The exam, and how to use this handbook
The AWS Certified Solutions Architect – Associate exam (code SAA-C03) checks whether you can design solutions on AWS that are secure, resilient, high-performing and cost-optimized. It is the most popular AWS certification, and it is the best foundation for any cloud architecture, DevOps or forward deployed role. This handbook takes you from zero to exam-ready, then shows how the same ideas apply to real systems.
Exam facts
| Item | Detail |
|---|---|
| Exam code | SAA-C03 |
| Questions | 65 in total: 50 scored + 15 unscored (you can't tell which are unscored) |
| Question types | Multiple choice (1 correct of 4) and multiple response (2+ correct of 5 or more) |
| Time | 130 minutes |
| Scoring | Scaled score from 100 to 1,000; 720 to pass |
| Guessing | No penalty — never leave a question blank |
| Scoring model | Compensatory: you need to pass overall, not each domain |
| Cost | USD 150 (check local pricing and taxes) |
| Delivery | Pearson VUE test centre or online proctored |
| Validity | 3 years |
| Recommended experience | About 1 year of hands-on AWS design experience (not mandatory) |
AWS updates exams, prices and service limits over time. This handbook follows the official SAA-C03 exam guide (version 1.1). Before booking, check the current exam guide on the AWS Certification website.
The four domains
| Domain | Weight | What it asks you to do |
|---|---|---|
| 1. Design Secure Architectures | 30% | Control access, protect workloads and protect data |
| 2. Design Resilient Architectures | 26% | Build loosely coupled, scalable, highly available and recoverable systems |
| 3. Design High-Performing Architectures | 24% | Choose fast, scalable storage, compute, databases, networks and data pipelines |
| 4. Design Cost-Optimized Architectures | 20% | Choose the cheapest design that still meets the requirements |
Every task statement, and where it's covered
| Task statement | Main chapters |
|---|---|
| 1.1 Design secure access to AWS resources | IAM, roles & federation, multi-account |
| 1.2 Design secure workloads and applications | Threat protection, securing workloads, VPC, connectivity |
| 1.3 Determine appropriate data security controls | Encryption & keys, S3 security, backup |
| 2.1 Design scalable and loosely coupled architectures | Auto Scaling, load balancing, messaging, containers, serverless |
| 2.2 Design highly available and/or fault-tolerant architectures | Resilient design, Route 53, RDS, Aurora |
| 3.1 High-performing and/or scalable storage | S3, block & file storage, hybrid storage |
| 3.2 High-performing and elastic compute | EC2, Auto Scaling, containers, serverless |
| 3.3 High-performing database solutions | RDS, Aurora, DynamoDB, caching |
| 3.4 High-performing and/or scalable networks | CloudFront & Global Accelerator, network performance |
| 3.5 High-performing data ingestion and transformation | Streaming, analytics & data lakes |
| 4.1 Cost-optimized storage | S3, backup & archival, cost management |
| 4.2 Cost-optimized compute | EC2 purchasing options, serverless |
| 4.3 Cost-optimized databases | Choosing a database, DynamoDB |
| 4.4 Cost-optimized networks | Network performance & cost, VPC connectivity |
What the exam is really testing
Questions are short business scenarios: "A company needs X, with constraint Y. Which solution meets these requirements MOST cost-effectively?" Several answers usually work; your job is to pick the one that best matches the constraint — cheapest, least operational overhead, most available, most secure. Memorising services isn't enough; you need to know when each one is the best fit. The chapter How to read exam questions teaches this skill.
How to use this handbook
- Read in order the first time. Each chapter builds on the previous ones, starting from zero.
- Do it hands-on. Create a free-tier account and build small things: a VPC with public and private subnets, an EC2 instance behind a load balancer, an S3 static site, a Lambda function behind API Gateway. Delete resources afterwards to avoid charges.
- Use the design chapters (secure, resilient, high-performing, cost-optimized) to connect services to the four domains.
- Practise with scenarios in the last section, then take full-length practice exams under timed conditions.
- Review the cheat sheet in the final days.
An 8-week study plan
| Week | Focus | Chapters |
|---|---|---|
| 1 | Foundations, IAM, multi-account | Start here, Security & identity (first half) |
| 2 | Encryption, threat protection, VPC basics | Rest of Security, VPC fundamentals |
| 3 | Networking in depth | Networking |
| 4 | Compute and serverless | Compute |
| 5 | Storage | Storage |
| 6 | Databases, messaging, analytics | Databases, Integration & analytics |
| 7 | Operations, cost, migration, design domains | Operations, Designing for the four domains |
| 8 | Practice exams, scenarios, weak areas, cheat sheet | Scenarios & real-world use cases |
If you already work with AWS daily, compress this to 3–4 weeks and spend more time on practice questions.
Practice exams are where most learning happens. After each one, review every question — including ones you got right — and write down why each wrong option was wrong.
Services listed in the guide that AWS has since retired or restricted
The exam guide's in-scope list includes a few services that AWS has since retired, closed to new customers or replaced — for example Amazon QLDB, AWS Data Pipeline, Amazon Elastic Transcoder, Amazon Forecast and parts of the AWS Snow Family. You should still know what they do at a high level, because exam questions are slower to change than the services. This handbook notes these cases where they come up.