AWS Certified Solutions Architect Associate (SAA-C03) Fact Sheet¶
Exam Overview¶
Exam Code: SAA-C03 Exam Name: AWS Certified Solutions Architect - Associate Duration: 130 minutes Questions: 65 questions Question Format: Multiple choice and multiple response Passing Score: 720/1000 (scaled scoring, approximately 72%) Cost: $150 USD Valid For: 3 years Language: Available in English, Japanese, Korean, Simplified Chinese Delivery: Pearson VUE (online proctored or testing center)
π Official Exam Page - Registration and official details π Exam Guide PDF - Detailed exam objectives π Sample Questions - Official practice questions
Target Audience¶
This certification is designed for: - Solutions architects designing distributed systems on AWS - Cloud architects building scalable and cost-effective solutions - System administrators transitioning to cloud architecture - Developers wanting to understand AWS architecture best practices - IT professionals with 1+ years of hands-on AWS experience
π Certification Path - AWS certification journey π Training and Certification - Official AWS training
Exam Domains¶
Domain 1: Design Resilient Architectures (26%)¶
This domain covers designing systems that are fault-tolerant, highly available, and can recover from failures.
1.1 Design Multi-Tier Architectures¶
Key Concepts: - Multi-tier application design (web, application, database tiers) - Decoupling application components - Stateless vs stateful architectures - Microservices patterns
π Multi-Tier Architecture - Overview π Decoupling Applications - Microservices patterns π Application Load Balancer - Layer 7 load balancing π Auto Scaling Groups - Scaling compute resources
1.2 Design Highly Available and/or Fault-Tolerant Architectures¶
Multi-AZ Deployments: - Distributing resources across Availability Zones - RDS Multi-AZ for automatic failover - ELB distribution across multiple AZs - Multi-AZ NAT Gateways
π Regions and Availability Zones - AWS global infrastructure π Multi-AZ Deployments - RDS high availability π ELB Health Checks - Monitoring instance health π Route 53 Failover Routing - DNS-based failover
High Availability Patterns: - Active-Active vs Active-Passive - Health checks and automated recovery - Circuit breaker patterns - Graceful degradation
π High Availability - HA patterns on AWS π Elastic Load Balancing - Load balancer types π Auto Scaling - Automatic scaling
1.3 Design Decoupling Mechanisms¶
Services for Decoupling: - Amazon SQS (message queuing) - Amazon SNS (pub/sub messaging) - Amazon EventBridge (event bus) - AWS Step Functions (workflow orchestration)
π Amazon SQS - Message queuing service π SQS Queue Types - Standard vs FIFO queues π Amazon SNS - Pub/sub messaging π SNS Message Filtering - Subscription filters π Amazon EventBridge - Event-driven architecture π AWS Step Functions - Workflow orchestration
1.4 Choose Appropriate Resilient Storage¶
Storage Options: - Amazon S3 (object storage) - Amazon EBS (block storage) - Amazon EFS (shared file storage) - Amazon FSx (managed file systems)
π Amazon S3 - Object storage π S3 Storage Classes - Standard, IA, Glacier π S3 Replication - Cross-region and same-region π S3 Versioning - Object versioning π Amazon EBS - Block storage volumes π EBS Volume Types - gp3, io2, st1, sc1 π EBS Snapshots - Backup and recovery π Amazon EFS - Elastic file system π Amazon FSx - Managed file systems
Domain 2: Design High-Performing Architectures (24%)¶
This domain focuses on selecting performant storage, compute, networking, and database solutions.
