Solutions Architect – Associate
Official study guide walkthrough
Exam objectives, cloud-computing fundamentals, global infrastructure, security and compliance, and the core service set, aligned with the official SAA-C03 study guide chapters.
Design-level notes for AWS Certified Solutions Architect – Associate (SAA-C03). The course notes build the mental model, the study-guide page covers the blueprint fundamentals, and the exam-tips page is your last pass before the test centre.
5 topics, 21 study points. Everything here is exam-oriented: each point is a fact or a distinction that SAA-C03 items are built on. Test yourself against the practice exam once you can explain a section without re-reading it.
1. Chapter 1: Exam Objectives
The AWS Certified Solutions Architect — Associate exam validates your ability to design distributed systems on AWS that are secure, reliable, performant, and cost-efficient. The exam focuses on architecting decisions, not on writing code or operating systems. There are four major domains: Design Resilient Architectures, Design High-Performing Architectures, Design Secure Applications and Architectures, and Design Cost-Optimized Architectures.
Designing and deploying scalable, highly available, and fault-tolerant systems is the core competency the exam tests. This means understanding how to architect for failure — assuming components will fail and designing systems that automatically detect and recover from those failures without human intervention. Key patterns include multi-AZ deployments, Auto Scaling groups, Elastic Load Balancing, and automated failover for databases and DNS.
The exam tests your ability to select the right AWS service for a given scenario rather than memorizing configuration details. For compute, the choice between EC2, ECS, Lambda, or Elastic Beanstalk depends on the workload type, scaling requirements, and operational model. For storage, the choice between S3, EBS, EFS, and Glacier depends on access patterns, latency requirements, and data lifecycle needs. For databases, the choice between RDS, DynamoDB, ElastiCache, and Redshift depends on data model, consistency requirements, and query patterns.
Cost optimization is a first-class architectural concern on this exam. You are expected to know when Reserved Instances, Spot Instances, or Savings Plans provide the best economics for a given workload. You should understand how to eliminate waste (unused resources, oversized instances), leverage managed services to reduce operational overhead, and use cost allocation tags and AWS Cost Explorer to monitor and manage spending.
2. Cloud Computing Fundamentals
Cloud computing is the on-demand delivery of IT resources — servers, storage, databases, networking, software — over the internet with pay-as-you-go pricing. Instead of owning and maintaining physical data centers and servers, you access computing resources from a cloud provider (like AWS) on an as-needed basis and pay only for what you consume. AWS launched its public cloud services in 2006 with S3 and EC2, fundamentally transforming how organizations build and operate technology infrastructure.
The six core advantages of cloud computing explain why organizations migrate to AWS. First, trading capital expense for variable expense means you pay for actual consumption rather than investing in hardware before you know how much you need. Second, achieving massive economies of scale means AWS can charge less than you would pay to run the same infrastructure yourself, because AWS’s aggregate demand spreads fixed costs across hundreds of thousands of customers. Third, stopping guessing about capacity means you provision exactly what you need and scale up or down within minutes rather than over-investing to handle peak loads that may never materialize.
The fourth advantage is increasing speed and agility — new IT resources are a click away, and the time to make those resources available to developers drops from weeks to minutes. Fifth, focusing on business differentiators means you stop spending money running and managing data centers and can redirect that investment to software that distinguishes your business. Sixth, going global in minutes means deploying your application in multiple AWS regions worldwide takes minutes rather than months, giving your customers lower latency wherever they are.
AWS cloud deployment models range from all-in cloud (all workloads and resources running on AWS) to hybrid deployments (mixing cloud resources with on-premises infrastructure). Hybrid deployments are common for organizations that must keep certain data or applications on-premises due to regulatory requirements, existing software licenses, or latency constraints, while migrating other workloads to cloud for scalability and cost benefits.
3. AWS Global Infrastructure
AWS operates its infrastructure through a global network of Regions, Availability Zones, and Edge Locations. This hierarchy is fundamental to understanding how to design resilient, low-latency architectures. Each layer of the hierarchy provides different types of redundancy and performance characteristics, and choosing the right combination for your workload is a core architectural decision.
An AWS Region is a physical geographic area of the world — such as US East (N. Virginia), EU (Frankfurt), or Asia Pacific (Tokyo). Each Region is completely independent with its own set of AWS services, data, and infrastructure. Data stored in one Region does not automatically replicate to another Region unless you explicitly configure cross-region replication. When choosing a Region, consider data residency and compliance requirements (some regulations require data to remain in a specific country), latency to your end users, service availability (not all services launch in all Regions simultaneously), and cost (pricing varies by Region).
