Solutions Architect – Associate
Core architecture notes
Security Groups versus NACLs versus Flow Logs, IAM and STS, VPC design, EC2, S3, CloudFront, databases, high availability and the monitoring stack — the working mental model for SAA-C03.
Design-level notes for AWS Certified Solutions Architect – Associate (SAA-C03). The course notes build the mental model, the study-guide page covers the blueprint fundamentals, and the exam-tips page is your last pass before the test centre.
10 topics, 46 study points. Everything here is exam-oriented: each point is a fact or a distinction that SAA-C03 items are built on. Test yourself against the practice exam once you can explain a section without re-reading it.
1. Security Groups vs NACLs vs Flow Logs
AWS provides three distinct layers of network security that work together to protect your infrastructure. Understanding the difference between them — and when each one applies — is fundamental to designing secure AWS architectures. The three tools are Security Groups (SGs), Network Access Control Lists (NACLs), and VPC Flow Logs.
Security Groups act as a virtual firewall at the instance level. They control inbound and outbound traffic for individual EC2 instances (and other resources like RDS or Lambda functions within a VPC). Security Groups are stateful, which means that if you allow an inbound request, the response traffic is automatically permitted regardless of outbound rules. By default, all inbound traffic is denied and all outbound traffic is allowed. You can attach multiple Security Groups to a single instance, and rules are evaluated collectively — there is no ordering or priority, just an implicit “allow if any rule matches”.
Network ACLs operate at the subnet level, acting as a stateless firewall that evaluates every packet independently. Because they are stateless, you must explicitly allow both inbound and outbound traffic — including the ephemeral response ports (1024–65535) needed for return traffic. NACLs evaluate rules in numbered order (lowest number first) and stop at the first matching rule. They are particularly useful for blocking specific IP ranges at scale across an entire subnet, which cannot be done with Security Groups.
VPC Flow Logs capture metadata about IP traffic flowing through your VPC, including accepted and rejected traffic. They do not inspect packet content — only source/destination IP, port, protocol, bytes transferred, and whether traffic was accepted or rejected. Flow Logs are invaluable for troubleshooting connectivity issues, detecting unusual traffic patterns, and performing security audits. Logs can be published to CloudWatch Logs or S3 for analysis.
A practical mental model: Security Groups are your first line of defense at the instance level (stateful, allow-based). NACLs are a secondary layer at the subnet level (stateless, allow and deny rules). Flow Logs are your observability tool — they tell you what actually happened on the network so you can audit, debug, and improve your security posture over time.
2. IAM & STS
AWS Identity and Access Management (IAM) is the centralized service for controlling who can do what in your AWS account. It lets you create and manage users, groups, and roles, and attach permission policies to them. IAM is global — it is not regional — meaning the users, groups, and roles you create apply across all AWS regions and services.
IAM is built around four core concepts. Users represent individual identities (humans or applications). Groups are collections of users that share the same permissions — managing permissions at the group level is far more scalable than assigning them user by user. Roles are identities that can be assumed by AWS services, EC2 instances, Lambda functions, or external entities — they provide temporary, scoped access without embedding long-term credentials. Policies are JSON documents that explicitly define allowed or denied actions on specific AWS resources, and they are attached to users, groups, or roles.
New IAM users have zero permissions by default. When you create a user for programmatic access, AWS generates an Access Key ID and Secret Access Key. These credentials are used with the CLI, SDKs, or direct API calls — they cannot be used to log into the AWS console. Critically, the Secret Access Key is only shown once at creation time. If you lose it, you must rotate and generate a new key pair. The root account has unrestricted administrative access and should never be used for day-to-day tasks — always enable MFA on the root account immediately after creating your AWS account.
AWS Security Token Service (STS) extends IAM by enabling temporary, limited-privilege credentials. Instead of embedding long-term access keys in your application code or configuration files, STS lets you request short-lived credentials that expire automatically. This dramatically reduces the blast radius of a credential leak. STS credentials are global and cannot be scoped to a specific region. Common STS use cases include role assumption for cross-account access, federated login, and service-to-service authentication.
IAM supports two forms of identity federation. Enterprise identity federation allows employees in your organization to authenticate via your existing corporate directory (Active Directory, LDAP) and assume IAM roles — this enables Single Sign-On (SSO) without creating separate AWS IAM identities for every employee. Web identity federation allows users to sign in with external identity providers such as Amazon, Facebook, Google, or any OpenID Connect 2.0 compatible provider. For mobile applications specifically, Amazon Cognito is the recommended service — it manages user identities, handles federation, and provides secure, scoped access to AWS resources.