2.1 Identify Elastic and Scalable Compute Solutions¶
Amazon EC2: - Instance types and families - Instance purchasing options - Placement groups - Enhanced networking
π Amazon EC2 - Elastic Compute Cloud π EC2 Instance Types - General, compute, memory, storage optimized π EC2 Pricing - On-Demand, Reserved, Spot π Spot Instances - Cost savings with Spot π Placement Groups - Cluster, partition, spread
Serverless Compute: - AWS Lambda (functions) - AWS Fargate (containers)
π AWS Lambda - Serverless functions π Lambda Pricing - Pay per request π Lambda Concurrency - Scaling behavior π AWS Fargate - Serverless containers
Container Services: - Amazon ECS (Elastic Container Service) - Amazon EKS (Elastic Kubernetes Service)
π Amazon ECS - Container orchestration π ECS Launch Types - EC2 vs Fargate π Amazon EKS - Kubernetes on AWS
2.2 Select High-Performing and Scalable Storage Solutions¶
Block Storage Performance: - EBS volume types (gp3, io2, io2 Block Express) - IOPS and throughput considerations - EBS-optimized instances
π EBS Performance - Volume performance π Provisioned IOPS - io2 volumes π EBS-Optimized Instances - Dedicated bandwidth
Object Storage Optimization: - S3 Transfer Acceleration - S3 Multipart Upload - CloudFront for content delivery
π S3 Transfer Acceleration - Faster uploads π S3 Multipart Upload - Large object uploads π Amazon CloudFront - Content delivery network
2.3 Select High-Performing Networking Solutions¶
VPC Networking: - VPC design and CIDR blocks - Subnets (public and private) - Route tables and routing - Internet Gateway and NAT Gateway - VPC Peering and Transit Gateway
π Amazon VPC - Virtual private cloud π VPC CIDR Blocks - IP addressing π Subnets - Subnet configuration π Route Tables - Routing configuration π Internet Gateway - Internet connectivity π NAT Gateway - Outbound internet for private subnets π VPC Peering - Connecting VPCs π AWS Transit Gateway - Network hub
Load Balancing: - Application Load Balancer (Layer 7) - Network Load Balancer (Layer 4) - Gateway Load Balancer
π Application Load Balancer - HTTP/HTTPS routing π ALB Target Groups - Routing targets π Network Load Balancer - TCP/UDP routing π NLB Static IP - Elastic IP addresses
Content Delivery: - Amazon CloudFront distributions - CloudFront origins (S3, ALB, custom) - Edge locations and caching
π CloudFront Distributions - Creating distributions π CloudFront Origins - Origin configuration π CloudFront Caching - Cache behavior
2.4 Choose High-Performing Database Solutions¶
Relational Databases: - Amazon RDS (managed relational databases) - Amazon Aurora (MySQL/PostgreSQL compatible) - Read replicas for scaling reads - Database engine options
π Amazon RDS - Relational Database Service π RDS DB Instances - Database instances π RDS Read Replicas - Read scaling π Amazon Aurora - High-performance database π Aurora Replicas - Read replicas
NoSQL Databases: - Amazon DynamoDB (key-value and document) - DynamoDB Global Tables - DynamoDB Accelerator (DAX)
π Amazon DynamoDB - NoSQL database π DynamoDB Tables - Table design π DynamoDB Indexes - GSI and LSI π DynamoDB Global Tables - Multi-region replication π DynamoDB DAX - In-memory caching
Caching Solutions: - Amazon ElastiCache (Redis and Memcached) - CloudFront caching - DAX for DynamoDB
π Amazon ElastiCache - In-memory caching π ElastiCache Redis - Redis features π ElastiCache Memcached - Memcached overview
Domain 3: Design Secure Applications and Architectures (30%)¶
This is the largest domain, covering IAM, data protection, and infrastructure security.
3.1 Design Secure Access to AWS Resources¶
Identity and Access Management (IAM): - IAM users, groups, and roles - IAM policies (identity-based and resource-based) - Policy evaluation logic - IAM best practices
π AWS IAM - Identity and Access Management π IAM Identities - Users, groups, roles π IAM Policies - Policy types π IAM Policy Evaluation - How policies are evaluated π IAM Roles - Temporary credentials π IAM Best Practices - Security recommendations
Cross-Account Access: - IAM roles for cross-account access - Resource-based policies - AWS Organizations
π Cross-Account Access - Account-to-account access π AWS Organizations - Multi-account management π Service Control Policies - Organization policies
Temporary Credentials: - AWS STS (Security Token Service) - AssumeRole operations - Federation
π AWS STS - Security Token Service π Assuming Roles - Using IAM roles π Identity Federation - External identity providers
3.2 Design Secure Application Tiers¶
Network Security: - Security Groups (stateful firewalls) - Network ACLs (stateless firewalls) - AWS Network Firewall - AWS WAF (Web Application Firewall)
π Security Groups - Instance-level firewalls π Network ACLs - Subnet-level firewalls π Security Group vs NACL - Comparison π AWS WAF - Web application firewall π AWS Network Firewall - Managed firewall
Application Security: - AWS Secrets Manager - AWS Systems Manager Parameter Store - Amazon Cognito for authentication
π AWS Secrets Manager - Secret storage and rotation π Parameter Store - Configuration and secrets π Amazon Cognito - User authentication
3.3 Select Appropriate Data Security Options¶
Encryption at Rest: - S3 encryption (SSE-S3, SSE-KMS, SSE-C) - EBS encryption - RDS encryption - DynamoDB encryption
π S3 Encryption - Object encryption π S3 Default Encryption - Bucket-level encryption π EBS Encryption - Volume encryption π RDS Encryption - Database encryption π DynamoDB Encryption - Table encryption
Key Management: - AWS KMS (Key Management Service) - Customer managed keys vs AWS managed keys - Key policies and grants
π AWS KMS - Key Management Service π KMS Keys - Key concepts π KMS Key Policies - Access control π KMS Grants - Temporary permissions
Encryption in Transit: - TLS/SSL certificates - AWS Certificate Manager (ACM) - VPN connections
π AWS Certificate Manager - SSL/TLS certificates π ACM with CloudFront - HTTPS configuration π VPN Connections - Site-to-Site VPN
Domain 4: Design Cost-Optimized Architectures (20%)¶
This domain focuses on selecting cost-effective resources and architectures.
