AWS Certified DevOps Engineer – Professional DOP-C02 is the current AWS professional-level exam for engineers who provision, operate and manage distributed application systems on AWS. AWS recommends two or more years of experience provisioning, operating and managing AWS environments, plus experience with software-development lifecycle practices and programming or scripting.
The current DOP-C02 exam is 180 minutes with 75 multiple-choice or multiple-response questions. The exam guide explains that 65 questions are scored and 10 are unscored. The passing score is 750 on a 100–1,000 scale and the current exam fee is USD 300.
SDLC Automation is the largest domain at 22%
Domain 1 covers CI/CD pipeline implementation, automated testing, artifact management and deployment strategies across instance, container and serverless environments.
Services and concepts include source repositories, AWS CodePipeline, CodeBuild, CodeDeploy, artifact storage, testing gates, rollback and safe release patterns such as rolling, blue/green or canary approaches.
CI/CD is about reliable flow, not just pipeline services
A CodePipeline workflow should connect source, build/test, artifact, deployment and approval. Candidates should understand failure handling, cross-account/Region considerations and how deployment requirements affect strategy.
CodeDeploy helps illustrate controlled application rollout and rollback on supported compute targets.
Configuration Management and IaC is 17%
Domain 2 tests defining reusable infrastructure, managing the infrastructure lifecycle, multi-account/multi-Region provisioning and automation for complex or large-scale tasks.
A CloudFormation foundation is central, alongside AWS CDK/SAM-style concepts, StackSets, configuration management, Systems Manager, Organizations and infrastructure version/change practices.
Resilient Cloud Solutions accounts for 15%
Domain 3 covers high availability, scalability and automated recovery to meet business RTO/RPO requirements. Candidates should translate availability objectives into technical design and identify single points of failure in existing workloads.
Multi-AZ, multi-Region, Auto Scaling, load balancing, replication, backup, failover and recovery automation all belong to this domain.
Monitoring and Logging accounts for another 15%
Domain 4 covers collection, aggregation and storage of logs/metrics, analysis for issue detection, and automated monitoring/event management in complex environments.
A CloudWatch model should include metrics, logs, alarms, dashboards and event-driven action, while CloudTrail/X-Ray and other services add audit and tracing context.
Incident and Event Response is 14%
Domain 5 covers event sources, processing/notification/action, configuration changes in response to events, and troubleshooting system/application failures. EventBridge, Health, CloudTrail, SNS/SQS/Kinesis/Lambda/Step Functions and Systems Manager can participate in response workflows.
Systems Manager is especially relevant for fleet operations and automated remediation of known undesirable state.
Security and Compliance is 17%
Domain 6 includes IAM at scale, automated security controls/data protection, and security monitoring/auditing. Candidates should understand IAM policies/roles, Organizations/SCPs, encryption, secrets, logging, Config, GuardDuty, Security Hub and related controls.
DevOps automation should make secure/compliant state repeatable rather than rely on manual reviews after deployment.
The exam is explicitly professional-level and cross-domain
A failed deployment can be an IAM problem, network problem, artifact issue, health-check failure or CloudFormation error. A resilience problem can involve deployment strategy and monitoring as well as architecture.
This is why professional scenarios often combine several AWS services and ask for the most operationally mature solution rather than one service definition.
The target role bridges software delivery and cloud operations
AWS lists advanced networking algorithms, deep developer security recommendations, database performance design and full-stack coding as out-of-scope. The target candidate instead builds automated infrastructure, operates systems, secures AWS environments and improves delivery/operations processes.
The DOP-C02 professional role is therefore centered on automation, resilience, observability, response and governance.
The blueprint is one continuous DevOps feedback loop
Code moves through automated pipelines into infrastructure described as code; monitoring validates the release; resilience keeps service available; events trigger remediation; security/compliance guardrails constrain the entire lifecycle; and lessons feed back into code and automation.
Domain 1 also includes artifact management because a delivery pipeline needs controlled, versioned inputs. Build outputs, container images, packages and deployment bundles should be stored, scanned, versioned and promoted predictably. Rebuilding an artifact differently for each environment undermines reproducibility.
Automated testing should appear at several pipeline stages. Unit tests, integration tests, security checks, policy checks and deployment validation can stop a release before production when evidence is insufficient. Professional DevOps design uses gates strategically rather than relying only on manual approval at the end.
Deployment strategies should be matched to failure tolerance. Rolling updates reduce extra capacity needs, blue/green provides a full alternate environment, and canary approaches expose a small portion of traffic first. The exam often asks which strategy best balances rollback speed, cost and risk.
Infrastructure as code should be versioned and reviewed like application code. CloudFormation/CDK/SAM templates, StackSets and configuration-management definitions can create or modify large parts of an environment. Change sets, pull requests, drift detection and rollback make infrastructure changes safer.
Multi-account automation is a professional-level theme. Organizations, Control Tower-like governance patterns, StackSets, IAM roles and centralized logging/configuration allow teams to apply standards without manually configuring every account. The challenge is preserving delegated ownership while enforcing guardrails.