3. VPC (Virtual Private Cloud)
A Virtual Private Cloud (VPC) is a logically isolated section of the AWS Cloud where you launch AWS resources in a virtual network that you define. Think of it as your own private data center within AWS — you control the IP address range, subnets, routing, and network gateways. Every AWS account comes with a default VPC in each region, preconfigured with public subnets and internet access so you can get started immediately.
The key components of a VPC are: the VPC itself (with a CIDR block like 10.0.0.0/16), Subnets (subdivisions of the VPC CIDR assigned to specific Availability Zones), Route Tables (rules that determine where traffic is directed), an Internet Gateway (IGW) for public internet access, NAT Gateways or NAT Instances for outbound-only internet access from private subnets, Security Groups and NACLs for traffic filtering, and VPC Endpoints for private connectivity to AWS services.
A critical distinction: the default VPC is configured so all subnets have internet access and every instance receives both a public and private IP address. In a custom VPC, no internet access exists by default — you must explicitly attach an Internet Gateway to the VPC and add a route table entry (0.0.0.0/0 → IGW) to make a subnet public. Any subnet without a route to the IGW is private by definition.
Subnets are tied to a single Availability Zone — a subnet cannot span multiple AZs. To achieve high availability, deploy your resources across subnets in multiple AZs. Security Groups are stateful (response traffic is automatically allowed), while NACLs are stateless (you must explicitly allow both request and response traffic). NACL rules are evaluated in numerical order — the first matching rule wins, so rule ordering matters.
NAT (Network Address Translation) allows instances in private subnets to initiate outbound connections to the internet while remaining unreachable from inbound internet traffic. NAT Gateways are the modern, managed approach — they are highly available within a single AZ, scale automatically, and require no management overhead. NAT Instances are the legacy approach: a single EC2 instance configured for NAT. With NAT Instances you must disable the Source/Destination Check attribute because NAT requires forwarding traffic not destined for the instance itself. VPC Peering enables private connectivity between two VPCs — but peering is non-transitive, meaning VPC A peered with VPC B and VPC B peered with VPC C does not mean A can communicate with C.
4. EC2 (Elastic Compute Cloud)
Amazon EC2 is the backbone of AWS compute — it provides resizable virtual machines (instances) in the cloud. Understanding EC2 deeply means knowing instance types, purchasing options, storage options, and networking behavior. EC2 instances are categorized into families based on their hardware profile: T and M families for general-purpose workloads, C for compute-intensive tasks (high CPU), R for memory-intensive workloads, I and D for storage-optimized use cases (high IOPS or high throughput), G for GPU-accelerated workloads, and F for FPGA-based custom hardware acceleration.
An Amazon Machine Image (AMI) is the template used to launch an EC2 instance. It includes the operating system, pre-installed software, and configuration. AMIs are region-specific, so if you need to launch instances in multiple regions, you must copy your AMI to each target region. When selecting or creating an AMI, you choose the OS (Linux, Windows), architecture (x86 or ARM), launch permissions, and the type of root storage (EBS-backed or instance store-backed).
EC2 instances have two primary storage options. EBS (Elastic Block Store) volumes are persistent network-attached block storage — they survive instance stops and reboots, can be detached and reattached to different instances, and support snapshots for backup. Instance Store volumes are ephemeral — they are physically attached to the host hardware and provide very high I/O performance, but all data is lost when the instance is stopped or terminated. For the highest possible IOPS on NoSQL databases like Cassandra, use i3 instances with NVMe SSD instance storage, which can deliver up to 3.3 million IOPS.
EC2 offers multiple purchasing models to optimize cost. On-Demand instances charge by the second with no commitment — ideal for unpredictable workloads. Reserved Instances offer up to 75% discount in exchange for a 1 or 3-year commitment — best for steady, predictable workloads. Spot Instances let you bid on unused EC2 capacity at up to 90% discount, but AWS can reclaim them with a 2-minute warning — suitable for fault-tolerant batch jobs. Dedicated Hosts are physical servers fully dedicated to your use, required for software licenses tied to physical cores or sockets, or strict compliance requirements.
Elastic IP addresses are static public IPv4 addresses you allocate to your account. Unlike the dynamic public IPs that EC2 assigns by default (which change when an instance is stopped), Elastic IPs remain fixed and can be remapped between instances instantly — this makes them useful for failover scenarios where you need a stable endpoint. However, Elastic IPs incur a charge when they are allocated but not associated with a running instance, so release them when not in use.