4.1 Identify Cost-Effective Storage Solutions¶
S3 Storage Classes: - S3 Standard vs S3-IA vs S3 Glacier - S3 Intelligent-Tiering - S3 Lifecycle policies
π S3 Storage Classes - Cost comparison π S3 Intelligent-Tiering - Automatic optimization π S3 Lifecycle - Automated transitions
EBS Cost Optimization: - Right-sizing volumes - gp3 vs gp2 cost savings - Snapshot lifecycle policies
π EBS Pricing - Volume pricing π EBS Snapshots Pricing - Snapshot costs π Data Lifecycle Manager - Automated snapshots
4.2 Identify Cost-Effective Compute and Database Services¶
EC2 Cost Optimization: - Reserved Instances vs Savings Plans - Spot Instances for fault-tolerant workloads - Right-sizing instances - Auto Scaling for dynamic workloads
π EC2 Pricing Options - Pricing comparison π Reserved Instances - 1-3 year commitments π Savings Plans - Flexible pricing π Spot Instances - Up to 90% savings
Serverless Cost Benefits: - Lambda pricing (pay per request) - Fargate pricing (pay per vCPU/memory) - API Gateway pricing
π Lambda Pricing - Request and duration pricing π Fargate Pricing - vCPU and memory pricing
Database Cost Optimization: - RDS Reserved Instances - Aurora Serverless for variable workloads - DynamoDB On-Demand vs Provisioned
π RDS Pricing - Database pricing π Aurora Serverless - Auto-scaling database π DynamoDB Pricing - On-Demand vs Provisioned
4.3 Design Cost-Optimized Network Architectures¶
Data Transfer Costs: - Understanding data transfer pricing - VPC Endpoints to avoid NAT Gateway costs - CloudFront for reducing origin load - S3 Transfer Acceleration costs
π Data Transfer Pricing - Understanding costs π VPC Endpoints - Private connections to AWS services π Gateway Endpoints - Free S3/DynamoDB access π Interface Endpoints - PrivateLink connections
Key AWS Services to Master¶
Compute¶
- EC2: Virtual servers, instance types, pricing options
- Lambda: Serverless functions, triggers, pricing
- ECS/EKS: Container orchestration
- Elastic Beanstalk: PaaS for web applications
π AWS Compute Services - Compute overview π Elastic Beanstalk - Platform as a Service
Storage¶
- S3: Object storage, storage classes, lifecycle
- EBS: Block storage, volume types, snapshots
- EFS: Shared file storage
- Storage Gateway: Hybrid cloud storage
π AWS Storage Services - Storage overview π Storage Gateway - Hybrid storage
Database¶
- RDS: Managed relational databases
- Aurora: High-performance database
- DynamoDB: NoSQL database
- ElastiCache: In-memory caching
- Redshift: Data warehousing
π AWS Database Services - Database overview π Amazon Redshift - Data warehouse
Networking¶
- VPC: Virtual private cloud, subnets, routing
- Route 53: DNS service
- CloudFront: Content delivery network
- Direct Connect: Dedicated network connection
- ELB: Load balancing (ALB, NLB, GLB)
π Route 53 - DNS service π Route 53 Routing Policies - Traffic routing π AWS Direct Connect - Dedicated connections
Security & Identity¶
- IAM: Users, groups, roles, policies
- KMS: Encryption key management
- Secrets Manager: Secret storage and rotation
- WAF: Web application firewall
- Shield: DDoS protection
π AWS Shield - DDoS protection π AWS GuardDuty - Threat detection
Management & Monitoring¶
- CloudWatch: Monitoring and logging
- CloudTrail: API logging and auditing
- AWS Config: Resource inventory and compliance
- Systems Manager: Operational management
- Trusted Advisor: Best practice recommendations
π Amazon CloudWatch - Monitoring service π CloudWatch Alarms - Alerting π AWS CloudTrail - Audit logging π AWS Config - Configuration tracking π AWS Trusted Advisor - Best practice checks
Required Reading¶
AWS Whitepapers (Essential)¶
π AWS Well-Architected Framework - Core framework (MUST READ) π Operational Excellence Pillar - Operations best practices π Security Pillar - Security best practices π Reliability Pillar - Resilience best practices π Performance Efficiency Pillar - Performance optimization π Cost Optimization Pillar - Cost management
