AWS Certified Solutions Architect – Associate
Before an SRE can be paged about a system, someone had to decide how that system was put together — how many Availability Zones it spans, whether its database fails over automatically or waits for a human, what happens to a request when a downstream service disappears mid-flight. The AWS Certified Solutions Architect – Associate (exam code SAA-C03) is the credential that tests exactly those decisions, across the whole breadth of AWS rather than any one operational corner of it, and it's usually the first AWS certification an SRE ends up holding — often before the AWS Certified CloudOps Engineer – Associate already covered on this course's certifications hub. This page covers what the SAA-C03 actually is, how it relates to that CloudOps exam and to the SRE discipline this course teaches, the official domains and weights, and who should bother sitting it.
Picture a big building again, but this time think about two different jobs. One person is the architect: before a single brick is laid, they decide how many staircases the building needs, whether the water tank refills itself automatically or someone has to notice it's empty, and what happens to the people on the third floor if the lift breaks. The other person is the building superintendent: once it's built, they're the one walking the halls every day, fixing the leak, watching the gauges, responding when an alarm goes off. The Solutions Architect exam tests the first job — the design decisions that determine, months before anything ever breaks, how much trouble a broken lift is actually going to cause. The CloudOps exam this course already covers tests the second job. Most SREs end up needing both, but they learn the architect's job first — it's hard to be a great superintendent of a building whose design you don't understand.
What the SAA-C03 actually is, and who it's for
☺ Like you're 10: It's a closed-book, multiple-choice test about design decisions — no live AWS console, no terminal, just scenarios and the best answer among four or five.
The AWS Certified Solutions Architect – Associate is AWS's own associate-tier credential for people who design solutions on AWS, currently examined under version SAA-C03, which succeeded the earlier SAA-C02 version. Unlike the CKA or this course's own exam simulator, it is a knowledge-based exam: multiple-choice and multiple-response questions delivered through Pearson VUE, either at a physical test center or online with a remote proctor. There is no live environment to build or break — you are reasoning about a described scenario and picking the option AWS considers architecturally correct, not typing commands against a real account.
It's aimed at people who design AWS-based systems, whether or not "Solutions Architect" is in their title — and that includes SREs, because the exam's territory is precisely the set of decisions that determine what an SRE is even capable of promising later. An SLO that assumes automatic failover doesn't mean anything if nobody designed automatic failover into the system in the first place; this exam is where you learn what that design actually looks like across the breadth of AWS's own services.
AWS itself organizes almost this entire exam around one internal document: the AWS Well-Architected Framework, particularly its six pillars — Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability. The SAA-C03's four domains are close cousins of four of those pillars. If you've read AWS's own Well-Architected whitepapers, most of this exam's content will already feel familiar; if you haven't, reading the Reliability and Cost Optimization pillars first is the highest-leverage hour you can spend before opening a practice test.
Why this is usually the first AWS credential an SRE holds
☺ Like you're 10: This one teaches the whole building; the CloudOps exam teaches how to keep one already-built building running day to day. Most people need the whole-building picture first.
This course's certifications hub already covers the AWS Certified CloudOps Engineer – Associate (SOA-C03) in depth — the exam that replaced the older "SysOps Administrator" credential and tests monitoring, remediation, deployment automation and day-2 operations on AWS. The SAA-C03 sits one layer upstream of it, and the two are genuinely complementary rather than redundant: CloudOps assumes a system already exists and asks whether you can keep it healthy; the SAA-C03 asks whether you can design that system in the first place, across a far wider slice of the AWS service catalog than CloudOps ever touches — compute, storage, databases, networking, security and cost, not just the operational tooling layered on top of them.
