⭐ Trusted by 700+ Buyers  ·  4.7★ Star Seller on Etsy  ·  $9.99/exam  ·  Grab it now →
Home › AWS › SAA-C03 study guide

AWS Certified Solutions Architect – Associate (SAA-C03) Practice Test & Study Guide

Everything you need to plan your SAA-C03 prep: the exam format, what each domain covers, a week-by-week study plan, original practice questions, and what thousands of study-group comments reveal about where candidates slip up.

Last updated · By the NotJustExam team

About the AWS Certified Solutions Architect – Associate (SAA-C03) exam

The AWS Certified Solutions Architect – Associate (SAA-C03) validates the ability to design and deploy well-architected solutions on AWS. It is not a service-trivia exam; it is built around scenario-based questions where you pick the best architecture for a given set of requirements, trade-offs, and constraints, which is why it is widely treated as a benchmark associate-level cloud credential.

It is aimed at people who already have hands-on experience designing systems on AWS — often one or more years working with a broad set of AWS services — including solutions architects, cloud engineers, and developers moving into architecture-focused roles. AWS does not enforce prerequisites, but the exam assumes practical familiarity with core services rather than textbook definitions.

SAA-C03 matters because it remains one of the most recognized cloud certifications in hiring pipelines, regardless of company size. It signals that you can reason about security, resilience, performance, and cost trade-offs across a real AWS architecture, not just recite service names.

AWS Certified Solutions Architect – Associate (SAA-C03) exam format at a glance

AttributeDetail (as of 2026, verify on the official page)
Exam codeSAA-C03
Number of questions65 (50 scored, 15 unscored and not identified to the candidate)
Question typesMultiple choice and multiple response
Duration130 minutes
Passing score720 on a scaled range of 100–1000
Cost150 USD; visit AWS's exam pricing page for regional and exchange-rate details
LanguagesEnglish, French, Italian, Japanese, Korean, Portuguese (Brazil), Spanish (Latin America), and other languages by region
DeliveryPearson VUE testing center or online proctored exam
Validity3 years from the date you pass

AWS Certified Solutions Architect – Associate (SAA-C03) domains & what they cover

The objectives are organized into four domains. The weightings below reflect the official AWS exam guide; confirm current figures on the official page.

  • Domain 1: Design Secure Architectures (about 30%) — The largest domain: IAM policies and roles, federated access, the shared responsibility model, and secure access patterns for application and data tiers, plus encryption at rest and in transit.
  • Domain 2: Design Resilient Architectures (about 26%) — Building scalable, loosely coupled architectures with queues and event-driven patterns, and designing for high availability and fault tolerance across AZs and regions, including backup and disaster-recovery strategies.
  • Domain 3: Design High-Performing Architectures (about 24%) — Choosing storage, compute, database, and networking solutions that match a workload's access patterns and performance needs, plus data ingestion and transformation pipelines.
  • Domain 4: Design Cost-Optimized Architectures (about 20%) — Selecting cost-effective storage, compute, database, and network options, and recognizing when a cheaper AWS service or pricing model meets the same requirements.

How hard is AWS Certified Solutions Architect – Associate (SAA-C03)?

SAA-C03 is considered a meaningful step up from the entry-level AWS Cloud Practitioner exam. The difficulty comes from breadth combined with scenario framing: most questions describe a business situation with several plausible-sounding answers, and you have to identify which option satisfies every stated constraint, not just the first "correct-looking" service.

The most common sticking points are questions that combine multiple domains at once — for example, a resilience requirement that also has a cost constraint — and storage/database selection questions, where several AWS services can technically work but only one fits the stated access pattern and cost profile best. Candidates who have only used a narrow slice of AWS services in their job often struggle with the exam's breadth.

For someone with hands-on AWS experience, a realistic prep window is six to eight weeks of steady study. Candidates newer to AWS, or coming primarily from a different cloud provider, should plan for ten to twelve weeks and prioritize hands-on labs over reading alone.

How to prepare for AWS Certified Solutions Architect – Associate (SAA-C03): a study plan

A phased plan that mixes conceptual coverage with hands-on labs tends to outperform pure reading, since the exam tests applied judgment.

