SAA-C03
AWS Certified Solutions Architect - Associate (SAA-C03)
Outline from the official exam guide (opens in a new tab), as of 2026-09-26.
Study the official path too
AWS publishes its own prep for this exam. Use it alongside Checksum.
- AWS Skill Builder exam prep plan for SAA-C03 (opens in a new tab)
- AWS Certification Official Practice Question Set (opens in a new tab): “These 20-question sets, developed by AWS, demonstrate the style of our certification exams.”
- AWS Certification Official Practice Exam (opens in a new tab) (needs a Skill Builder subscription)
In preparation. Lessons and questions appear once approved.
Outline
Word for word from the official exam guide.
Domain 1 · Weight 30%Not started0%
Design Secure Architectures
Task 1.1Not started
Design secure access to AWS resources
Lessons appear once approved.
Skills measured (11)
Knowledge of
- 1.1.K1Access controls and management across multiple accounts
- 1.1.K2AWS federated access and identity services (for example, IAM, AWS IAM Identity Center)
- 1.1.K3AWS global infrastructure (for example, Availability Zones, AWS Regions)
- 1.1.K4AWS security best practices (for example, the principle of least privilege)
- 1.1.K5The AWS shared responsibility model
Skills in
- 1.1.S1Applying AWS security best practices to IAM users and root users (for example, multi-factor authentication [MFA])
- 1.1.S2Designing a flexible authorization model that includes IAM users, groups, roles, and policies
- 1.1.S3Designing a role-based access control strategy (for example, AWS STS, role switching, cross-account access)
- 1.1.S4Designing a security strategy for multiple AWS accounts (for example, AWS Control Tower, service control policies [SCPs])
- 1.1.S5Determining the appropriate use of resource policies for AWS services
- 1.1.S6Determining when to federate a directory service with IAM roles
Task 1.2Not started
Design secure workloads and applications
Lessons appear once approved.
Skills measured (10)
Knowledge of
- 1.2.K1Application configuration and credentials security
- 1.2.K2AWS service endpoints
- 1.2.K3Control ports, protocols, and network traffic on AWS
- 1.2.K4Secure application access
- 1.2.K5Security services with appropriate use cases (for example, Amazon Cognito, Amazon GuardDuty, Amazon Macie)
- 1.2.K6Threat vectors external to AWS (for example, DDoS, SQL injection)
Skills in
- 1.2.S1Designing VPC architectures with security components (for example, security groups, route tables, network ACLs, NAT gateways)
- 1.2.S2Determining network segmentation strategies (for example, using public subnets and private subnets)
- 1.2.S3Integrating AWS services to secure applications (for example, AWS Shield, AWS WAF, IAM Identity Center, AWS Secrets Manager)
- 1.2.S4Securing external network connections to and from the AWS Cloud (for example, VPN, AWS Direct Connect)
Task 1.3Not started
Determine appropriate data security controls
Lessons appear once approved.
Skills measured (11)
Knowledge of
- 1.3.K1Data access and governance
- 1.3.K2Data recovery
- 1.3.K3Data retention and classification
- 1.3.K4Encryption and appropriate key management
Skills in
- 1.3.S1Aligning AWS technologies to meet compliance requirements
- 1.3.S2Encrypting data at rest (for example, AWS KMS)
- 1.3.S3Encrypting data in transit (for example, AWS Certificate Manager [ACM] using TLS)
- 1.3.S4Implementing access policies for encryption keys
- 1.3.S5Implementing data backups and replications
- 1.3.S6Implementing policies for data access, lifecycle, and protection
- 1.3.S7Rotating encryption keys and renewing certificates
Domain 2 · Weight 26%Not started0%
Design Resilient Architectures
Task 2.1Not started
Design scalable and loosely coupled architectures
Lessons appear once approved.
Skills measured (23)
Knowledge of
- 2.1.K1API creation and management (for example, Amazon API Gateway, REST API)
- 2.1.K2AWS managed services with appropriate use cases (for example, AWS Transfer Family, Amazon SQS, AWS Secrets Manager)
- 2.1.K3Caching strategies
- 2.1.K4Design principles for microservices (for example, stateless workloads compared with stateful workloads)
- 2.1.K5Event-driven architectures
- 2.1.K6Horizontal scaling and vertical scaling
- 2.1.K7How to appropriately use edge accelerators (for example, content delivery network [CDN])
- 2.1.K8How to migrate applications into containers
- 2.1.K9Load balancing concepts (for example, Application Load Balancer [ALB])
- 2.1.K10Multi-tier architectures
- 2.1.K11Queuing and messaging concepts (for example, publish/subscribe)
- 2.1.K12Serverless technologies and patterns (for example, AWS Fargate, AWS Lambda)
- 2.1.K13Storage types with associated characteristics (for example, object, file, block)
- 2.1.K14The orchestration of containers (for example, Amazon ECS, Amazon EKS)
- 2.1.K15When to use read replicas
- 2.1.K16Workflow orchestration (for example, AWS Step Functions)
Skills in
- 2.1.S1Designing event-driven, microservice, and/or multi-tier architectures based on requirements
- 2.1.S2Determining scaling strategies for components used in an architecture design
- 2.1.S3Determining the AWS services required to achieve loose coupling based on requirements
- 2.1.S4Determining when to use containers
- 2.1.S5Determining when to use serverless technologies and patterns
- 2.1.S6Recommending appropriate compute, storage, networking, and database technologies based on requirements
- 2.1.S7Using purpose-built AWS services for workloads
Task 2.2Not started
Design highly available and/or fault-tolerant architectures
Lessons appear once approved.
