How to read exam questions
SAA-C03 questions are short scenarios with several answers that would technically work. Passing depends as much on reading carefully as on knowing services. This chapter gives you a repeatable method.
Anatomy of a question
A company runs a web application on EC2 instances in a single Availability Zone. The application must remain available if an Availability Zone fails. Which solution meets these requirements with the LEAST operational overhead?
Every question has:
- Context — what exists today.
- Requirements — what must be true (available if an AZ fails).
- The qualifier — the deciding constraint (least operational overhead).
The qualifiers, decoded
| Qualifier | What it usually points to |
|---|---|
| MOST cost-effective / lowest cost | Pay-per-use or serverless, the right storage class, Spot for interruptible work, avoiding over-provisioning, avoiding NAT/inter-AZ/Region data charges |
| LEAST operational overhead | Fully managed and serverless services (Lambda, Fargate, DynamoDB, Aurora Serverless, managed integrations) instead of building on EC2 |
| Highly available | Multiple AZs, load balancers, Auto Scaling, Multi-AZ databases |
| Fault tolerant | Survives failures with no interruption — redundancy everywhere |
| Disaster recovery | Another Region; match the strategy to RPO and RTO |
| Most secure | Least privilege, private networking, encryption with customer-managed keys where control is required |
| Decouple / loosely coupled | SQS, SNS, EventBridge, Step Functions |
| Real time | Kinesis Data Streams (or MSK), WebSockets, DynamoDB Streams |
| Near real time | Kinesis Data Firehose |
| Without changing the application | Infrastructure-level fixes: load balancers, Auto Scaling, RDS Proxy, Storage Gateway, read replicas behind endpoints |
| Minimal latency for global users | CloudFront, Global Accelerator, edge locations, DynamoDB global tables, Aurora Global Database |
A four-step method
- Read the last sentence first. Find the qualifier before reading the story.
- List the hard requirements. Underline numbers (RPO 15 minutes, 10 TB, 2 years), constraints (no internet, must be encrypted with keys the company manages) and words like must or only.
- Eliminate answers that break any requirement — these are usually easy to spot.
- Choose between the survivors using the qualifier and the Well-Architected principles.
Common distractor patterns
- Works, but over-engineered. A multi-Region active-active design when the requirement is just "available if an AZ fails".
- Works, but more operational effort. Running your own database on EC2 when RDS meets the need.
- Right service, wrong feature. "Enable S3 Transfer Acceleration" when the problem is retrieval speed for global users (that's CloudFront).
- Almost right, with one wrong detail. "Use an NLB with path-based routing" — path-based routing is an ALB feature.
- Not possible. "Attach an EBS volume to instances in two AZs" — EBS volumes live in one AZ.
- Manual steps. "Write a script that runs every night…" when a managed feature already does it (lifecycle rules, AWS Backup).
If an answer requires you to build, patch or babysit something that AWS offers as a managed feature, it's rarely the best answer — unless the question explicitly requires that level of control.
Multiple-response questions
- The question tells you how many to choose: "Select TWO" or "Select THREE".
- Each option is usually independently true or false — evaluate them one by one.
- Combinations often form a complete solution ("create a gateway endpoint" + "update the bucket policy").
Time management
130 minutes for 65 questions is two minutes each.
- First pass: answer everything you can within about a minute; flag anything uncertain and move on.
- Second pass: return to flagged questions with fresh eyes.
- Never leave a question blank — there is no penalty for guessing.
Worked example
Back to our opening question. Requirements: survive an AZ failure; least operational overhead.
| Option | Verdict |
|---|---|
| A. Take nightly AMIs and relaunch in another AZ if needed | ✗ Manual recovery, downtime |
| B. Create an Auto Scaling group across two AZs behind an Application Load Balancer | ✓ Automatic, managed, multi-AZ |
| C. Run a second identical instance in another AZ and switch DNS manually | ✗ Manual failover |
| D. Move to a larger instance type | ✗ Doesn't address AZ failure |
Answer: B.
Read the qualifier first, eliminate anything that breaks a requirement, then pick the most managed, simplest design that satisfies everything. That approach alone earns many marks.