AWS Certified Solutions Architect – Associate
Design secure, resilient, high-performing, and cost-optimized systems on AWS. One of the most in-demand cloud credentials.
Practice the real format
Do you think you are ready? Put your knowledge to the test with a free, timed practice exam that mirrors the Solutions Architect format — with instant scoring, per-domain breakdowns, and full answer explanations.
Start a practice exam →The AWS Certified Solutions Architect – Associate (SAA-C03) validates your ability to design solutions on AWS that are secure, resilient, high-performing, and cost-effective. It is one of the most widely pursued cloud certifications in the industry and assumes roughly a year of hands-on experience designing or operating AWS workloads.
While studying for this certification, you will learn how to design, build, and deploy secure, scalable, and highly available applications on AWS. You will gain an understanding of AWS core services, architectural best practices, and how to select the right cloud solutions based on business and technical requirements.
The course covers key concepts such as designing resilient architectures, implementing cost-optimized solutions, managing security controls, and improving application performance using AWS services. You will also learn how to architect solutions that leverage compute, storage, networking, databases, monitoring, and serverless technologies to meet real-world business needs.
This certification also tests your ability to apply the AWS Well-Architected Framework principles, including operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability. Additionally, it focuses on best practices for designing cloud environments that are secure, flexible, fault-tolerant, and capable of scaling with changing business requirements.
Who Should Take This Certification?
Good fit for:
- Cloud consultants
- Solution architects
- Cloud engineers
- DevOps engineers
- Infrastructure architects
- Application developers working with cloud solutions
- Technical project managers involved in cloud transformation initiatives
- IT professionals transitioning from traditional infrastructure to AWS cloud
However, this certification is an associate-level certification designed to validate practical knowledge of AWS architecture principles and the ability to design solutions using AWS services. It focuses on architectural decision-making rather than deep expertise in individual AWS services or advanced implementation skills.
It helps learners build a strong foundation in AWS cloud architecture, security, networking, scalability, reliability, and cost management practices. The certification is ideal for professionals who want to demonstrate their ability to design and recommend AWS-based solutions for a variety of business scenarios.
Those seeking advanced cloud architecture expertise, enterprise-scale solution design skills, or leadership-level cloud strategy capabilities should consider pursuing AWS Certified Solutions Architect – Professional after completing this certification.
Read the exam structure guide to understand exactly what's tested, or the benefits guide to see why this certification is worth pursuing. When you're ready, take a full practice exam.
Your 6-week study plan
This plan maps directly to the four official SAA-C03 exam domains, spending one week on each, with the final two weeks devoted entirely to full-length practice papers and targeted revision. Aim for 6–8 hours of study per week.
- Complete a deep dive into AWS IAM — users, groups, roles, policies (identity-based vs. resource-based), permission boundaries, SCPs in AWS Organizations, and the principle of least privilege as applied in exam scenarios.
- Complete a thorough study of Amazon VPC security — Security Groups vs. NACLs (stateful vs. stateless), public vs. private subnets, NAT Gateway vs. NAT Instance, VPC Flow Logs, and VPC endpoints (Gateway and Interface).
- Complete a session on encryption and secrets management — AWS KMS (CMKs, data keys, envelope encryption), AWS Secrets Manager vs. Parameter Store, and S3 encryption options (SSE-S3, SSE-KMS, SSE-C, client-side).
- Complete a review of network connectivity and edge security — AWS WAF, AWS Shield, Amazon CloudFront with signed URLs and OAC, and when to use AWS PrivateLink vs. VPC peering vs. Transit Gateway for private connectivity.
Week 1 checkpoint: Security is 30% of the exam — the largest domain. Be able to draw a secure 3-tier VPC from memory: public subnet (ALB), private subnet (EC2), isolated subnet (RDS), with the correct Security Group rules between each layer.
- Complete a study block on EC2 resilience patterns — Auto Scaling Groups (dynamic, scheduled, predictive), launch templates, placement groups (cluster, spread, partition), and Multi-AZ deployments behind an Application Load Balancer.
- Complete a session on database high availability — Amazon RDS Multi-AZ vs. Read Replicas, Amazon Aurora Global Database and Aurora Serverless, DynamoDB global tables, and ElastiCache for read scaling.
- Complete a deep dive into disaster recovery strategies — backup and restore, pilot light, warm standby, and multi-site active/active. Know the RTO/RPO trade-offs and which AWS service combination achieves each tier.
- Complete a review of decoupling and queuing patterns — Amazon SQS (Standard vs. FIFO, visibility timeout, DLQ), Amazon SNS fan-out, and how decoupled architectures improve fault tolerance across services like Lambda and EC2.
Week 2 checkpoint: For every DR strategy, be able to state the RTO, RPO, approximate cost tier, and the core AWS services used. The exam presents these as "company needs recovery within X hours with Y data loss" — you select the strategy, not just the service.
