AWS Certified DevOps Engineer – Professional (DOP-C02) Study Guide: Domains and Study Plan
An AWS DOP-C02 guide covering the six exam domains, delivery automation, and a practical preparation plan.
The AWS Certified DevOps Engineer – Professional (DOP-C02) exam tests how to build and operate automated, highly available systems on AWS. It covers CI/CD, infrastructure as code (IaC), monitoring, incident response, resilience, and security/compliance. The focus is connecting development, deployment, and operations in a process that can be verified and recovered.
Objectives and service scope can change, so use the latest AWS DOP-C02 exam guide as your source of truth.
Who is this exam for? What background helps?
The exam is for DevOps, platform, or SRE engineers and people responsible for pipelines, infrastructure automation, and production operations. AWS describes its target candidate as having at least two years of experience provisioning, operating, and managing AWS environments, plus software lifecycle and programming or scripting experience. This is a target profile, not a registration requirement.
Build a foundation with DVA-C02 for development and deployment, or SOA-C03 for operations. DOP-C02 focuses on automated delivery and cross-environment operations; SAP-C02 focuses on architecture and organizational complexity.
Exam domains and weights
| Domain | Official name | Main focus | Weight |
|---|---|---|---|
| 1 | SDLC Automation | CI/CD, automated testing, and deployment strategies | 22% |
| 2 | Configuration Management and IaC | Configuration, reusable infrastructure, and account automation | 17% |
| 3 | Resilient Cloud Solutions | High availability, scaling, and self-healing systems | 15% |
| 4 | Monitoring and Logging | Logs, metrics, alarms, and monitoring automation | 15% |
| 5 | Incident and Event Response | Incident handling and automated response | 14% |
| 6 | Security and Compliance | Scaled identity, security automation, and compliance validation | 17% |
SDLC Automation has the largest weight. Configuration management and security/compliance each account for 17%. Study the complete delivery lifecycle, not only CI/CD tools.
How to study each domain
Domain 1: SDLC Automation
Understand CI/CD pipelines, automated testing, artifact management, and deployment strategies for instances, containers, and serverless applications.
Common mix-up: treating a green pipeline as proof of a successful release. Define quality gates, staged deployment, post-deployment validation, and rollback conditions.
Domain 2: Configuration Management and IaC
Learn to provision and manage infrastructure repeatably with declarative configuration, and automate the setup and governance of multi-account and multi-Region environments.
Common mix-up: configuration drift, secrets in repositories, or manually copying settings at scale. Separate infrastructure definitions, parameters, and secrets, and make changes auditable.
Domain 3: Resilient Cloud Solutions
Focus on high availability, scaling, and self-healing. Determine which components recover automatically after a failure and which require a human decision.
Common mix-up: configuring Auto Scaling without checking health signals, state, or data consistency after recovery. Validate the design with failure scenarios.
Domain 4: Monitoring and Logging
Design how logs and metrics are collected, aggregated, stored, and analyzed. Connect monitoring signals to alarms and operational actions.
Common mix-up: dashboards without action thresholds, or growing log costs without a retention plan. Assign an owner and response process to each critical signal.
Domain 5: Incident and Event Response
Use event-driven methods to detect issues, respond automatically, and escalate to people when needed, while preserving audit records and post-incident improvements.
Common mix-up: triggering high-privilege automation for every event. Define severity tiers, automated actions, human approval, and escalation paths; restrict automation permissions.
Domain 6: Security and Compliance
Integrate identity, data protection, security monitoring, and compliance checks into routine automation across accounts.
Common mix-up: checking security only after release, or giving pipeline roles excessive permissions. Add policy checks, scans, and compliance evaluation to the pipeline and record results.
Suggested study order
- CI/CD, automated testing, and release strategies.
- IaC, configuration, parameters, and secrets management.
- Resilience, monitoring, and logging.
- Incident-response automation.
- Scaled security and continuous compliance.
Check your readiness with three questions
- If a production deployment fails, how do automated rollback and human decisions work together?
- How do you prove an artifact’s origin and ensure the pipeline has only the permissions it needs?
- When many alerts arrive at once, how do you prioritize, reduce noise, and escalate?
A three-step preparation plan
- Use the official guide. Review the task statements in all six domains and plan time by weight.
- Map the delivery loop. Explain how each stage—from commit, build, test, and release to monitoring, rollback, and compliance records—is verified.
- Practice and review. Group scenario-question misses by domain and cause, then return to the relevant official task and AWS documentation.
Start practicing
When you are ready, use exam code DOP-C02 to practice by domain, then revisit the matching task statements.