Study guide · Core notes

Solutions Architect Notes: choose the design that fits

Reference notes for SAA-C03: who can reach a resource, how the design survives failure, which storage and database meet the speed, and which lever actually changes the bill.

Exam guide: SAA-C0310 modulesReviewed October 2026

How to read these notes: Items tagged Extra are outside the SAA-C03 in-scope list, such as Amazon Lightsail and the AWS CDK. Learn the unmarked items first. New to the exam? Start with the overview for the format and domain weights. Foundational service names are in the Cloud Practitioner notes.

Module 1: Secure access

Domain 1 starts with who is allowed to call an API. Least privilege means the identity can do the task in front of it and nothing else. The AWS account root user is for a few account-level tasks only: turn on MFA, do not use it daily, and do not create access keys for it.

Identity tools on SAA-C03. A control that sets a maximum is not the same as a control that grants access.
ToolUse it whenIt does not
IAM userA long-lived identity in one account. Prefer a role for anything that can assume one.Travel cleanly across accounts. Access keys on users are a common finding.
IAM role and STSAn application, a federated user, or another account needs temporary credentials.Stay valid forever. The credentials expire.
Identity-based policyYou attach allow or deny to a user, group, or role.By itself, cross a resource policy or an SCP that denies the same action.
Resource policyThe resource must name who can use it, such as an S3 bucket policy or a role trust policy.Replace the identity policy. Both sides can be required.
IAM Identity CenterYour workforce needs single sign-on into many AWS accounts.Sign up customers of your application. That is Amazon Cognito.
Service control policyA member account must be blocked from an action even if an IAM policy allows it.Grant access. SCPs do not apply to the management account, and they never add a permission that IAM did not allow.
Permission boundaryA delegated admin may create roles, but those roles must not exceed a ceiling you set.Grant access by itself. It is another maximum.

Cross-account access is a role in the destination account, a trust policy that names the source account, and an identity policy in the source account that allows sts:AssumeRole. AWS Resource Access Manager shares a supported resource, such as a subnet or a resolver rule, instead of copying it. AWS Control Tower is the landing zone that sets up the multi-account structure. AWS Config records whether resources drift from a rule. AWS CloudTrail records who called which API.

Module 2: Secure workloads and network paths

Place the resource, then decide which traffic is allowed to reach it.

Subnet placement

Public subnets have a route to an internet gateway. Private subnets do not. Load balancers that receive internet traffic sit in public subnets. Application instances and databases sit in private subnets.

Security group and network ACL

A security group is stateful, attached to the elastic network interface, and supports allow rules. Return traffic is allowed automatically. A network ACL is stateless, attached to the subnet, and can deny. You must allow both directions.

Admin access

Systems Manager Session Manager reaches an instance through the AWS API. You do not open port 22 to the internet, and the session can be recorded. A bastion host is the older pattern and adds an instance to patch.

Edge threats

AWS WAF inspects HTTP and can block SQL injection, cross-site scripting, and rate spikes. AWS Shield Standard is included and covers common DDoS. Shield Advanced is the paid plan with more visibility and response support. Amazon GuardDuty reports suspicious activity. It does not drop the packet for you.

Secrets

AWS Secrets Manager stores a secret and can rotate it, including database credentials. Systems Manager Parameter Store is the lighter place for configuration and for secrets that you rotate yourself.

Private connectivity

A site-to-site VPN encrypts over the internet. AWS Direct Connect is a dedicated connection and is not encrypted by itself. AWS PrivateLink exposes a service through an interface endpoint so the traffic stays on the AWS network.

Amazon Inspector looks for vulnerabilities and unintended network exposure. Amazon Macie looks for sensitive data in Amazon S3. AWS Security Hub collects findings. Amazon Detective helps you investigate a finding. These are different jobs.

Module 3: Data security

Encrypt where the data sits, and encrypt the path it travels. AWS KMS is the default for keys that AWS services can use. A customer managed key lets you write the key policy and turn on yearly automatic rotation. An AWS managed key is rotated for you and is tied to one service. AWS CloudHSM is a dedicated hardware module when you must control the key material more directly than KMS allows.