That breadth is exactly why so many SREs sit the SAA-C03 first, even ones whose day job looks more like CloudOps than architecture. It's the exam most likely to teach you a service you've never touched — Global Accelerator, Storage Gateway, DataSync — because its job is to survey the whole portfolio, not go deep on the handful of services your current on-call rotation happens to page you about.
| SAA-C03 (this page) | CloudOps Engineer Associate (SOA-C03) | |
|---|---|---|
| Question | Can you design a resilient, secure, performant, cost-aware AWS system? | Can you monitor, troubleshoot, and operate one that already exists? |
| Time horizon | Design-time — before anything is running | Run-time — day 2 and beyond |
| Breadth | Whole AWS portfolio — compute, storage, database, network, security, cost | Narrower — monitoring, remediation, deployment automation, business continuity |
| Biggest domain | Design Secure Architectures (30%) | Monitoring, Logging and Remediation (20%) |
| Format | Knowledge-based, multiple choice/response | Knowledge-based, multiple choice/response |
| Typical order | Usually taken first | Usually taken second, once you're operating what SAA taught you to design |
Neither exam is a substitute for the other, and holding both is common precisely because they cover different halves of the same job. See the certifications hub for the full comparison against every credential this course tracks, including the CloudOps exam's own domain breakdown and logistics.
The official domains and weights (SAA-C03)
☺ Like you're 10: Four topics, and security alone is nearly a third of the whole test — bigger than cost and performance combined would suggest, if you only skimmed the title.
These are the four domains and weights as published in AWS's own AWS Certified Solutions Architect – Associate (SAA-C03) Exam Guide. They sum to exactly 100% — 30 + 26 + 24 + 20. AWS structures each domain into a small number of task statements, each with its own list of in-scope skills and services; the summary below reflects that structure without reproducing AWS's exact wording line for line.
30% — Design Secure Architectures
- Design secure access to AWS resources — IAM users, roles, groups, policies, permission boundaries, and temporary credentials via STS
- Design secure workloads and applications — security groups, network ACLs, AWS WAF, and secrets handled through Secrets Manager or Parameter Store rather than in code
- Determine appropriate data security controls — encryption at rest and in transit, KMS key management and key policies, S3 bucket policies and block-public-access settings
26% — Design Resilient Architectures
- Design scalable and loosely coupled architectures — decoupling components with SQS, SNS, and EventBridge so a failure in one component doesn't cascade into another
- Design highly available and/or fault-tolerant architectures — Multi-AZ deployments, Auto Scaling, load-balancer health checks, and Route 53 DNS failover
24% — Design High-Performing Architectures
- Determine high-performing and/or scalable storage solutions — S3 storage classes, EBS volume types, EFS versus FSx for shared file access
- Design high-performing and elastic compute solutions — right-sizing EC2 instance families, Lambda for event-driven workloads, container placement
- Determine high-performing database solutions — RDS versus Aurora versus DynamoDB, read replicas, and caching with ElastiCache
- Determine high-performing and/or scalable network architectures — VPC design, CloudFront, Global Accelerator, Direct Connect and VPN
- Determine design solutions for data ingestion and transformation — Kinesis, Glue, and pipeline patterns for streaming and batch data
20% — Design Cost-Optimized Architectures
- Design cost-optimized storage solutions — S3 lifecycle policies and storage-class tiering as workloads age
- Design cost-optimized compute solutions — Spot Instances, Savings Plans and Reserved Instances, and right-sizing against actual utilization
- Design cost-optimized database solutions — Aurora Serverless, DynamoDB on-demand capacity, and reserved capacity for predictable workloads
- Design cost-optimized network architectures — VPC endpoints to avoid NAT Gateway data-processing charges, and being deliberate about cross-AZ and cross-Region data transfer
AWS has already revised this exam once — SAA-C03 replaced SAA-C02 in 2022 — and it will do so again eventually. Task statements, in-scope service lists, and domain weights are AWS's to change without much notice, and study material still describing SAA-C02 or SAA-C01 is describing an exam you can no longer sit. Confirm the current domains and weights against AWS's own SAA-C03 exam guide PDF before you build a study plan around anything on this page.