FAQs (Highly Recommended)¶
π EC2 FAQ - EC2 common questions π S3 FAQ - S3 common questions π VPC FAQ - VPC common questions π RDS FAQ - RDS common questions π Lambda FAQ - Lambda common questions
Study Strategy¶
Recommended Timeline (6-8 weeks, 10-15 hours/week)¶
Weeks 1-2: IAM, EC2, and VPC Fundamentals - Complete AWS Skill Builder or training course modules - Build hands-on labs for EC2 and VPC - Practice IAM policy creation - Study time: 12-15 hours/week
Weeks 3-4: Storage and Databases - Deep dive into S3, EBS, EFS - Study RDS, DynamoDB, ElastiCache - Build multi-tier application with database - Study time: 12-15 hours/week
Weeks 5-6: Advanced Topics - Load balancing and auto-scaling - CloudFront, Route 53 - Serverless architectures (Lambda, API Gateway) - Study time: 10-12 hours/week
Weeks 7-8: Review and Practice Tests - Take practice exams (aim for 75-80% score) - Review weak areas - Read Well-Architected Framework - Study time: 10-15 hours/week
Study Resources¶
Official AWS Training: π AWS Skill Builder - Free AWS training π Exam Prep: Solutions Architect Associate - Official exam prep course
Popular Courses: - Stephane Maarek's AWS SAA course (Udemy) - Comprehensive - Adrian Cantrill's SAA course - Deep technical - A Cloud Guru SAA path - Good for beginners
Practice Tests: - Tutorials Dojo (Jon Bonso) - Highly recommended - Whizlabs practice tests - Official AWS practice exam
Exam Day Tips¶
Preparation¶
- Arrive 15 minutes early (testing center) or start setup 30 minutes early (online)
- Bring two forms of ID
- Review flagged topics from practice tests
- Get good sleep the night before
During Exam¶
- Read questions carefully - look for keywords like "MOST cost-effective", "LEAST operational overhead"
- Eliminate wrong answers first
- Flag uncertain questions for review
- Manage time: ~2 minutes per question
- Don't overthink - trust your preparation
Common Question Patterns¶
- Scenario-based architecture questions
- Choosing between similar services (RDS vs DynamoDB, S3 vs EBS)
- Cost optimization scenarios
- High availability and disaster recovery
- Security best practices
Technical Setup (Online Proctoring)¶
- Stable internet connection (minimum 1 Mbps upload/download)
- Webcam and microphone required
- Clear desk workspace
- Close all other applications
- Government-issued photo ID ready
π Exam Day Checklist - Preparation tips
After Certification¶
Career Benefits¶
- Average 15-20% salary increase
- Opens doors to cloud architect roles
- Foundation for professional-level certifications
- Industry recognition
Next Certifications¶
π AWS Certified Solutions Architect - Professional - Advanced architecture π AWS Certified Developer - Associate - Development focus π AWS Certified SysOps Administrator - Associate - Operations focus
Maintaining Certification¶
- Certification valid for 3 years
- Recertification required
- Continuing education through AWS training
- Stay updated with new services and features
π Recertification - Renewal process π AWS Training - Continuous learning
Quick Reference¶
Exam Details at a Glance¶
- 65 questions in 130 minutes = 2 minutes per question
- 720/1000 to pass = Approximately 72%
- 26% resilient architectures = ~17 questions
- 24% high-performing = ~16 questions
- 30% secure = ~20 questions
- 20% cost-optimized = ~13 questions
Key Concepts by Domain¶
| Domain | Must-Know Topics |
|---|---|
| Resilient | Multi-AZ, Auto Scaling, ELB, S3 replication, RDS Multi-AZ |
| High-Performing | Instance types, caching, CloudFront, read replicas |
| Secure | IAM policies, security groups, encryption (KMS), VPC design |
| Cost-Optimized | Reserved Instances, Spot, S3 classes, right-sizing |
Good luck with your AWS Solutions Architect Associate certification! π