AWS Certificate Manager issues public TLS certificates for services that integrate with it, including Elastic Load Balancing, Amazon CloudFront, and Amazon API Gateway. Those public certificates are not exportable, so you cannot install one on an EC2 instance yourself. Data in transit between your users and those integrated services uses TLS. Data at rest uses KMS encryption on S3, EBS, RDS, and similar services.

Protect the copy as well as the original. S3 Versioning and replication, RDS automated backups, and AWS Backup are how you recover from deletion or corruption, which is a security outcome as well as a resilience one. Rotate keys and renew certificates before they expire. Amazon Macie is how you find which S3 buckets already hold sensitive data so you can tighten the bucket policy.

Module 4: Loose coupling and scale

A tier that can grow on its own should not wait on a tier that cannot.

Integration choices. Pick the one whose delivery promise matches the workload.
NeedServiceDesign point
Hold work until a consumer is freeAmazon SQSStandard queues are at-least-once. FIFO queues add ordering and deduplication. A dead-letter queue keeps messages that failed too many times.
Tell many subscribers at onceAmazon SNSFan-out. A common pattern is one topic and a queue per downstream service.
Route events from AWS servicesAmazon EventBridgeRules match events and send them on. It is also the scheduler when you do not want a server waking up to check the clock.
A workflow with retries and branchesAWS Step FunctionsOrchestration. It is not a buffer for a traffic spike.
An HTTP API in front of codeAmazon API Gateway and AWS LambdaUse this when each request is short. Lambda has a 15-minute maximum.
Containers without managing serversAWS Fargate on Amazon ECS or Amazon EKSFargate is the compute. ECS and EKS are the orchestrators. Amazon ECR stores the image.

Horizontal scaling adds instances. Vertical scaling replaces an instance with a larger one and usually involves downtime. Stateless instances belong in an Auto Scaling group behind a load balancer: any instance can serve any request because session data lives in Amazon ElastiCache or Amazon DynamoDB, not on the instance disk. Put session state on the instance and scale-in will drop users.

Module 5: High availability and disaster recovery

An Availability Zone failure and a Region failure are different designs. Multi-AZ means at least two zones in one Region, a load balancer or a managed Multi-AZ database, and an Auto Scaling group that can replace an instance. Multi-Region means you have decided the business can pay for a second copy because a whole Region might be unavailable, users are far away, or data must stay in a specific geography.

Recovery strategies named in the SAA-C03 exam guide, from the longest recovery to the shortest.
StrategyWhat is already runningTradeoff
Backup and restoreBackups onlyLowest cost. Highest RPO and RTO, because you rebuild after the event.
Pilot lightThe critical core, smallYou scale the rest when you fail over. Faster than a restore, still not instant.
Warm standbyA full environment at reduced sizeYou scale up the copy that is already serving or ready to serve.
Active-activeFull capacity in more than one placeLowest RTO. Highest cost. Both sides take traffic.

RPO is how much data you can afford to lose, measured in time. RTO is how long the service can be down. A synchronous Multi-AZ database aims at a very small RPO inside one Region. A cross-Region read replica is asynchronous, so the RPO is the replication lag, and promotion is a step you plan.

Amazon RDS Multi-AZ keeps a standby and fails over the endpoint. That standby is not a read endpoint. Read replicas are for read traffic and are asynchronous. Amazon Aurora stores six copies across three Availability Zones and can fail over to a replica. Amazon RDS Proxy pools connections so a fleet of Lambda functions does not exhaust the database. Amazon Route 53 failover routing plus health checks sends users to the healthy endpoint. Immutable infrastructure means you launch a new image rather than patching one server in place.

Module 6: Storage and compute performance

Name the access pattern before you name the service.

Object, file, block

Amazon S3 is object storage. Amazon EBS is a block volume for one instance, except multi-attach on supported io1 and io2 volumes. Amazon EFS is a shared POSIX file system. Amazon FSx is the managed file system when you need Windows, Lustre, NetApp ONTAP, or OpenZFS.