- Complete a study session on compute performance — EC2 instance families (compute-optimised, memory-optimised, storage-optimised), when to use AWS Lambda vs. ECS vs. Fargate vs. EC2, and Elastic Load Balancer types (ALB, NLB, GLB) and when each is the right choice.
- Complete a deep dive into storage performance — Amazon S3 (multipart upload, Transfer Acceleration, Byte-Range Fetches), Amazon EBS (gp3 vs. io2, throughput vs. IOPS), Amazon EFS (performance modes, throughput modes), and FSx options (Lustre for HPC, Windows File Server).
- Complete a session on caching and database read performance — Amazon ElastiCache (Redis vs. Memcached, Lazy Loading vs. Write-Through), DynamoDB Accelerator (DAX), and CloudFront as a caching layer for dynamic and static content.
- Complete a review of networking throughput patterns — AWS Direct Connect, VPN vs. Direct Connect trade-offs, Global Accelerator for latency reduction, and Route 53 routing policies (latency-based, geolocation, geoproximity, weighted, failover).
Week 3 checkpoint: Know the distinction between Global Accelerator (network-layer performance, static IPs, TCP/UDP) and CloudFront (content delivery, caching, HTTP/HTTPS). The exam frequently uses near-identical scenarios to test this specific distinction.
- Complete a session on EC2 pricing models — On-Demand vs. Reserved Instances (Standard, Convertible, Scheduled) vs. Savings Plans vs. Spot Instances. Know the exact use case and workload type that justifies each, and when to combine them (e.g. baseline RI + burst Spot).
- Complete a study block on cost-optimized storage — S3 storage classes (Standard, Intelligent-Tiering, Standard-IA, One Zone-IA, Glacier Instant/Flexible/Deep Archive), lifecycle policies, and S3 Requester Pays for cost attribution.
- Complete a deep dive into serverless cost patterns — AWS Lambda (pay-per-invocation, duration pricing, Provisioned Concurrency cost trade-offs), API Gateway (REST vs. HTTP API pricing), and Amazon SQS, SNS, and EventBridge for event-driven, low-idle-cost architectures.
- Complete a review of the AWS Well-Architected Framework — all six pillars (operational excellence, security, reliability, performance efficiency, cost optimization, sustainability), AWS Trusted Advisor checks, and AWS Compute Optimizer for rightsizing recommendations.
Week 4 checkpoint: After completing all four domains, create a one-page cheat sheet: one key service or pattern per sub-topic across every domain. Flag anything you couldn't recall without notes — those gaps are exactly what weeks 5 and 6 will address through practice papers.
- Complete your first full-length timed practice paper under realistic exam conditions — 65 questions, 130 minutes, no pausing, no notes. Record your per-domain score carefully before reviewing any answers.
- Complete a thorough answer review session — for every wrong answer, understand why the correct option is right and why each distractor is wrong. SAA-C03 distractors are intentionally plausible; the difference is usually one specific constraint (stateful vs. stateless, synchronous vs. asynchronous, cost vs. speed).
- Complete a targeted revision block on your two lowest-scoring domains — return to your Week 1–4 notes, focus only on the specific services or patterns your paper score flagged, and create a concise summary of each weak area.
- Complete a second full-length practice paper by the end of the week. Compare per-domain scores against Paper 1 to confirm improvement and identify any remaining gaps before the final week.
- Complete a third full-length practice paper early in the week. Target a consistent score above 80%. If any domain is still below 70%, do one focused revision block on just that domain before your exam date.
- Complete a scenario-pattern drill — go through the most commonly confused SAA-C03 pairs: ALB vs. NLB, SQS vs. SNS vs. EventBridge, S3 Lifecycle vs. Intelligent-Tiering, Security Groups vs. NACLs, Direct Connect vs. VPN. Being able to decide in under 20 seconds saves crucial time on the day.
- Complete a final consolidation paper 2–3 days before your exam. Once you score above 80% on two consecutive papers, stop sitting full papers and switch to light notes review only — over-practising introduces fatigue, not improvement.
- Complete a pre-exam checklist: confirm your exam slot and ID requirements, prepare your testing environment (quiet space, stable internet for online proctoring), rest well the night before, and log in or arrive 15 minutes early. The preparation is done — trust it.
How to use this plan
Weeks 1–4 are pure domain study — no practice papers, just building solid knowledge across security, resilience, performance, and cost. Weeks 5 and 6 are exam simulation: sit full-length timed papers, review every explanation carefully, and do targeted revision on weak domains. The SAA-C03 rewards architectural thinking over service memorisation — when reviewing wrong answers, always ask "why is this architecture pattern better?" not just "which service is correct?". Aim for above 80% consistently on two back-to-back papers before booking.
Ready to test yourself?
Do you think you are ready? Put your knowledge to the test with a free, timed practice exam that mirrors the Solutions Architect format — with instant scoring, per-domain breakdowns, and full answer explanations.
Start a practice exam →