Exam prep
AWS Certified Solutions Architect – Associate (SAA-C03)
Helpful information and relevant policies for AWS Certification candidates regarding test day procedures, including check-in steps, ID requirements, testing rules, and exam functionality.
Start my AWS Certified Solutions Architect – Associate (SAA-C03) planExam day
Know what AWS Certified Solutions Architect – Associate (SAA-C03) asks on the day.
Question formats to expect:
-
Single select (Radio)
Select one option from a collection of options
-
Multiple select (Checkbox)
Select all options that apply from a collection of options
Exam domains
What AWS Certified Solutions Architect – Associate (SAA-C03) covers.
Every exam domain — so practice maps to what the exam actually weights.
- 01
Design Secure Architectures
30% of the examCovers designing secure access to AWS resources, secure workloads and applications, and appropriate data security controls.
- 02
Design Resilient Architectures
26% of the examCovers designing scalable and loosely coupled architectures, and highly available and/or fault-tolerant architectures.
- 03
Design High-Performing Architectures
24% of the examCovers high-performing storage, compute, database, network architectures, and data ingestion and transformation solutions.
- 04
Design Cost-Optimized Architectures
20% of the examCovers cost-optimized storage, compute, database, and network architectures.
Curriculum
Inside the AWS Certified Solutions Architect – Associate (SAA-C03) plan.
11 modules · 51 units · ~51h of structured prep.
- 01
Designing Secure Architectures: Identity and Access
4 units · ~4hMaster IAM policies, roles, federation, and resource-based access controls that underpin secure AWS architectures, the highest-weighted exam domain.
- 1. IAM Policies, Roles, and Permissions
- 2. Federation, Identity Center, and Amazon Cognito
- 3. Secrets Management and Key Rotation
- 4. Scenario Practice: Access Control Design
- 02
Designing Secure Architectures: Data and Network Protection
6 units · ~6hApply encryption, key management, and network-layer security controls (NACLs, security groups, WAF, Shield) to protect data at rest and in transit.
- 1. Encryption at Rest: KMS, SSE-S3, and SSE-C
- 2. Encryption in Transit and Certificate Management
- 3. S3 Access Control: Bucket Policies, Signed URLs, and CORS
- 4. Network Security: Security Groups, NACLs, and DDoS Protection
- 5. Sensitive Data Discovery with Amazon Macie
- 6. Scenario Practice: Secure Data and Network Design
- 03
Designing Resilient Architectures: High Availability Patterns
6 units · ~6hDesign fault-tolerant, highly available architectures using Multi-AZ deployments, Auto Scaling, load balancing, and DNS failover.
- 1. Multi-AZ Subnet and VPC Design for Resilience
- 2. EC2 Auto Scaling Groups and ALB Across AZs
- 3. Step Scaling Policies, Warm-Up, and Slow Start
- 4. RDS Multi-AZ, Aurora Multi-AZ, and Read Replicas
- 5. Route 53 Failover Routing and Disaster Recovery Strategies
- 6. Scenario Practice: High Availability and DR Design
- 04
Designing Resilient Architectures: Decoupling and Loose Coupling
4 units · ~4hBuild loosely coupled, scalable architectures using SQS, SNS, EventBridge, Step Functions, and serverless integration patterns.
- 1. Decoupling with Amazon SQS and SNS
- 2. Event-Driven Architecture with EventBridge and Step Functions
- 3. Serverless Compute Integration: Lambda and API Gateway
- 4. Scenario Practice: Decoupled and Fault-Tolerant Design
- 05
Designing High-Performing Architectures: Compute and Storage
5 units · ~5hSelect and optimize EC2 instance types, storage options, and caching layers for performance-sensitive workloads.
- 1. EC2 Instance Types, Placement Groups, and Lifecycle
- 2. EBS Volume Types and Performance (gp3, io2, st1, sc1)
- 3. Shared File Storage: Amazon EFS and FSx
- 4. Caching with ElastiCache and CloudFront
- 5. Scenario Practice: Performance-Optimized Compute and Storage
- 06
Designing High-Performing Architectures: Database and Network
5 units · ~5hSelect performant database services and design networking (VPC, load balancers, DirectConnect, Global Accelerator) for scale.
- 1. Database Selection: RDS vs Aurora vs DynamoDB vs Redshift
- 2. RDS Proxy and Connection Management
- 3. Load Balancer Selection: ALB vs NLB
- 4. VPC Networking for Performance: DirectConnect, Transit Gateway, Global Accelerator
- 5. Scenario Practice: Database and Network Performance Design
- 07
Designing Cost-Optimized Architectures
5 units · ~5hApply AWS pricing models, right-sizing, storage tiering, and FinOps best practices to design cost-efficient solutions.
- 1. EC2 Purchasing Options: On-Demand, Reserved, and Spot
- 2. Right-Sizing Compute and Capacity Planning
- 3. S3 Storage Classes and Lifecycle Policies
- 4. Cost-Effective Database and Migration Strategies
- 5. Scenario Practice: Cost-Optimization Trade-offs
- 08
AWS VPC Networking Fundamentals
4 units · ~4hDeepen core VPC networking skills including subnets, gateways, route tables, and DNS/DHCP configuration that underpin all four exam domains.
- 1. Public and Private Subnets, Route Tables, and Internet Gateways
- 2. NAT Gateways vs NAT Instances, and Elastic IPs
- 3. VPC Peering, Endpoints, and DHCP Option Sets
- 4. Scenario Practice: VPC Design Problems
Ready when you are
Start your AWS Certified Solutions Architect – Associate (SAA-C03) plan.
Start preparing for AWS Certified Solutions Architect – Associate (SAA-C03) for free today.