What you actually need to know: the SRE-relevant landmarks
☺ Like you're 10: Here's the real substance behind those bullet points — the specific design choices that show up again and again, both on the exam and in a real production incident review.
High availability inside a Region: Multi-AZ, Auto Scaling, and health checks
The mechanical core of the Resilient Architectures domain is a pattern you'll see in one form or another across almost every service: spread the workload across multiple Availability Zones, let a health check decide what's healthy, and let something automated act on that decision without waiting for a human. RDS Multi-AZ keeps a synchronously replicated standby in a second AZ and fails over to it automatically; an Application Load Balancer's target-group health checks pull an unhealthy EC2 instance out of rotation before it serves a single bad response; an Auto Scaling group replaces an instance that fails its own health check without anyone paging on-call. None of this is exotic — it's the same reliability-pattern thinking this course covers in reliability patterns, expressed as specific AWS configuration rather than general theory.
# Multi-AZ RDS: the single flag that turns a database from a single point of # failure into one with automatic failover — read this flag on every exam scenario # that mentions "database" and "availability" in the same sentence. aws rds create-db-instance \ --db-instance-identifier orders-db \ --engine postgres \ --multi-az \ --db-instance-class db.r6g.large \ --allocated-storage 100 # Route 53 health check: DNS-level failover, not a load balancer. # Used when the failover target lives in a different Region entirely. aws route53 create-health-check \ --caller-reference orders-primary-2026 \ --health-check-config Type=HTTPS,ResourcePath=/health,FullyQualifiedDomainName=orders.example.com,Port=443,RequestInterval=10,FailureThreshold=3
Beyond one Region: Multi-Region patterns and disaster recovery
The exam expects you to reason in terms of RTO (how long can the system be down) and RPO (how much data can you afford to lose), and to pick the cheapest architecture that still meets both — backup and restore at the slow, cheap end; pilot light; warm standby; and multi-site active-active at the fast, expensive end. This is the same tradeoff space this course covers in disaster recovery and business continuity, and the exam's cost-optimization domain and resilience domain deliberately pull against each other here — the "most resilient" answer is rarely the correct one unless the scenario's stated RTO/RPO actually demands it. Multi-region and multi-AZ architecture covers the same ladder in more depth than any single exam question will ask for.
Database and storage design: picking the right primitive, not just the popular one
A recurring exam shape is a scenario that quietly rules out the "obvious" answer through one detail: strict single-digit-millisecond latency at massive scale points away from RDS and toward DynamoDB; a requirement for complex joins points the other way; a need for a fully managed, MySQL/PostgreSQL-compatible engine with faster failover than stock RDS points at Aurora specifically. S3 storage classes follow the same logic — Standard, Standard-IA, One Zone-IA, Glacier and Glacier Deep Archive trade retrieval speed and durability against cost, and a lifecycle policy that ages objects down that ladder automatically is usually the "cost-optimized" answer the exam is fishing for. Database reliability engineering covers the reliability side of these same tradeoffs; reliability economics covers the cost side.
Security architecture: identity first, network second
AWS's own exam guidance treats IAM as the default answer to "how should these two things authenticate to each other" — an EC2 instance role or a Lambda execution role, not a hardcoded access key, and never a long-lived credential where a temporary one via STS would do. Security groups and NACLs matter, but they're the second line of defense in most correct answers, not the first. Security's overlap with reliability covers why this ordering isn't just an AWS convention — a compromised long-lived credential is as much an availability risk as a security one, since revoking it under pressure, mid-incident, is exactly the kind of manual toil this course spends its foundations pages arguing against.
Cost as a design constraint, not an afterthought
The Cost-Optimized domain is worth 20% precisely because AWS treats cost as a first-class architectural constraint, not a finance-team problem bolted on after the design is done — the same framing this course uses in reliability economics, where every extra nine of reliability has a real, quantifiable price. Reserved Instances and Savings Plans trade commitment for discount on steady-state load; Spot Instances trade availability guarantees for a much steeper discount, and only belong under workloads that tolerate interruption; VPC endpoints avoid NAT Gateway's per-GB processing charge for traffic that's AWS-internal anyway. The exam rewards recognizing which lever fits which workload shape, not memorizing that "Spot is cheap."
