Skip to content

AWS Certified Solutions Architect — Associate

Associate · SAA-C03

Learn AWS architecture, not service trivia.

Learn each architecture. Understand the tradeoffs. Then test yourself.

Open Practice
17architecture scenarios
  1. 01Learn
  2. 02Recall
  3. 03Apply
  4. 04Mix

Learn

The Solutions Architect curriculum.

Open the full curriculum
  1. 01Public Web App On AWSA highly available public web application with one public entrance, private application servers, managed state, and health-based scaling.
  2. 02CloudFront WAF Protected Web EdgeEvolve a public AWS web application into a faster, safer global front door with CloudFront, AWS WAF, Shield, and protected origins.
  3. 03Private App Access To S3Practice readyHow an application in private subnets reaches Amazon S3 without public IP addresses or NAT, then secure the path with roles and policies.
  4. 04Highly Available RDS AppEvolve a single-database web application so it survives database and Availability Zone failures, reconnects safely, and can recover from bad data.
  5. 05Static Site With CloudFront And S3A globally fast HTTPS static website with CloudFront while S3 stores the files privately behind origin access control.
  6. 06Serverless API With Lambda And DynamoDBA low-operations API with managed HTTP entry, request-time Lambda compute, DynamoDB key access, safe retries, and deliberate capacity controls.
  7. 07Event-Driven Order ProcessingPractice readyEvolve synchronous checkout into durable order acceptance, event routing, buffered consumers, coordinated fulfillment, and retry-safe processing.
  8. 08Secure Partner File Ingest On S3Practice readyHow partner SFTP uploads into encrypted, isolated, retryable S3 ingestion that promotes only validated files into trusted data zones.
  9. 09Analytics Data Lake On S3A beginner-friendly AWS data lake by separating durable storage, metadata, transformation, occasional SQL, warehouse analytics, streaming ingestion, and dashboards.
  10. 10Backup vs Replication Recovery DesignWhy backups preserve history while replication supports continuity, then design around acceptable data loss (RPO), recovery time (RTO), isolation, and restore testing.
  11. 11Multi-Region Disaster Recovery On AWSChoose and build an AWS disaster recovery strategy from RTO and RPO, progressing from backup and restore through pilot light, warm standby, and active-active.
  12. 12On-Premises Migration To AWSPlan a phased migration to AWS by separating server, database, file, network, validation, cutover, and rollback problems instead of treating migration as one large copy.
  13. 13Hybrid Network Connectivity To AWSHybrid connectivity progressively by separating the physical path, routing, Transit Gateway segmentation, DNS forwarding, security inspection, and failure recovery.
  14. 14Multi-Account Cost GovernanceAWS cost governance progressively with account ownership, cost allocation tags, Cost Explorer, Budgets, anomaly detection, Data Exports, preventive guardrails, rightsizing, and commitments.
  15. 15Landing Zone Guardrails For Multi-Account AWSA governed multi-account AWS foundation with Organizations, OUs, Control Tower, Account Factory, IAM Identity Center, centralized evidence, and layered controls.
  16. 16Secure Cross-Account CloudTrail LoggingCentralized CloudTrail evidence across an AWS organization using an organization trail, a separate log archive account, restrictive S3 and KMS policies, validation, and retention controls.
  17. 17Centralized Security Findings And Incident TriageHow multi-account AWS security signals into owned response using delegated administrators, regional coverage, Security Hub aggregation, EventBridge routing, evidence, and guarded automation.

Practice

Can you explain the decision without looking back?

Choose a scenario you have studied. Recall it first, then answer exam-style questions.

Choose a scenario