  1. Weeks 1–3: Build the service map. Work through all four domains once, focusing on core compute, storage, database, and networking services and how they fit together. Prioritize breadth over depth on this pass.
  2. Weeks 4–6: Go hands-on with the heavy domains. Spend real lab time on IAM policies, VPC design, and resilience patterns (multi-AZ, auto scaling, failover), since Design Secure Architectures and Design Resilient Architectures together make up more than half the exam.
  3. Weeks 7–8: Drill with scenario-based practice questions. Work timed sets that mirror the exam's scenario style, and for every question you miss, identify which specific constraint you overlooked rather than just noting the correct service.
  4. Final week: Simulate and review weak spots. Take full-length timed practice runs, review your error log, and revisit whichever domain still produces avoidable mistakes.

Use practice questions to train scenario analysis — spotting the one constraint that eliminates three of the four answer choices — rather than to memorize specific service facts.

AWS Certified Solutions Architect – Associate (SAA-C03) FAQ

How much does the SAA-C03 exam cost?

The exam costs 150 USD as of 2026. Pricing can vary by country due to exchange rates and local taxes, so check AWS's official exam pricing page for your region before registering.

How long is the certification valid?

The certification is valid for 3 years from the date you pass. Before it expires, you can recertify by passing the current version of the exam again, or by earning a qualifying higher-level certification such as AWS Certified Solutions Architect – Professional.

Are there prerequisites?

There are no mandatory prerequisites, so anyone can register directly. AWS recommends at least one year of hands-on experience designing and deploying systems on AWS, which strongly affects how approachable the scenario questions feel.

What is the retake policy if I fail?

You must wait 14 days after a failed attempt before retaking the exam, and you pay the exam fee again each time unless you have a retake benefit from a bundle or exam voucher. Additional retakes follow the same 14-day rule.

Is the exam taken online or at a test center?

Both options exist through Pearson VUE. You can take SAA-C03 at a physical testing center or online with remote proctoring, which requires a private room, a working webcam, and a system check before the exam starts.

Is the Solutions Architect Associate certification worth it?

For most cloud, infrastructure, and architecture-track roles, yes. It is one of the most recognized AWS credentials among employers, and the scenario-based preparation tends to build architecture judgment that transfers directly to real design decisions, not just resume value.

Free SAA-C03 practice questions

5 original questions written for NotJustExam from the public SAA-C03 exam objectives and independently answer-checked. Try answering before you open the explanation.

Question 1

An application running on an EC2 instance needs to write objects to an S3 bucket. The security team wants to avoid storing long-term AWS access keys anywhere on the instance. Which approach best meets this requirement?

  1. Store an IAM user's access key and secret key in the instance's environment variables
  2. Attach an IAM role to the EC2 instance and grant the role S3 write permissions
  3. Embed the access key and secret key directly in the application code
  4. Create an IAM user, generate long-term keys, and store them in a configuration file on the instance
Show answer & explanation

Answer: B. An IAM role attached to an EC2 instance provides temporary credentials automatically through the instance metadata service, so the application never needs to store or manage long-term access keys at all. Storing an IAM user's keys in environment variables (A) still involves long-term credentials residing on the instance, which is exactly the risk the requirement asks to avoid.

Source: official documentation

Question 2

A processing tier occasionally receives sudden bursts of work that exceed its capacity, causing requests to fail if sent directly. The team wants producers and consumers decoupled so the processing tier can consume messages at its own pace without losing work during a burst. Which service should sit between the producer and the processing tier?

  1. Amazon SQS
  2. AWS Direct Connect
  3. Amazon Route 53
  4. AWS Transit Gateway
Show answer & explanation

Answer: A. Amazon SQS provides a durable buffer between producers and consumers, holding messages until the consumer is ready to process them, which decouples the two tiers and absorbs bursts without dropping work. AWS Transit Gateway (D) is a network connectivity hub for routing traffic between VPCs and on-premises networks, not a message buffering or decoupling mechanism for application workloads.

Source: official documentation

Question 3

Hundreds of Linux-based EC2 instances spread across several Availability Zones must all read and write the same files at the same time, and storage capacity should grow automatically with the data. Which storage service best fits this requirement?