Large-scale operations should prefer managed automation over one-off shell sessions. Systems Manager, Lambda, Step Functions, EventBridge and configuration-management tools can coordinate repeatable fleet tasks with logging, permissions and failure handling.
Resilience requires translating business RTO/RPO and availability requirements into architecture. Multi-AZ redundancy may satisfy one workload, while cross-Region replication and automated failover may be necessary for another. Overengineering every workload is as poor a DevOps decision as underengineering a critical one.
Self-healing is a key DOP-C02 idea. Health checks, Auto Scaling, managed service failover, event-driven remediation and immutable replacement can restore desired service automatically. Automation should address known failure modes while still exposing incidents that require human diagnosis.
Monitoring design should distinguish metrics, logs and traces. Metrics show trends and thresholds, logs provide detailed event context and traces connect distributed request paths. CloudWatch, X-Ray, CloudTrail and service-specific telemetry often need to be combined to find root cause.
Cross-account and cross-Region observability is especially important in complex AWS estates. Central dashboards, log aggregation and event routing reduce the chance that each account becomes an isolated monitoring island. Permissions and encryption must still protect centralized telemetry.
Incident response in DOP-C02 is strongly event-driven. AWS Health, EventBridge and CloudTrail can trigger notifications or workflows; SNS, SQS, Kinesis, Lambda and Step Functions can process events; Systems Manager can apply controlled remediation. Candidates should understand the chain rather than memorize service names separately.
Failed deployment analysis is a core professional skill. CodePipeline may fail because CodeBuild tests failed, an artifact is missing, CodeDeploy health checks reject targets, CloudFormation cannot create a resource, or IAM prevents an action. The best first step is reading the pipeline/deployment evidence at the failing stage.
Security at scale includes identity boundaries across teams and automation. Human administrators, pipelines, workloads and cross-account roles all need least privilege. Organizations/SCPs can restrict entire accounts while IAM/resource policies define finer permissions.
Secrets and encryption should be automated into delivery rather than copied manually. KMS, Secrets Manager/Parameter Store-style patterns, certificate services and encrypted storage can provide data protection while pipelines retrieve only the credentials required for their task.
Security monitoring/auditing includes CloudTrail, Config, GuardDuty, Security Hub, Inspector and log analysis. The professional role should turn findings into repeatable remediation or guardrails rather than manually fixing the same misconfiguration in every account.
Cost optimization appears as a cross-cutting operations consideration even though there is no dedicated cost domain. Build minutes, retained logs, duplicate environments, idle capacity, data transfer and overprovisioned resilience all affect operational efficiency. The exam can reward solutions that meet requirements without unnecessary complexity.
The current certification page also notes that the exam uses English, Japanese, Korean and Simplified Chinese, with the Korean version scheduled for retirement after December 31, 2026. This does not change the technical blueprint, but it is a current logistics detail for candidates choosing an exam language.
For final scope review, think in verbs from the exam guide: implement CI/CD, automate testing, manage artifacts, define infrastructure, automate accounts, implement resilience, collect/analyze telemetry, process events, remediate configuration and automate security/compliance. Those verbs make the professional job role clearer than a service catalog.
The exam guide explicitly describes a compensatory scoring model. Candidates do not need to pass each domain individually; the overall scaled score determines the result. That does not justify skipping smaller domains, because professional scenarios routinely combine security, events, IaC and monitoring in one question.
Code-repository best practices also sit beneath SDLC automation. Branching, protected changes, peer review, artifact traceability and immutable build outputs help teams know exactly what code and configuration reached an environment.
Hybrid deployments remain in scope conceptually because DevOps engineers may automate systems that span AWS and on-premises environments. The professional skill is designing repeatable deployment/monitoring/configuration workflows across boundaries without assuming every component runs in one VPC.
Tagging and metadata are cross-cutting operations tools. Consistent tags can drive cost allocation, ownership, automation scope, backup policy, monitoring or remediation. Poor metadata makes fleet-level automation riskier because resources cannot be selected reliably.
Event-driven architectures such as fan-out, queues and streams help decouple producers from consumers. The candidate should know when SNS, SQS, Kinesis, EventBridge, Lambda or Step Functions fit the required delivery, buffering, ordering or orchestration behavior.
Systems Manager OpsCenter and related operational tools can centralize incidents and remediation tasks. The broader principle is that operational events should be captured, enriched, assigned and resolved through repeatable workflows instead of relying on ad-hoc administrator memory.
AWS Config belongs at the intersection of desired state, compliance and event response. A noncompliant resource can be detected and, in suitable cases, automatically remediated. This is a concrete example of turning governance into code and automation.
For final blueprint review, build one scenario that crosses all six domains: code enters a pipeline, IaC provisions infrastructure, blue/green deploys across resilient targets, CloudWatch validates health, EventBridge triggers rollback/remediation, and security policies/logging prove compliance. That integrated view matches the level of the professional exam.
Within the broader AWS certification portfolio, DOP-C02 is the advanced role for engineers who can turn that loop into reliable, secure and scalable operations across complex AWS environments.