Skills measured (20)
Knowledge of
- 2.2.K1AWS global infrastructure (for example, Availability Zones, AWS Regions, Amazon Route 53)
- 2.2.K2AWS Managed Services (AMS) with appropriate use cases (for example, Amazon Comprehend, Amazon Polly)
- 2.2.K3Basic networking concepts (for example, route tables)
- 2.2.K4Disaster recovery (DR) strategies (for example, backup and restore, pilot light, warm standby, active-active failover, recovery point objective [RPO], recovery time objective [RTO])
- 2.2.K5Distributed design patterns
- 2.2.K6Failover strategies
- 2.2.K7Immutable infrastructure
- 2.2.K8Load balancing concepts (for example, ALB)
- 2.2.K9Proxy concepts (for example, Amazon RDS Proxy)
- 2.2.K10Service quotas and throttling (for example, how to configure the service quotas for a workload in a standby environment)
- 2.2.K11Storage options and characteristics (for example, durability, replication)
- 2.2.K12Workload visibility (for example, AWS X-Ray)
Skills in
- 2.2.S1Determining automation strategies to ensure infrastructure integrity
- 2.2.S2Determining the AWS services required to provide a highly available and/or fault-tolerant architecture across AWS Regions or Availability Zones
- 2.2.S3Identifying metrics based on business requirements to deliver a highly available solution
- 2.2.S4Implementing designs to mitigate single points of failure
- 2.2.S5Implementing strategies to ensure the durability and availability of data (for example, backups)
- 2.2.S6Selecting an appropriate DR strategy to meet business requirements
- 2.2.S7Using AWS services that improve the reliability of legacy applications and applications not built for the cloud (for example, when application changes are not possible)
- 2.2.S8Using purpose-built AWS services for workloads
Domain 3 · Weight 24%Not started0%
Design High-Performing Architectures
Task 3.1Not started
Determine high-performing and/or scalable storage solutions
Lessons appear once approved.
Skills measured (5)
Knowledge of
- 3.1.K1Hybrid storage solutions to meet business requirements
- 3.1.K2Storage services with appropriate use cases (for example, Amazon S3, Amazon EFS, Amazon EBS)
- 3.1.K3Storage types with associated characteristics (for example, object, file, block)
Skills in
- 3.1.S1Determining storage services and configurations that meet performance demands
- 3.1.S2Determining storage services that can scale to accommodate future needs
Task 3.2Not started
Design high-performing and elastic compute solutions
Lessons appear once approved.
Skills measured (10)
Knowledge of
- 3.2.K1AWS compute services with appropriate use cases (for example, AWS Batch, Amazon EMR, AWS Fargate)
- 3.2.K2Distributed computing concepts supported by AWS global infrastructure and edge services
- 3.2.K3Queuing and messaging concepts (for example, publish/subscribe)
- 3.2.K4Scalability capabilities with appropriate use cases (for example, Amazon EC2 Auto Scaling, AWS Auto Scaling)
- 3.2.K5Serverless technologies and patterns (for example, AWS Lambda, Fargate)
- 3.2.K6The orchestration of containers (for example, Amazon ECS, Amazon EKS)
Skills in
- 3.2.S1Decoupling workloads so that components can scale independently
- 3.2.S2Identifying metrics and conditions to perform scaling actions
- 3.2.S3Selecting the appropriate compute options and features (for example, EC2 instance types) to meet business requirements
- 3.2.S4Selecting the appropriate resource type and size (for example, the amount of Lambda memory) to meet business requirements
Task 3.3Not started
Determine high-performing database solutions
Lessons appear once approved.