Exam logistics — verify before you book
☺ Like you're 10: Here's the shape of the test as AWS generally publishes it — but prices, pass marks and formats have all moved before, so check AWS's own page before you pay.
The figures below are what AWS publishes on its own certification page and exam guide, and what candidates consistently report. Treat them as a snapshot, not a guarantee — verify anything time- or money-sensitive before you register.
| Item | What is generally published |
|---|---|
| Format | Multiple choice and multiple response, closed-book — no console, no terminal, no reference material |
| Delivery | Pearson VUE testing center, or online with a remote proctor |
| Question count | 65 questions — AWS blends scored and unscored (unidentified, non-counting) items into the same set on its associate-level exams, without always publishing the exact split for every exam |
| Duration | 130 minutes |
| Passing score | Scaled score of 720 out of a 100–1,000 scale |
| Price | Around USD $150 list; AWS publishes country-specific pricing, and discount vouchers are common through AWS training partners and re/Start-style programs |
| Validity | 3 years from the date you pass |
| Prerequisites | None formally enforced — AWS recommends at least 1 year of hands-on experience designing distributed systems on AWS before sitting it |
| Permitted resources | None — this is a closed-book exam with no allowlisted documentation, unlike the CKA's permitted-docs model |
Price, question count, passing score and prerequisites all move without much announcement, and AWS has already retired one version of this exam. This site is independent and unofficial. Confirm current details on AWS's own Solutions Architect – Associate certification page, and read the official exam guide PDF linked from that page — it's the authoritative source on domains, weights, and in-scope services, all of which AWS revises periodically.
Where it sits in the AWS ladder, and what to do next
☺ Like you're 10: It's the broad middle rung. There's an easier foundational badge below it, a harder professional badge directly above it, and specialty badges off to the side.
AWS's certification portfolio is a floor plan, not a straight line, in much the same way this course's CKA page describes the CNCF ladder. AWS Certified Cloud Practitioner sits below it as the foundational, non-technical entry point. At the same associate tier, alongside the SAA-C03, sit AWS Certified Developer – Associate and the CloudOps Engineer – Associate already covered on this course's certifications hub — three associate exams looking at the same platform from three different chairs: architect, developer, and operator. Above the SAA-C03 sits its natural sequel, AWS Certified DevOps Engineer – Professional, which assumes the design vocabulary this exam builds and spends its own weight on CI/CD pipelines, multi-account governance, and incident response at a deeper level than either associate exam attempts.
If your platform runs on a different cloud, or you want the equivalent credential there for comparison, this course also profiles Google Associate Cloud Engineer and Azure Administrator Associate (AZ-104) — both sit at a comparable associate altitude on their respective clouds, though neither maps its domains onto AWS's four one-for-one. For infrastructure certifications that aren't cloud-specific at all, CKA and HashiCorp Terraform Associate cover the substrate and the provisioning layer respectively, and pair naturally with whichever cloud credential you choose. Full comparisons across every certification this course tracks live on the certifications hub.
How to prepare using this site
☺ Like you're 10: Here's the map from each exam domain to the exact pages here that teach the underlying idea, so you're not starting from zero.
This course teaches SRE as a discipline rather than as an AWS certification study guide, so it runs deeper than the SAA-C03 on error budgets, incident response, and postmortems, and lighter on the pure service breadth AWS expects — Storage Gateway, DataSync, and similar services you'll want to read AWS's own documentation for directly. Everything below is genuine SAA-C03-relevant material already on this site.