5. S3 (Simple Storage Service)
Amazon S3 is AWS’s object storage service — it stores data as objects (files + metadata) within containers called buckets. S3 is not a file system and cannot host operating systems or databases, but it is extraordinarily versatile: it can hold files from 0 bytes to 5 TB, serves as a static website host, acts as a data lake for analytics, and backs up virtually any type of data. S3 is designed for 99.999999999% (eleven nines) of durability — AWS automatically replicates your data across multiple physical facilities within a region.
S3 offers several storage classes optimized for different access patterns and costs. S3 Standard is the default — low latency, high throughput, designed for frequently accessed data. S3 Standard-IA (Infrequent Access) costs less per GB stored but adds a retrieval fee — good for data accessed monthly. S3 One Zone-IA stores data in only one AZ, making it cheaper but less resilient. S3 Intelligent-Tiering automatically moves objects between Standard and IA tiers based on access patterns, eliminating the need to manually manage lifecycle rules for unpredictable workloads. S3 Glacier and Glacier Deep Archive are archival tiers with retrieval times ranging from minutes to hours — designed for compliance and long-term backup at very low cost.
S3 Versioning keeps every version of an object, including all overwrites and deletes. Once enabled on a bucket, versioning can only be suspended — not fully disabled. A delete operation on a versioned object places a “delete marker” rather than permanently removing it, so previous versions remain recoverable. MFA Delete adds an extra layer of protection: it requires multi-factor authentication to permanently delete object versions, protecting against accidental or malicious deletion.
S3 supports multiple server-side encryption options. SSE-S3 uses AWS-managed keys (AES-256) transparently — the simplest option with no key management overhead. SSE-KMS uses AWS Key Management Service, giving you control over key rotation, audit logging of key usage via CloudTrail, and the ability to set key policies. SSE-C (Customer-Provided Keys) lets you supply your own encryption keys — AWS performs the encryption but does not store your keys. Client-Side Encryption means you encrypt data before uploading it to S3. For cross-bucket or cross-origin web requests, configure CORS (Cross-Origin Resource Sharing) on the bucket to allow the necessary origins.
Pre-signed URLs grant temporary access to specific S3 objects without requiring the requester to have AWS credentials. They are ideal for sharing private files for a limited time or for allowing upload to S3 without exposing your bucket publicly. S3 Transfer Acceleration speeds up uploads for globally distributed users by routing data through CloudFront edge locations to AWS’s optimized backbone network. For very large files, multipart upload breaks the object into parts that are uploaded in parallel, improving performance and resilience — recommended for files over 100 MB and required for files over 5 GB.
6. CloudFront
Amazon CloudFront is AWS’s global Content Delivery Network (CDN). It caches content at a worldwide network of edge locations — AWS infrastructure points geographically close to end users — so that requests are served with lower latency than if every request traveled back to your origin server. Edge locations are not just read caches: you can also write to them (for example, S3 Transfer Acceleration uses edge locations for uploads).
A CloudFront distribution defines where your content comes from (the origin) and how it is cached and delivered. Supported origins include S3 buckets, EC2 instances, Application Load Balancers, and any HTTP endpoint. When a user requests content, CloudFront checks whether a cached copy exists at the nearest edge location. If found (a “cache hit”), CloudFront serves it immediately. If not (a “cache miss”), CloudFront fetches it from the origin, caches it at the edge for the duration specified by the TTL (Time to Live), and returns it to the user. Increasing the default TTL reduces the number of origin fetches and improves performance.
Cache invalidation forces CloudFront to remove cached objects before their TTL expires — useful when you deploy updated content and cannot wait for caches to naturally expire. Invalidations are charged per path, so for frequent updates consider versioning your file names (e.g., app-v2.js) rather than invalidating repeatedly. CloudFront also supports forwarding query strings to the origin for dynamic content, allowing different cached responses based on query parameter values.
CloudFront integrates with Route 53 for DNS-based failover. When using S3 as an origin for Route 53 failover routing, the S3 bucket name must exactly match the domain name configured in Route 53. RTMP distributions (legacy) supported streaming Flash media files via the RTMP protocol, though this is rarely used in modern architectures. For offloading read traffic from S3 buckets to reduce costs and improve global performance, a CloudFront Distribution in front of your S3 bucket — combined with Regional Edge Caches as an intermediate layer — is the standard pattern.