Skills measured (13)
Knowledge of
- 3.3.K1AWS global infrastructure (for example, Availability Zones, AWS Regions)
- 3.3.K2Caching strategies and services (for example, Amazon ElastiCache)
- 3.3.K3Data access patterns (for example, read-intensive compared with write-intensive)
- 3.3.K4Database capacity planning (for example, capacity units, instance types, Provisioned IOPS)
- 3.3.K5Database connections and proxies
- 3.3.K6Database engines with appropriate use cases (for example, heterogeneous migrations, homogeneous migrations)
- 3.3.K7Database replication (for example, read replicas)
- 3.3.K8Database types and services (for example, serverless, relational compared with non-relational, in-memory)
Skills in
- 3.3.S1Configuring read replicas to meet business requirements
- 3.3.S2Designing database architectures
- 3.3.S3Determining an appropriate database engine (for example, MySQL compared with PostgreSQL)
- 3.3.S4Determining an appropriate database type (for example, Amazon Aurora, Amazon DynamoDB)
- 3.3.S5Integrating caching to meet business requirements
Task 3.4Not started
Determine high-performing and/or scalable network architectures
Lessons appear once approved.
Skills measured (8)
Knowledge of
- 3.4.K1Edge networking services with appropriate use cases (for example, Amazon CloudFront, AWS Global Accelerator)
- 3.4.K2How to design network architecture (for example, subnet tiers, routing, IP addressing)
- 3.4.K3Load balancing concepts (for example, Application Load Balancer [ALB])
- 3.4.K4Network connection options (for example, AWS VPN, AWS Direct Connect, AWS PrivateLink)
Skills in
- 3.4.S1Creating a network topology for various architectures (for example, global, hybrid, multi-tier)
- 3.4.S2Determining network configurations that can scale to accommodate future needs
- 3.4.S3Determining the appropriate placement of resources to meet business requirements
- 3.4.S4Selecting the appropriate load balancing strategy
Task 3.5Not started
Determine high-performing data ingestion and transformation solutions
Lessons appear once approved.
Skills measured (14)
Knowledge of
- 3.5.K1Data analytics and visualization services with appropriate use cases (for example, Amazon Athena, AWS Lake Formation, Amazon Quick)
- 3.5.K2Data ingestion patterns (for example, frequency)
- 3.5.K3Data transfer services with appropriate use cases (for example, AWS DataSync, AWS Storage Gateway)
- 3.5.K4Data transformation services with appropriate use cases (for example, AWS Glue)
- 3.5.K5Secure access to ingestion access points
- 3.5.K6Sizes and speeds needed to meet business requirements
- 3.5.K7Streaming data services with appropriate use cases (for example, Amazon Kinesis)
Skills in
- 3.5.S1Building and securing data lakes
- 3.5.S2Designing data streaming architectures
- 3.5.S3Designing data transfer solutions
- 3.5.S4Implementing visualization strategies
- 3.5.S5Selecting appropriate compute options for data processing (for example, Amazon EMR)
- 3.5.S6Selecting appropriate configurations for ingestion
- 3.5.S7Transforming data between formats (for example, .csv to .parquet)
Domain 4 · Weight 20%Not started0%
Design Cost-Optimized Architectures
Task 4.1Not started
Design cost-optimized storage solutions
Lessons appear once approved.
Skills measured (21)
Knowledge of
- 4.1.K1Access options (for example, an S3 bucket with Requester Pays object storage)
- 4.1.K2AWS cost management service features (for example, cost allocation tags, multi-account billing)
- 4.1.K3AWS cost management tools with appropriate use cases (for example, AWS Cost Explorer, AWS Budgets, AWS Cost and Usage Report)
- 4.1.K4AWS storage services with appropriate use cases (for example, Amazon FSx, Amazon EFS, Amazon S3, Amazon EBS)
- 4.1.K5Backup strategies
- 4.1.K6Block storage options (for example, hard disk drive [HDD] volume types, solid state drive [SSD] volume types)
- 4.1.K7Data lifecycles
- 4.1.K8Hybrid storage options (for example, AWS DataSync, AWS Transfer Family, AWS Storage Gateway)
- 4.1.K9Storage access patterns
- 4.1.K10Storage tiering (for example, cold tiering for object storage)
- 4.1.K11Storage types with associated characteristics (for example, object, file, block)
Skills in
- 4.1.S1Designing appropriate storage strategies (for example, batch uploads to Amazon S3 compared with individual uploads)
- 4.1.S2Determining the correct storage size for a workload
- 4.1.S3Determining the lowest cost method of transferring data for a workload to AWS storage
- 4.1.S4Determining when storage auto scaling is required
- 4.1.S5Managing S3 object lifecycles
- 4.1.S6Selecting the appropriate backup and/or archival solution
- 4.1.S7Selecting the appropriate service for data migration to storage services
- 4.1.S8Selecting the appropriate storage tier
- 4.1.S9Selecting the correct data lifecycle for storage
- 4.1.S10Selecting the most cost-effective storage service for a workload
Task 4.2Not started
Design cost-optimized compute solutions
Lessons appear once approved.
