Exam prep

AWS Certified Solutions Architect – Associate (SAA-C03)

Helpful information and relevant policies for AWS Certification candidates regarding test day procedures, including check-in steps, ID requirements, testing rules, and exam functionality.

Start my AWS Certified Solutions Architect – Associate (SAA-C03) plan

Exam day

Know what AWS Certified Solutions Architect – Associate (SAA-C03) asks on the day.

65 questions
130 minutes
72% to pass
4 options per MCQ

Question formats to expect:

  • Single select (Radio)

    Select one option from a collection of options

  • Multiple select (Checkbox)

    Select all options that apply from a collection of options

Exam domains

What AWS Certified Solutions Architect – Associate (SAA-C03) covers.

Every exam domain — so practice maps to what the exam actually weights.

  1. 01

    Design Secure Architectures

    30% of the exam

    Covers designing secure access to AWS resources, secure workloads and applications, and appropriate data security controls.

  2. 02

    Design Resilient Architectures

    26% of the exam

    Covers designing scalable and loosely coupled architectures, and highly available and/or fault-tolerant architectures.

  3. 03

    Design High-Performing Architectures

    24% of the exam

    Covers high-performing storage, compute, database, network architectures, and data ingestion and transformation solutions.

  4. 04

    Design Cost-Optimized Architectures

    20% of the exam

    Covers cost-optimized storage, compute, database, and network architectures.

Curriculum

Inside the AWS Certified Solutions Architect – Associate (SAA-C03) plan.

11 modules · 51 units · ~51h of structured prep.

  1. 01

    Designing Secure Architectures: Identity and Access

    4 units · ~4h

    Master IAM policies, roles, federation, and resource-based access controls that underpin secure AWS architectures, the highest-weighted exam domain.

    1. 1. IAM Policies, Roles, and Permissions
    2. 2. Federation, Identity Center, and Amazon Cognito
    3. 3. Secrets Management and Key Rotation
    4. 4. Scenario Practice: Access Control Design
  2. 02

    Designing Secure Architectures: Data and Network Protection

    6 units · ~6h

    Apply encryption, key management, and network-layer security controls (NACLs, security groups, WAF, Shield) to protect data at rest and in transit.

    1. 1. Encryption at Rest: KMS, SSE-S3, and SSE-C
    2. 2. Encryption in Transit and Certificate Management
    3. 3. S3 Access Control: Bucket Policies, Signed URLs, and CORS
    4. 4. Network Security: Security Groups, NACLs, and DDoS Protection
    5. 5. Sensitive Data Discovery with Amazon Macie
    6. 6. Scenario Practice: Secure Data and Network Design
  3. 03

    Designing Resilient Architectures: High Availability Patterns

    6 units · ~6h

    Design fault-tolerant, highly available architectures using Multi-AZ deployments, Auto Scaling, load balancing, and DNS failover.

    1. 1. Multi-AZ Subnet and VPC Design for Resilience
    2. 2. EC2 Auto Scaling Groups and ALB Across AZs
    3. 3. Step Scaling Policies, Warm-Up, and Slow Start
    4. 4. RDS Multi-AZ, Aurora Multi-AZ, and Read Replicas
    5. 5. Route 53 Failover Routing and Disaster Recovery Strategies
    6. 6. Scenario Practice: High Availability and DR Design
  4. 04

    Designing Resilient Architectures: Decoupling and Loose Coupling

    4 units · ~4h

    Build loosely coupled, scalable architectures using SQS, SNS, EventBridge, Step Functions, and serverless integration patterns.

    1. 1. Decoupling with Amazon SQS and SNS
    2. 2. Event-Driven Architecture with EventBridge and Step Functions
    3. 3. Serverless Compute Integration: Lambda and API Gateway
    4. 4. Scenario Practice: Decoupled and Fault-Tolerant Design
  5. 05

    Designing High-Performing Architectures: Compute and Storage

    5 units · ~5h

    Select and optimize EC2 instance types, storage options, and caching layers for performance-sensitive workloads.

    1. 1. EC2 Instance Types, Placement Groups, and Lifecycle
    2. 2. EBS Volume Types and Performance (gp3, io2, st1, sc1)
    3. 3. Shared File Storage: Amazon EFS and FSx
    4. 4. Caching with ElastiCache and CloudFront
    5. 5. Scenario Practice: Performance-Optimized Compute and Storage
  6. 06

    Designing High-Performing Architectures: Database and Network

    5 units · ~5h

    Select performant database services and design networking (VPC, load balancers, DirectConnect, Global Accelerator) for scale.

    1. 1. Database Selection: RDS vs Aurora vs DynamoDB vs Redshift
    2. 2. RDS Proxy and Connection Management
    3. 3. Load Balancer Selection: ALB vs NLB
    4. 4. VPC Networking for Performance: DirectConnect, Transit Gateway, Global Accelerator
    5. 5. Scenario Practice: Database and Network Performance Design
  7. 07

    Designing Cost-Optimized Architectures

    5 units · ~5h

    Apply AWS pricing models, right-sizing, storage tiering, and FinOps best practices to design cost-efficient solutions.

    1. 1. EC2 Purchasing Options: On-Demand, Reserved, and Spot
    2. 2. Right-Sizing Compute and Capacity Planning
    3. 3. S3 Storage Classes and Lifecycle Policies
    4. 4. Cost-Effective Database and Migration Strategies
    5. 5. Scenario Practice: Cost-Optimization Trade-offs
  8. 08

    AWS VPC Networking Fundamentals

    4 units · ~4h

    Deepen core VPC networking skills including subnets, gateways, route tables, and DNS/DHCP configuration that underpin all four exam domains.

    1. 1. Public and Private Subnets, Route Tables, and Internet Gateways
    2. 2. NAT Gateways vs NAT Instances, and Elastic IPs
    3. 3. VPC Peering, Endpoints, and DHCP Option Sets
    4. 4. Scenario Practice: VPC Design Problems

Ready when you are

Start your AWS Certified Solutions Architect – Associate (SAA-C03) plan.

Start preparing for AWS Certified Solutions Architect – Associate (SAA-C03) for free today.