Within each Region, AWS maintains a minimum of three Availability Zones (AZs). An AZ is one or more discrete data centers, each with redundant power, networking, and cooling, physically separated from other AZs by meaningful distances (typically tens of miles) to prevent correlated failures. Despite the physical separation, AZs within a Region are interconnected with high-bandwidth, low-latency private fiber — allowing synchronous replication with sub-millisecond latency. Designing your application across multiple AZs is the primary mechanism for achieving high availability within a Region.
Edge Locations are AWS infrastructure points deployed in major cities around the world — far more numerous than Regions or AZs. Edge Locations are used by CloudFront (CDN), Route 53 (DNS), and AWS Global Accelerator to serve content and route traffic from locations geographically close to end users. Because edge locations cache content locally, end users experience lower latency than if every request had to travel to your origin Region. There are hundreds of edge locations globally, ensuring that users everywhere can access your content with minimal delay.
4. Security & Compliance
The AWS Shared Responsibility Model is the foundational framework for understanding who is responsible for what in cloud security. AWS is responsible for the security “of” the cloud — the physical security of data centers, the global network infrastructure, the virtualization layer (hypervisor), and the managed services themselves. Customers are responsible for the security “in” the cloud — the operating systems they run on EC2, the applications they deploy, the data they store, their IAM configurations, network firewall rules, and encryption settings.
In practice, the boundary shifts depending on which service you use. For EC2 (IaaS), you manage the OS, runtime, application, and data — AWS manages everything below the hypervisor. For managed services like RDS, AWS also manages the OS and database engine patching — you manage the database schema, user access, and encryption settings. For fully managed services like S3 or Lambda, AWS manages nearly all infrastructure concerns — you are responsible primarily for access control and data classification. Understanding this sliding scale is essential for correctly identifying security responsibilities in exam scenarios.
AWS participates in numerous compliance programs that certify its infrastructure and services meet industry-specific security standards. These include SOC 1, SOC 2, and SOC 3 reports for financial and operational controls; PCI DSS for payment card industry requirements; HIPAA for US healthcare data privacy; FedRAMP for US federal government workloads; ISO 27001 for information security management; and many others. When you build on AWS, you inherit the compliance controls AWS has already implemented for its infrastructure — but you are still responsible for implementing and documenting controls within your own application layer to achieve compliance certification.
AWS provides a rich set of native security services. IAM controls identity and access. AWS KMS manages encryption keys for data at rest. AWS Secrets Manager and Parameter Store manage secrets and configuration securely. AWS Shield provides DDoS protection (with Shield Advanced offering more sophisticated mitigation and 24/7 support). AWS WAF (Web Application Firewall) filters malicious web traffic based on customizable rules. Amazon Inspector performs automated security assessments of EC2 instances and container images. AWS Security Hub aggregates findings from multiple security services into a unified dashboard for centralized visibility.
5. Core AWS Services
AWS organizes its hundreds of services into logical categories. For the Solutions Architect exam, mastering the core services in compute, storage, database, networking, and management is essential — these services appear in the vast majority of architectural scenarios you will encounter.
The core compute services are: EC2 (virtual machines), AWS Lambda (serverless functions executed on demand), Amazon ECS and EKS (container orchestration), and AWS Elastic Beanstalk (PaaS for deploying web applications). Choosing between them depends on your control vs. operational overhead tradeoff — EC2 gives maximum control, Lambda gives minimum overhead for event-driven workloads, containers sit in between for portable and scalable microservices.
The core storage services are: S3 (object storage for virtually any data type at unlimited scale), EBS (persistent block storage attached to EC2 instances), Amazon EFS (managed NFS file system shared across multiple EC2 instances), AWS Glacier (long-term archival storage at very low cost), and AWS Storage Gateway (hybrid storage connecting on-premises environments to cloud storage). Each service fits a different access pattern and performance profile.
The core database services are: RDS (managed relational databases), Amazon Aurora (AWS-native high-performance relational database), DynamoDB (serverless NoSQL at any scale), Amazon ElastiCache (managed in-memory caching), Amazon Redshift (data warehouse for analytics), and Amazon Neptune (managed graph database). Selecting the right database is one of the most common and consequential architectural decisions — always match the database type to the data model and access patterns of the application.
The core networking services are: VPC (private network isolation), Amazon Route 53 (DNS and traffic routing), Amazon CloudFront (global CDN), and AWS Direct Connect (dedicated private network connection from on-premises to AWS). The core management and governance services are: CloudWatch (monitoring and observability), CloudFormation (infrastructure as code), CloudTrail (API audit logging), AWS Config (resource configuration history and compliance), and AWS Systems Manager (operational management of EC2 and on-premises instances). Security services include IAM, AWS KMS, AWS Shield, AWS WAF, and Amazon Inspector.
Where to go next
- Back to the AWS Solutions Architect overview.
- Look up any service you could not name in the AWS services glossary.
- Sit the 80-item practice exam once two or three note pages are solid.
Dernière mise à jour le 18 sept. 2026