Skills measured (15)
Knowledge of
- 4.2.K1AWS cost management service features (for example, cost allocation tags, multi-account billing)
- 4.2.K2AWS cost management tools with appropriate use cases (for example, AWS Cost Explorer, AWS Budgets, AWS Cost and Usage Report)
- 4.2.K3AWS global infrastructure (for example, Availability Zones, AWS Regions)
- 4.2.K4AWS purchasing options (for example, Spot Instances, Reserved Instances, Savings Plans)
- 4.2.K5Distributed compute strategies (for example, edge processing)
- 4.2.K6Hybrid compute options (for example, AWS Outposts)
- 4.2.K7Instance types, families, and sizes (for example, memory optimized, compute optimized, virtualization)
- 4.2.K8Optimization of compute utilization (for example, containers, serverless computing, microservices)
- 4.2.K9Scaling strategies (for example, auto scaling, hibernation)
Skills in
- 4.2.S1Determining an appropriate load balancing strategy (for example, Application Load Balancer [Layer 7] compared with Network Load Balancer [Layer 4] compared with Gateway Load Balancer)
- 4.2.S2Determining appropriate scaling methods and strategies for elastic workloads (for example, horizontal compared with vertical, EC2 hibernation)
- 4.2.S3Determining cost-effective AWS compute services with appropriate use cases (for example, AWS Lambda, Amazon EC2, AWS Fargate)
- 4.2.S4Determining the required availability for different classes of workloads (for example, production workloads, non-production workloads)
- 4.2.S5Selecting the appropriate instance family for a workload
- 4.2.S6Selecting the appropriate instance size for a workload
Task 4.3Not started
Design cost-optimized database solutions
Lessons appear once approved.
Skills measured (14)
Knowledge of
- 4.3.K1AWS cost management service features (for example, cost allocation tags, multi-account billing)
- 4.3.K2AWS cost management tools with appropriate use cases (for example, AWS Cost Explorer, AWS Budgets, AWS Cost and Usage Report)
- 4.3.K3Caching strategies
- 4.3.K4Data retention policies
- 4.3.K5Database capacity planning (for example, capacity units)
- 4.3.K6Database connections and proxies
- 4.3.K7Database engines with appropriate use cases (for example, heterogeneous migrations, homogeneous migrations)
- 4.3.K8Database replication (for example, read replicas)
- 4.3.K9Database types and services (for example, relational compared with non-relational, Amazon Aurora, Amazon DynamoDB)
Skills in
- 4.3.S1Designing appropriate backup and retention policies (for example, snapshot frequency)
- 4.3.S2Determining an appropriate database engine (for example, MySQL compared with PostgreSQL)
- 4.3.S3Determining cost-effective AWS database services with appropriate use cases (for example, DynamoDB compared with Amazon RDS, serverless)
- 4.3.S4Determining cost-effective AWS database types (for example, time series format, columnar format)
- 4.3.S5Migrating database schemas and data to different locations and/or different database engines
Task 4.4Not started
Design cost-optimized network architectures
Lessons appear once approved.
Skills measured (14)
Knowledge of
- 4.4.K1AWS cost management service features (for example, cost allocation tags, multi-account billing)
- 4.4.K2AWS cost management tools with appropriate use cases (for example, AWS Cost Explorer, AWS Budgets, AWS Cost and Usage Report)
- 4.4.K3Load balancing concepts (for example, Application Load Balancer [ALB])
- 4.4.K4NAT gateways (for example, NAT instance costs compared with NAT gateway costs)
- 4.4.K5Network connectivity (for example, private lines, dedicated lines, VPNs)
- 4.4.K6Network routing, topology, and peering (for example, AWS Transit Gateway, VPC peering)
- 4.4.K7Network services with appropriate use cases (for example, DNS)
Skills in
- 4.4.S1Configuring appropriate NAT gateway types for a network (for example, a single shared NAT gateway compared with NAT gateways for each Availability Zone)
- 4.4.S2Configuring appropriate network connections (for example, AWS Direct Connect compared with VPN compared with internet)
- 4.4.S3Configuring appropriate network routes to minimize network transfer costs (for example, Region to Region, Availability Zone to Availability Zone, private to public, AWS Global Accelerator, VPC endpoints)
- 4.4.S4Determining strategic needs for content delivery networks (CDNs) and edge caching
- 4.4.S5Reviewing existing workloads for network optimizations
- 4.4.S6Selecting an appropriate throttling strategy
- 4.4.S7Selecting the appropriate bandwidth allocation for a network device (for example, a single VPN compared with multiple VPNs, Direct Connect speed)
About the exam
From the vendor’s own pages.
Results are a scaled score from 100 to 1,000, and the minimum passing score is 720.
The exam has 65 questions, either multiple choice or multiple response.
50 of the questions affect your score.
The exam lasts 130 minutes.
Unanswered questions count as incorrect, and there is no penalty for guessing.