  1. Amazon EBS with Multi-Attach enabled
  2. Amazon S3 with Transfer Acceleration
  3. Amazon EFS
  4. Amazon EC2 instance store volumes
Show answer & explanation

Answer: C. Amazon EFS is a managed, elastic NFS file system designed to be mounted concurrently by many EC2 instances across multiple Availability Zones, automatically scaling capacity as data is added. EBS Multi-Attach (A) allows a single volume to be attached to multiple instances, but it is limited to instances within the same Availability Zone and to a small number of Nitro-based instances, which does not meet a multi-AZ, hundreds-of-instances requirement.

Source: official documentation

Question 4

A batch analytics job runs nightly, tolerates interruption, and can be restarted from the last checkpoint if the underlying compute is reclaimed. The team wants to minimize EC2 cost for this workload. Which EC2 purchasing option is most cost-effective?

  1. On-Demand Instances
  2. Dedicated Hosts
  3. Spot Instances
  4. Reserved Instances with a 3-year all-upfront term
Show answer & explanation

Answer: C. Spot Instances offer the largest discount off On-Demand pricing and are well suited to interruption-tolerant, restartable batch workloads, since AWS can reclaim the capacity with a short warning and the job can resume from its checkpoint. Reserved Instances (D) reduce cost for steady-state, predictable usage over a committed term, but they do not offer the same depth of discount as Spot for a workload that is explicitly interruption-tolerant and does not need guaranteed capacity.

Source: official documentation

Question 5

A company must ensure that objects uploaded to an S3 bucket are always encrypted at rest, and wants uploads that do not specify encryption to be automatically encrypted using an AWS-managed key without requiring any change to the uploading application. Which S3 feature satisfies this?

  1. S3 Object Lock in compliance mode
  2. S3 Transfer Acceleration
  3. A bucket policy that denies GetObject requests over HTTP
  4. Default encryption on the bucket using SSE-S3
Show answer & explanation

Answer: D. Configuring default encryption on an S3 bucket automatically applies server-side encryption (SSE-S3 or SSE-KMS) to every object that is uploaded without an explicit encryption header, requiring no application changes. A bucket policy denying HTTP GetObject requests (C) enforces encryption in transit, not encryption at rest for stored objects.

Source: official documentation

What 14,137 study-group comments reveal about SAA-C03

We summarised the public study-group discussion behind every question in our SAA-C03 bank and compared it with an independent AI review. Where they disagree, a posted answer key alone is not enough to trust — which is why every question in the full bank shows the community vote, a discussion summary and a reasoned explanation side by side.

1,019practice questions reviewed
14,137study-group comments summarised from Q2 2021 – Q3 2025
19%of questions where the answer commonly posted online is disputed
41%of single-answer questions where the community vote is split

The SAA-C03 traps that come up most

  • Gateway endpoints don't use security groups — VPC Gateway Endpoints (used for S3 and DynamoDB) are controlled through endpoint policies and route tables, not security groups; only Interface Endpoints attach security groups.
  • NLB can't see HTTP-level errors the way ALB can — A Network Load Balancer operates at the transport layer and cannot inspect HTTP status codes; an Application Load Balancer is needed for health checks that detect application-level errors.
  • EBS Multi-Attach only works on Provisioned IOPS volumes — Attaching a single EBS volume to multiple instances simultaneously is supported only on io1/io2 Provisioned IOPS SSD volumes, not on gp2, gp3, or other volume types.
  • A Multi-AZ standby instance cannot serve read queries — The standby in a standard RDS Multi-AZ deployment is not accessible for reads; only read replicas, or the readable secondary instances in a Multi-AZ DB cluster, can offload read traffic.
  • RDS automated backup retention tops out at 35 days — Automated backups can be retained for at most 35 days; meeting longer retention requirements requires manual snapshots or another backup mechanism outside the automated backup window.

Inside the full SAA-C03 practice bank

  • 1018 practice questions in an interactive web app, plus a printable PDF
  • The community-voted answer and a summary of the study-group discussion for each question
  • A step-by-step AI explanation of why the right answer is right — and why the others are not
  • One-time $9.99, lifetime access, no subscription

More certification study guides

Independent study material. NotJustExam is not affiliated with, endorsed by, or sponsored by any certification body; all certification names, trademarks and exam codes belong to their owners and are used for descriptive purposes only. The sample questions on this page are original items written for NotJustExam from the publicly available exam objectives. Exam facts change — always confirm details on the official exam page before you register.