AWS Solutions Architect Associate: architecture decisions
Prepare AWS architecture decisions with lessons, questions, and scenarios on security, resilience, performance, and cost.
Objectives and progression
Ten original modules include 70 questions and 12 fictional AWS architecture, banking, and production cases. Expanded lessons cover hybrid private access, container startup, regional permissions, recovery, capacity, and cost comparison using synthetic values. The internal assessment reuses 44 decisions in 75 minutes. Full mocks and exhaustive SAA-C03 task coverage are still outstanding. Exercises require no AWS account and do not represent executed cloud experiments or independent specialist review.
Audience: Cloud engineers, developing architects, and technical managers with production responsibility.
Prerequisites: AWS fundamentals, TCP/IP networking, and familiarity with databases and availability.
385 estimated study minutes
- Diagnose permissions and network paths.
- Relate capacity and recovery to RTO and RPO.
- Select data, caching, and processing according to access patterns.
- Assess cost, commitments, and resource retirement.
- Establish startup dependencies and measure complete recovery under comparable costs.
Modules
- Identity, trust, and permissions
- Networks, endpoints, and hybrid connectivity
- Data protection and recovery
- Resilience, capacity, and recovery
- Storage and content delivery
- Databases, replicas, and cache
- Events, queues, and processing
- Costs, commitments, and retirement
- Private access and startup without hidden dependencies
- Recovery: dependencies, capacity, and cost
Continue learning
References and version
SAA-C03
- SAA-C03 exam guide · 2026-10-01
- AWS Certified Solutions Architect - Associate · 2026-09-29
- IAM security best practices · 2026-09-29
- IAM roles · 2026-09-29
- IAM policy evaluation logic · 2026-09-29
- Service control policies · 2026-09-29
- KMS key policies · 2026-09-29
- Security groups · 2026-09-29
- Network ACLs · 2026-09-29
- Internet gateways · 2026-09-29
- Configure an interface endpoint · 2026-10-01
- Gateway endpoints for Amazon S3 · 2026-10-01
- Direct Connect encryption · 2026-09-29
- VPC peering behavior · 2026-09-29
- Restrict access to an S3 origin · 2026-09-29
- S3 Object Lock · 2026-09-29
- Secrets Manager rotation · 2026-09-29
- CloudTrail data events · 2026-09-29
- S3 Versioning · 2026-09-29
- RDS point-in-time restore · 2026-09-29
- EC2 Auto Scaling architecture benefits · 2026-09-29
- Disaster recovery options in the cloud · 2026-10-01
- Define recovery objectives · 2026-09-29
- Route 53 health checks · 2026-09-29
- Amazon EFS overview · 2026-09-29
- FSx for Windows File Server · 2026-09-29
- S3 multipart uploads · 2026-09-29
- CloudFront cache policies · 2026-09-29
- S3 Lifecycle transitions · 2026-09-29
- S3 Intelligent-Tiering · 2026-09-29
- EBS general purpose SSD volumes · 2026-09-29
- RDS Multi-AZ DB instance deployments · 2026-09-29
- RDS read replicas · 2026-09-29
- DynamoDB partition-key design · 2026-09-29
- Aurora reader endpoints · 2026-09-29
- ElastiCache Memcached caching strategies · 2026-09-29
- RDS best practices · 2026-09-29
- SQS standard queues · 2026-09-29
- SQS visibility timeout · 2026-09-29
- SQS dead-letter queues · 2026-09-29
- SNS fanout to SQS · 2026-09-29
- Scale using SQS backlog · 2026-09-29
- AWS Lambda overview · 2026-09-29
- Savings Plans overview · 2026-09-29
- Spot interruptions · 2026-09-29
- NAT gateway pricing considerations · 2026-09-29
- AWS Budgets · 2026-09-29
- Delete an EBS volume · 2026-09-29
- SAA-C03 content domain 1 · 2026-09-29
- SAA-C03 content domain 2 · 2026-09-29
- SAA-C03 content domain 3 · 2026-09-29
- SAA-C03 content domain 4 · 2026-09-29
- EBS modification limitations · 2026-09-29
- Route 53 record TTL · 2026-09-29
- Control access using endpoint policies · 2026-10-01
- Amazon ECR interface VPC endpoints · 2026-10-01
- Replicate Secrets Manager secrets across Regions · 2026-10-01
- Control access to multi-Region keys · 2026-10-01
- AWS PrivateLink pricing · 2026-10-01
What you will explore
0 / 10Identity, trust, and permissions
Diagnose access without accumulating unnecessary permissions.
Networks, endpoints, and hybrid connectivity
Follow the request path through DNS, routes, and filters.
Data protection and recovery
Choose controls for access, retention, auditing, and recovery.
Resilience, capacity, and recovery
Relate possible failures to remaining capacity and business objectives.
Storage and content delivery
Select protocols, performance, and lifecycle from access patterns.
Databases, replicas, and cache
Distinguish availability, read scaling, and consistency.
Events, queues, and processing
Design consumers that tolerate repetition, failures, and load variation.
Costs, commitments, and retirement
Optimize spending while preserving capacity, recovery, and ownership.
Private access and startup without hidden dependencies
Follow a request from client to data and establish that new resources can start in a private design.
Recovery: dependencies, capacity, and cost
Measure the recovery critical path and compare designs under the same service commitments.