Handbook · 48 chapters · ~129 min
AWS Solutions Architect Handbook
A complete path from zero to passing the AWS Certified Solutions Architect – Associate (SAA-C03) exam — every domain and task statement in the official exam guide, explained from first principles, then practised with exam-style scenarios and real-world architectures.
Start reading →Start here
01 · 4 minThe exam, and how to use this handbookSAA-C03 format, scoring, the four domains, every task statement, and a study plan.02 · 4 minCloud and AWS fundamentalsCloud concepts, Regions and Availability Zones, edge locations, shared responsibility and pricing basics.03 · 2 minThe AWS Well-Architected FrameworkThe six pillars and design principles that the exam's four domains are built on.04 · 3 minHow to read exam questionsDecode requirement keywords, eliminate distractors and handle multiple-response questions.
Security & identity
05 · 3 minIAM fundamentalsUsers, groups, roles, policies, the root user, MFA and how permissions are evaluated.06 · 3 minRoles, federation and identity servicesSTS, cross-account access, IAM Identity Center, Directory Service and Amazon Cognito.07 · 2 minMulti-account strategy and governanceAWS Organizations, SCPs, Control Tower, consolidated billing, RAM and Service Catalog.08 · 3 minEncryption, keys, certificates and secretsKMS, CloudHSM, ACM, Secrets Manager and Parameter Store — protecting data at rest and in transit.09 · 3 minThreat protection and security servicesShield, WAF, Firewall Manager, Network Firewall, GuardDuty, Inspector, Macie, Security Hub and friends.10 · 3 minSecuring workloads and applicationsSecurity groups vs NACLs, network segmentation, private access to services, and database security.
Networking
11 · 3 minVPC fundamentalsCIDR blocks, subnets, route tables, internet and NAT gateways, and IPv6.12 · 3 minConnecting VPCs, services and on-premises networksPeering, Transit Gateway, VPC endpoints, PrivateLink, Site-to-Site VPN, Client VPN and Direct Connect.13 · 2 minAmazon Route 53DNS basics, record types, alias records, routing policies, health checks and private zones.14 · 2 minElastic Load BalancingApplication, Network and Gateway Load Balancers — features, health checks and choosing between them.15 · 2 minCloudFront and Global AcceleratorEdge caching, origin protection, signed URLs, edge functions — and when Global Accelerator wins instead.16 · 3 minNetwork performance and costData transfer charges, NAT design, endpoints, placement groups, enhanced networking and throttling.
Compute
17 · 3 minEC2 fundamentalsInstance families and sizes, AMIs, storage options, user data, metadata and hibernation.18 · 2 minEC2 purchasing optionsOn-Demand, Savings Plans, Reserved Instances, Spot, Dedicated options and Capacity Reservations.19 · 2 minAuto ScalingAuto Scaling groups, launch templates, scaling policies, health checks and lifecycle hooks.20 · 2 minContainers on AWSECS, EKS, Fargate, ECR, ECS/EKS Anywhere — and how to move applications into containers.21 · 3 minServerless and other compute optionsLambda, API Gateway, Step Functions, AppSync, Elastic Beanstalk, Batch, and hybrid/edge compute.
Storage
22 · 3 minAmazon S3 essentialsBuckets and objects, storage classes, lifecycle, versioning, replication, performance and features.23 · 2 minSecuring Amazon S3Block Public Access, bucket policies, Object Ownership, access points, encryption and VPC endpoints.24 · 3 minBlock and file storageEBS volume types and snapshots, instance store, EFS, and the FSx family.25 · 2 minHybrid storage and data transferStorage Gateway, DataSync, Transfer Family, the Snow Family and choosing a transfer method.26 · 2 minBackup, archival and data protectionAWS Backup, snapshots, retention, cross-Region copies, immutable backups and archive tiers.
Databases
27 · 3 minAmazon RDSManaged relational databases — engines, Multi-AZ, read replicas, backups, encryption and RDS Proxy.28 · 2 minAmazon AuroraCloud-native MySQL/PostgreSQL — shared storage, replicas, endpoints, Global Database and Serverless v2.29 · 3 minAmazon DynamoDBServerless NoSQL — keys, capacity modes, indexes, DAX, streams, global tables and backups.30 · 2 minCaching and purpose-built databasesElastiCache strategies, plus DocumentDB, Neptune, Keyspaces, Timestream, Redshift, OpenSearch and more.31 · 2 minChoosing a databaseA decision guide across relational, NoSQL and analytical engines — plus database migration.
Integration, data & analytics
32 · 3 minDecoupling with queues, topics and eventsSQS, SNS, EventBridge, Amazon MQ and AppFlow — loose coupling and event-driven design.33 · 2 minStreaming and data ingestionKinesis Data Streams, Data Firehose, Managed Service for Apache Flink, MSK and Kinesis Video Streams.34 · 2 minAnalytics and data lakesS3 data lakes, Glue, Athena, Lake Formation, EMR, Redshift, QuickSight and OpenSearch.35 · 2 minAI and machine learning servicesThe managed AI services the exam lists — what each does and the clue words that point to it.
Operations, cost & migration
36 · 3 minMonitoring, logging and auditingCloudWatch, X-Ray, CloudTrail, Config, Trusted Advisor, Compute Optimizer and the Health Dashboard.37 · 2 minAutomation and infrastructure as codeCloudFormation, Systems Manager, Service Catalog, Proton, Elastic Beanstalk and immutable infrastructure.38 · 2 minCost management and optimisationCost Explorer, Budgets, Cost and Usage Report, tagging, consolidated billing and a cost-lever checklist.39 · 3 minMigrating to AWSThe 7 Rs, discovery and planning tools, Application Migration Service, DMS, VMware Cloud and data transfer.
Designing for the four domains
40 · 2 minDomain 1: Designing secure architecturesTask statements 1.1–1.3 turned into a checklist of patterns and decisions.41 · 3 minDomain 2: Designing resilient architecturesLoose coupling, high availability, fault tolerance and the four disaster recovery strategies.42 · 2 minDomain 3: Designing high-performing architecturesStorage, compute, database, network and data-ingestion performance — task statements 3.1–3.5.43 · 2 minDomain 4: Designing cost-optimized architecturesCost-optimized storage, compute, databases and networks — task statements 4.1–4.4.
Scenarios & real-world use cases
44 · 7 minScenario practice: security and resilience12 exam-style questions on Domains 1 and 2, with hidden answers and full explanations.45 · 6 minScenario practice: performance and cost12 exam-style questions on Domains 3 and 4, with hidden answers and full explanations.46 · 2 minReal-world architecturesEight reference architectures — what to build, why each service is there, and how it maps to the exam.47 · 3 minExam cheat sheetKeyword-to-service mappings, numbers worth remembering and the classic "versus" comparisons.48 · 2 minThe final week and exam dayHow to revise, book, sit the exam, manage time — and what to do after you pass.
More handbooks by Bipin Singh: browse the library →