AWS Solutions Architect – Associate (SAA-C03) Master Study Guide & Architecture Blueprint
Master the architectural patterns, storage decision trees, decoupling mechanisms, high-availability setups, and cost-optimization principles tested on the AWS SAA-C03 exam.
Table of Contents
- 1. SAA-C03 Exam Overview & Benchmark
- 2. The 4 SAA-C03 Domains & Scoring Weight
- 3. AWS Storage Decision Matrix (S3, EBS, EFS, FSx)
- 4. Database Architecture Matrix (Aurora, RDS, DynamoDB)
- 5. Decoupling & Event-Driven Architecture (SQS, SNS, EventBridge)
- 6. High-Yield VPC Networking & PrivateLink
- 7. Disaster Recovery Strategies (RTO vs RPO)
- 8. Cost-Optimization Patterns That Score Points
- 9. Top 5 Architectural Traps on the Exam
- 10. Practice in the Free Timed Simulator
1. SAA-C03 Exam Overview & Benchmark
The AWS Certified Solutions Architect – Associate (SAA-C03) certification tests your ability to design resilient, high-performing, secure, and cost-optimized distributed systems on AWS. Unlike developer or sysops exams, SAA-C03 evaluates architectural trade-offs: choosing the right service mix based on customer constraints (latency, budget, compliance, and recovery times).
2. The 4 SAA-C03 Domains & Scoring Weight
| Domain | Weight | Core Competencies Tested |
|---|---|---|
| Domain 1: Design Secure Architectures | 30% | IAM roles/policies, AWS KMS key rotation, Security Groups vs NACLs, WAF, Shield, VPC Endpoints |
| Domain 2: Design Resilient Architectures | 26% | Multi-AZ deployments, Auto Scaling Groups, SQS decoupling, Aurora Global Databases, Disaster Recovery |
| Domain 3: Design High-Performing Architectures | 24% | CloudFront caching with OAC, DynamoDB DAX, ElastiCache Redis, S3 Transfer Acceleration, EFS IOPS |
| Domain 4: Design Cost-Optimized Architectures | 20% | S3 Lifecycle policies, Glacier Deep Archive, EC2 Spot Instances, Savings Plans, Gateway Endpoints |
3. AWS Storage Decision Matrix (S3, EBS, EFS, FSx)
Storage selection questions appear heavily on every SAA-C03 test. Use this decision matrix:
| Storage Service | Type | Sharing Capability | Ideal Workloads |
|---|---|---|---|
| Amazon S3 | Object Storage | HTTP/REST Worldwide | Static web assets, backups, data lake ingestion, infinite scalability. |
| Amazon EBS | Block Storage | Single EC2 in 1 AZ (Multi-Attach for io1/io2 only) | OS boot volumes, high IOPS transactional databases (PostgreSQL, MySQL). |
| Amazon EFS | File Storage (NFSv4) | Thousands of EC2/Containers across Multi-AZ | Shared content management (WordPress), Linux file trees, parallel computing. |
| Amazon FSx for Lustre | High-Speed POSIX | Compute clusters | Machine learning training, high-performance computing (HPC), financial modeling. |
| FSx for Windows | SMB File Share | Windows instances & Active Directory | Enterprise Windows apps, home directories, Microsoft SQL Server Failover Clusters. |
4. Database Architecture Matrix (Aurora, RDS, DynamoDB)
- Amazon Aurora: 5x throughput of standard MySQL, 3x PostgreSQL. Replicates 6 copies across 3 AZs automatically. Fails over in under 30 seconds. Use Aurora Global Database for sub-second cross-region replication.
- RDS Multi-AZ vs. Read Replicas:
- Multi-AZ: Synchronous replication for High Availability & automated failover. The standby is NOT accessible for reads!
- Read Replicas: Asynchronous replication for Performance & Read Scaling. Can be promoted to master during disaster recovery.
- Amazon DynamoDB: NoSQL key-value store with single-digit millisecond latency. Use DAX (DynamoDB Accelerator) for microsecond in-memory read caching without rewriting application code!
5. Decoupling & Event-Driven Architecture (SQS, SNS, EventBridge)
When you see "decouple", "handle traffic bursts", or "prevent request loss" on the exam, think:
- Amazon SQS (Standard): Unlimited throughput, at-least-once delivery, best-effort ordering. Scale worker Auto Scaling groups using the
ApproximateNumberOfMessagesVisibleCloudWatch metric. - Amazon SQS (FIFO): Strictly ordered (First-In, First-Out), exactly-once processing, 300 msg/sec limit (3,000 with batching).
- Amazon SNS: Pub/Sub notification service (fan-out pattern: 1 publisher → multiple SQS queues or Lambdas).
- Amazon EventBridge: Serverless event bus with advanced schema matching, third-party SaaS integrations, and automated scheduling.
6. High-Yield VPC Networking & PrivateLink
- Gateway Endpoints: Only available for Amazon S3 and Amazon DynamoDB. Free of charge, configured via VPC Route Table entry. Eliminates NAT Gateway data transfer costs!
- Interface Endpoints (AWS PrivateLink): Available for almost all other AWS services (KMS, SQS, Secrets Manager, etc.). Provisions an Elastic Network Interface (ENI) with a private IP in your subnet. Incurs hourly and data processing fees.
- Transit Gateway: Connects thousands of VPCs and on-premises networks in a hub-and-spoke model. Replaces complex mesh VPC peering!
7. Disaster Recovery Strategies (RTO vs RPO)
Disaster Recovery Patterns Ordered by Cost & Speed:
- Backup & Restore: Lowest cost, highest RTO/RPO (hours to days). Data backed up to S3 and replicated across regions.
- Pilot Light: Core services (databases) constantly replicate, but compute instances are kept off or minimal until disaster strikes.
- Warm Standby: A scaled-down version of the fully functional environment always runs in the secondary region.
- Multi-Region Active-Active: Highest cost, zero downtime (RTO/RPO near zero). Traffic served by Route 53 latency/geolocation routing to multiple active regions.
8. Cost-Optimization Patterns That Score Points
- S3 Lifecycle Transition: S3 Standard → S3 Standard-IA (30 days) → S3 Glacier Flexible / Deep Archive → Expiration.
- Compute Savings: Spot Instances for fault-tolerant, stateless worker tasks (up to 90% discount). Compute Savings Plans for predictable baseline EC2 and Fargate usage.
- Egress Costs: Keeping data transfers within the same Availability Zone is free; cross-AZ incurs costs; cross-Region incurs higher fees. Use CloudFront to reduce origin egress costs!
9. Top 5 Architectural Traps on the Exam
Trap 1: "Client wants low latency worldwide for dynamic HTTP API responses"
Wrong Answer: S3 Transfer Acceleration (that is only for uploading to S3).
Correct Answer: Amazon CloudFront with dynamic caching and regional edge caches, or AWS Global Accelerator with Anycast IPs.
Trap 2: "Synchronous Multi-AZ RDS replica used for read traffic"
Wrong Answer: Directing reporting queries to the standby Multi-AZ replica.
Correct Answer: The standby cannot accept read queries. You must provision an asynchronous Read Replica for analytics.
Test Your Architectural Skills in the Free SAA-C03 Simulator
Challenge yourself with real enterprise scenarios, 130-minute exam timer, domain scoring, and deep answer rationales. 100% Free with zero registration required!
🚀 Launch Free AWS SAA-C03 Simulator Now