane dependency affects even IAM, Route 53, and CloudFront?
  • Do you know the difference between ZoneName and ZoneId, and the matching method for reducing cross-AZ data transfer costs between two accounts?
  • Can you explain the differences in the responsibility boundary for EC2 / ECS Fargate / Lambda / S3 under the shared responsibility model?
  • Can you recall, in order, the 6-step IAM policy evaluation algorithm (Deny→SCP→Resource→Identity→Boundary→Session)?
  • Can you explain, in one line each, the differences between SCPs, Permission Boundaries, and Session Policies?
  • Do you know which IAM Role internally realizes an Identity Center Permission Set?
  • Do you know in which regions to place AWS Health Dashboard and EventBridge aws.health rules?
  • Can you explain the PCI-DSS value of the Organization Trail + Log Archive Account + S3 Object Lock pattern?
  • Can you explain how the quadruple defense of IMDSv2 + hop limit 1 + Config rule + SCP blocks SSRF?
  • Do you know the standard pattern of delegating GuardDuty, Security Hub, Inspector, and Macie to a security account via Delegated Administrator?

📝 Practice Questions

Click a choice to reveal the answer and explanation.

Question 1

A game company serving Korean users operates in ap-northeast-2. The operations team wants to know in advance and prepare for the fact that during a us-east-1 outage, "console login remains possible, but writes such as creating new IAM users or changing Route 53 records may not be." What is the most appropriate additional measure on the SDK/CLI side?

Question 2

An operations team running a web service on an ASG lost all traffic when AZ-a failed. Root-cause analysis showed the NAT GW existed only in AZ-a, and the private subnet route tables of AZ-b and AZ-c all pointed at the AZ-a NAT GW. What's the answer?

Question 3

An EC2 instance attempts a PUT to an S3 bucket encrypted with SSE-KMS using a KMS CMK and gets AccessDenied. The IAM Policy has `s3:PutObject Allow`, and the Bucket Policy also has an Allow. In CloudTrail, both an `s3.amazonaws.com` event and a `kms.amazonaws.com` event are logged as failures. The most likely cause is?

Question 4

A company operates 60 AWS accounts with 200 employees. Employees join and leave every week, and the security team is exhausted by access key rotation and missed offboarding. The most efficient change is?

Question 5

A company runs 50 accounts under Organizations and wants to prevent all accounts from using any region other than `us-east-1` and `ap-northeast-2`. The goal is data sovereignty compliance. The most efficient method is?

Question 6

An operator wants to delegate IAM Role creation to developers, while enforcing that those Roles' effective permissions cannot exceed the company's standard policy scope. Which combination is correct?

Question 7

A company wants to collect CloudTrail logs from 50 member accounts in one place and prevent operators from modifying or deleting those logs. The goal is meeting PCI-DSS requirement 10.5.5. The standard pattern is?

Question 8

An operations team wants to prevent metadata SSRF attacks against EC2 instances. What is the strongest quadruple-defense operational standard?

Question 9

An operator wants to see the EC2 instance inventory of 100 accounts at once. The security team wants OS patch status, tags, and instance types. The most efficient method is?

Question 10

An operations team created an EventBridge `aws.health` rule to receive us-east-1 outage alerts at 3 AM. The standard pattern for receiving all events without gaps is?

Question 11

A security operator must separate start/stop permissions for 200 EC2 instances across 5 departments. There are 100 employees and 200 EC2 instances; employees join and leave weekly and department transfers are frequent. The most scalable approach is?

Question 12

A security operator wants to see the GuardDuty findings, Security Hub scores, Inspector vulnerabilities, and Macie data classification results of 100 accounts in one place. The standard pattern is?

Next Week Preview: Week 2 — The Internals of CloudWatch

Next week covers the internal structure of CloudWatch Metrics and Logs, the most frequently used operator tool. The starting point of every alarm and every debugging session.

  • Day 1: The Metrics data model — Namespace, Dimension, Resolution (1s vs 60s), cardinality explosion
  • Day 2: The Logs Group/Stream/Event structure and Subscription Filters, the VPC Flow Logs cost trap
  • Day 3: The Logs Insights query language — the operator's SQL, a parse / filter / stats pattern library
  • Day 4: Metric Filters, EMF in depth, Anomaly Detection's ML baselines
  • Day 5: Week 2 review + 10 scenario questions

Once you finish Week 2, you'll develop the instinct to look at a pile of console graphs and judge within 5 seconds whether "our service is dying right now." That instinct is 50% of the SOA-C02 exam and of real-world operations.

PreviousAWS Organizations: How One Person Operates 100 AccountsWeek 1 · Day 4Next CloudWatch Metrics Internal Structure: Namespace, Dimension, Resolution, CardinalityWeek 2 · Day 1

On this page

  • The Operator's Mental Map: One Page, One More Look
  • Pitfall Collection: 6 Mistakes Operators Keep Repeating
  • The Operator's One-Line Command Card: One More Pass Before the Exam
  • Week 1 Self-Assessment Checklist
  • Practice Questions (12 Scenarios)
  • Next Week Preview: Week 2 — The Internals of CloudWatch