7. Databases
Amazon RDS (Relational Database Service) is a managed service for relational databases. AWS handles provisioning, patching, backups, and hardware maintenance — you focus on schema design and queries. Supported engines include MySQL, PostgreSQL, MariaDB, Oracle, Microsoft SQL Server, and Amazon Aurora. RDS automates daily backups with a configurable retention window (1 to 35 days) and allows point-in-time recovery to any second within that window.
RDS Multi-AZ deployments maintain a synchronous standby replica in a different Availability Zone. If the primary instance fails — whether due to hardware failure, OS patching, or an AZ outage — RDS automatically fails over to the standby with minimal downtime, typically 1–2 minutes. Multi-AZ is about high availability and durability, not performance. Read Replicas serve a different purpose: they are asynchronous copies of your primary database that offload read-heavy traffic. You can have up to 5 read replicas per primary instance, but using them requires application-level routing (directing read queries to replica endpoints). Read Replicas can be promoted to standalone databases.
Amazon Aurora is AWS’s proprietary relational database engine, compatible with MySQL and PostgreSQL. It delivers up to 5x the performance of MySQL on the same hardware by using a distributed, fault-tolerant storage architecture that automatically replicates data across three AZs in six copies. Aurora storage scales automatically up to 128 TB without manual intervention, and Aurora Global Database allows low-latency reads across multiple regions for globally distributed applications.
Amazon DynamoDB is AWS’s fully managed NoSQL database, capable of delivering single-digit millisecond read and write performance at any scale. DynamoDB uses a key-value and document data model. You provision Read Capacity Units (RCUs) and Write Capacity Units (WCUs) to control throughput, or use on-demand mode to let AWS scale automatically based on actual usage. For caching frequently read DynamoDB items, DynamoDB Accelerator (DAX) provides an in-memory cache that reduces read latency from milliseconds to microseconds.
Amazon ElastiCache provides managed in-memory caching using two engines: Redis and Memcached. Caching frequently accessed database query results or session state dramatically reduces database load and improves application response times. Redis supports persistence, replication, Pub/Sub messaging, and data structures like sorted sets and lists — making it suitable for session storage, leaderboards, and real-time analytics. Memcached is simpler, multi-threaded, and designed for pure horizontal scaling of a distributed cache. For session state storage in a scalable web application, both ElastiCache (Redis) and DynamoDB are common choices. Amazon Redshift is AWS’s managed data warehouse, optimized for analytics on petabyte-scale datasets using columnar storage and massively parallel query processing. Redshift Spectrum extends Redshift’s SQL query capabilities to structured, semi-structured, and unstructured data stored directly in S3.
8. High Availability & Load Balancing
High availability in AWS architecture means designing systems that continue operating even when individual components fail. The key patterns are redundancy (multiple instances across multiple AZs), decoupling (services communicate through queues or load balancers rather than directly), and automation (Auto Scaling replaces unhealthy instances and adjusts capacity to match demand). No single point of failure should be able to bring down your entire application.
AWS Elastic Load Balancing (ELB) automatically distributes incoming traffic across multiple targets — EC2 instances, containers, or IP addresses — in one or more AZs. There are three types: the Application Load Balancer (ALB) operates at Layer 7 (HTTP/HTTPS) and supports path-based and host-based routing, making it ideal for microservices and containerized applications. The Network Load Balancer (NLB) operates at Layer 4 (TCP/UDP) and is designed for extreme performance — it handles millions of requests per second with ultra-low latency, and preserves the client IP address. The Classic Load Balancer is the legacy option that operates at both Layer 4 and 7 but lacks the advanced routing features of the ALB.
To route traffic to on-premises servers alongside cloud instances, configure a target group using IP addresses (rather than instance IDs) with an ALB or NLB — this works because IP-based targets are not limited to AWS instances and can include any routable endpoint, including servers in your data center connected via AWS Direct Connect or VPN.
Stateful applications — where session data is stored in memory on a single server — cannot scale horizontally without session affinity (“sticky sessions”), which defeats the purpose of load balancing. The correct architectural pattern is to make applications stateless: move session state out of the web tier and into a shared, scalable store like DynamoDB or ElastiCache. Each web server then becomes interchangeable, load balancers can freely route requests to any instance, and the application scales linearly. A VPC endpoint for DynamoDB allows your EC2 instances to communicate with DynamoDB privately, without traversing the internet, meeting strict security and compliance requirements.