| SAA-C03 domain | Study here |
|---|---|
| Design Secure Architectures · 30% | Security's overlap with reliability |
| Design Resilient Architectures · 26% | Reliability patterns · Multi-region & multi-AZ architecture · Disaster recovery & business continuity · Distributed systems reliability fundamentals |
| Design High-Performing Architectures · 24% | Database reliability engineering · Network reliability engineering · Capacity planning & performance |
| Design Cost-Optimized Architectures · 20% | Reliability economics |
| Resilience testing, once it's built | Chaos engineering · AWS Fault Injection Service |
| Before it ships | Production readiness reviews |
| Speed & recall | Glossary · Flashcards |
Sketch a three-tier web application on paper: an Application Load Balancer, an Auto Scaling group of EC2 instances across two Availability Zones, an RDS database, and static assets on S3 behind CloudFront. Then go component by component and ask Timmy's question — what happens when this one thing fails? An AZ goes dark. The primary database instance dies. A Spot Instance in the ASG gets reclaimed. CloudFront's origin becomes unreachable. For each failure, name the mechanism that's supposed to catch it, and be honest about which ones you actually designed in versus assumed would "probably be fine." That honesty is the entire Resilient Architectures domain in one exercise.
Professor Owl: So — Multi-AZ RDS, an ASG spanning two zones, CloudFront in front. On paper, resilient.
Timmy the Turtle: On paper. What's the RTO if the whole Region goes dark, not just one AZ?
Professor Owl: ...We never designed for that. Multi-AZ only survives a zone failure, not a Region-wide one.
Sol the Sloth: A warm standby in a second Region would fix that. It would also roughly double the monthly bill. I did the arithmetic while you two were talking.
Foxy: So which is it — pay double, or accept the Region-outage risk?
Timmy the Turtle: That's not a question this page can answer for you. It's a question the exam expects you to answer from the scenario's own stated RTO — and a question a real production system answers from its actual error budget, not from what sounds impressive in a design review.
Pair this page with the CloudOps Engineer – Associate profile for the operational half of the same platform, and with AWS Certified DevOps Engineer – Professional once you're ready to go deeper. Full comparisons against every certification this course tracks live on the certifications hub.
1. What kind of exam is the SAA-C03 — knowledge-based or performance-based — and what does that mean for how you study it compared to the CKA? 2. How does the SAA-C03 differ from the CloudOps Engineer Associate in scope and time horizon, and why do SREs often take the SAA-C03 first? 3. List the four SAA-C03 domains with their weights, largest to smallest. 4. Name two mechanisms that give a system automatic failover within a single Region, and explain why they alone aren't enough to survive a full Region outage. 5. Why does the Cost-Optimized Architectures domain matter to an SRE, not just to a finance team?
Check your answers
- It's a knowledge-based, closed-book, multiple-choice/multiple-response exam with no live environment — unlike the CKA's performance-based, live-cluster format. Studying for it means reasoning through scenarios and AWS's own documented best practices, not rehearsing commands against a real account.
- The SAA-C03 tests design-time decisions across the whole AWS portfolio — security, resilience, performance, and cost — while CloudOps Engineer Associate tests run-time operations on a system that already exists: monitoring, remediation, and deployment automation. SREs often take the SAA-C03 first because you can't operate a system's reliability well without understanding the design tradeoffs that determined what's achievable in the first place.
- Design Secure Architectures 30%; Design Resilient Architectures 26%; Design High-Performing Architectures 24%; Design Cost-Optimized Architectures 20%.
- Any two of: RDS Multi-AZ automatic failover, Auto Scaling group health checks replacing unhealthy instances, or an Application Load Balancer's health checks pulling unhealthy targets out of rotation. These operate within a Region across Availability Zones — they don't protect against a failure of the Region itself, which needs a genuinely separate Region running a pilot-light, warm-standby, or active-active pattern.
- Because reliability isn't free, and an SRE who ignores cost either overspends on redundancy the business can't sustain or, more dangerously, under-designs because a costed-out resilient option got quietly rejected without anyone stating the resulting risk out loud. Treating cost as an explicit design constraint — the same framing this course uses in reliability economics — keeps that tradeoff a deliberate, visible decision instead of an accidental one.