9. Monitoring & Logging
Amazon CloudWatch is the central monitoring and observability service for AWS. It collects metrics, logs, and events from AWS services and custom applications, and allows you to set alarms, create dashboards, and trigger automated actions. By default, EC2 instances report basic metrics (CPU utilization, network in/out, disk read/write) to CloudWatch at 5-minute intervals. Enabling detailed monitoring reduces this to 1-minute intervals at an additional cost. Some metrics — such as RAM utilization and disk space — are not visible to the AWS hypervisor and must be collected using the CloudWatch Agent installed on the instance and published as custom metrics.
CloudWatch Alarms evaluate metric data against configurable thresholds over a specified time window and take action when the threshold is breached. Actions can include sending an SNS notification, triggering an Auto Scaling policy, or stopping/rebooting an EC2 instance. CloudWatch Logs Insights allows querying log data using a purpose-built query language, making it possible to extract insights from application logs, VPC Flow Logs, Lambda logs, and more.
AWS CloudTrail records every API call made in your AWS account — who made the call, from which IP address, when, and what was changed. This creates a complete audit trail for security investigation, compliance reporting, and troubleshooting. CloudTrail events are stored in S3 and can be streamed to CloudWatch Logs for real-time alerting. Unlike CloudWatch (which monitors performance metrics), CloudTrail focuses on account activity and governance. VPC Flow Logs complement CloudTrail by capturing the network-layer picture: the actual IP traffic flowing to and from your network interfaces, regardless of whether it reached its destination.
10. Other Key Services
Amazon Route 53 is AWS’s highly available and scalable DNS service. It translates human-readable domain names into IP addresses and supports multiple routing policies for sophisticated traffic management: Simple routing directs traffic to a single resource; Weighted routing splits traffic across resources by percentage for A/B testing or gradual migrations; Latency-based routing directs users to the region with the lowest network latency; Failover routing sends traffic to a primary resource and automatically switches to a standby if health checks fail; Geolocation routing sends users to resources based on their geographic location for localization or data residency compliance.
AWS Lambda is a serverless compute service that runs your code in response to events without requiring you to provision or manage servers. Lambda scales automatically from a single request to thousands per second, and you are billed only for actual execution time in 100ms increments — there is no charge when your code is not running. Lambda functions are event-driven: they can be triggered by API Gateway, S3 events, DynamoDB streams, SNS messages, SQS queues, CloudWatch Events, and dozens of other sources. Each Lambda function has a maximum execution timeout (up to 15 minutes), configurable memory (128 MB to 10 GB), and runs in an ephemeral isolated environment.
Amazon API Gateway is a fully managed service for creating, publishing, and securing RESTful and WebSocket APIs at any scale. It handles all the undifferentiated heavy lifting of API management: traffic management, authorization and access control, monitoring, and API versioning. API Gateway integrates natively with Lambda for serverless backends, making it the foundation of most serverless architectures.
Amazon SQS (Simple Queue Service) is a fully managed message queuing service that decouples application components. When a producer writes faster than a consumer can process, SQS buffers the messages — smoothing out traffic spikes and preventing downstream services from being overwhelmed. SQS Standard queues provide maximum throughput with at-least-once delivery and best-effort ordering. SQS FIFO queues guarantee exactly-once processing and strict first-in, first-out ordering, at slightly lower throughput. Amazon SNS (Simple Notification Service) is a pub/sub messaging service that pushes notifications to multiple subscribers simultaneously — useful for fan-out patterns where a single event must trigger multiple downstream actions.
AWS CloudFormation enables Infrastructure as Code (IaC) — you describe your entire AWS infrastructure in JSON or YAML templates, and CloudFormation provisions and manages the resources for you. This makes your infrastructure reproducible, versionable, and auditable. A CloudFormation Stack is a collection of resources provisioned from a single template; ChangeSets preview the impact of template changes before applying them. AWS Elastic Beanstalk is a Platform-as-a-Service (PaaS) that abstracts away infrastructure management — you upload your application code and Beanstalk handles capacity provisioning, load balancing, auto-scaling, and health monitoring. AWS Systems Manager provides operational visibility and control over EC2 instances and on-premises servers, including a Session Manager feature that replaces SSH/RDP with browser-based or CLI-based shell access without opening inbound ports.
Where to go next
- Back to the AWS Solutions Architect overview.
- Look up any service you could not name in the AWS services glossary.
- Sit the 80-item practice exam once two or three note pages are solid.
Last updated Sep 18, 2026