EBS volume type

gp3 is the general SSD and lets you set IOPS separately from size. io2 is for sustained high IOPS. st1 is a throughput HDD for large sequential data and is not a boot volume. Instance store is local and disappears when the instance stops.

Instance family

C is compute optimized. R is memory optimized. I and D are storage optimized. M is general purpose. T is burstable and a poor fit for steady high CPU. P and G are for GPU work.

Scaling signal

Target tracking follows a metric such as CPU. Scheduled scaling matches a known clock, such as office hours. Step scaling reacts to the size of the breach. Decouple with a queue when the workers should scale on queue depth, not on the web tier's CPU.

Lambda performance is tied to memory: more memory also means more CPU. Raise memory when the function is slow, and watch the timeout. For a long-running or always-on container, Fargate or EC2 is the better compute. AWS Batch fits large job queues. Amazon EMR fits Spark or Hadoop clusters you want to size yourself.

Module 7: Database performance

Use Amazon RDS or Amazon Aurora when you need relational joins and transactions. Aurora is the higher-throughput MySQL- and PostgreSQL-compatible option, with many read replicas and storage that already spans Availability Zones. Use Amazon DynamoDB when the access is a key lookup at any scale and you do not need joins. Amazon DocumentDB is the document database. Amazon Neptune is the graph database. Amazon Keyspaces is the Cassandra-compatible service. Amazon Redshift is the warehouse, not the transactional store.

Read replicas scale reads. They do not replace Multi-AZ failover. Amazon ElastiCache holds hot query results. Redis gives you replication and richer data structures. Memcached is the simpler cache. DynamoDB Accelerator (DAX) is the cache in front of DynamoDB. RDS Proxy is for connection spikes, especially from Lambda.

On-demand capacity on DynamoDB or Aurora Serverless fits a spiky or unpredictable load. Provisioned capacity is cheaper when you know the rate. A cache is the first thing to add when the same reads hit a database that is otherwise the right engine.

Module 8: Network performance

The path is part of the latency budget.

Network services that show up when the question is about speed or reach, not only about security.
ChoicePick it for
Application Load BalancerHTTP and HTTPS, with routing by host or path. AWS WAF attaches here.
Network Load BalancerTCP or UDP at high packet rates, and static IP addresses.
Gateway Load BalancerTraffic that must pass through a fleet of virtual appliances.
Amazon CloudFrontCaching HTTP content at edge locations.
AWS Global AcceleratorStatic anycast addresses and the AWS network path for TCP or UDP. Not a cache.
AWS Direct ConnectA consistent dedicated link. Add a VPN if you also need encryption.
AWS Transit GatewayMany VPCs and on-premises networks in a hub. VPC peering is one-to-one and not transitive.

Put the compute in the same Region as the data, and in the same Availability Zone when latency and cross-AZ data transfer both matter. Amazon Route 53 latency-based routing sends a user to the Region that answers faster. Geolocation routing follows rules you write about where the user is.

Module 9: Ingestion and transformation

Amazon Kinesis Data Streams is the durable stream you consume at your own pace, with shards you size. Amazon Data Firehose loads a stream into Amazon S3, Amazon Redshift, or Amazon OpenSearch Service with less for you to run. AWS Glue catalogs data and transforms it, including from CSV to a columnar format such as Parquet. Amazon Athena queries data that already sits in S3. Amazon EMR is the cluster when Glue or Athena is not enough control. AWS Lake Formation adds permissions around that lake.

For moving data in, AWS DataSync copies files online to S3, EFS, or FSx. The AWS Snow Family moves large sets offline when the network would take too long. AWS Storage Gateway keeps a hybrid file, volume, or tape front end. AWS Transfer Family accepts SFTP, FTPS, or FTP into S3 or EFS. AWS Database Migration Service copies a database and can keep replicating changes. Secure the ingestion path the same way as any other path: private endpoints, least-privilege roles, and encryption.

Module 10: Cost-optimized design

Change the purchasing option, the storage class, or the network path. Do not drop a requirement the stem still states.

Compute purchasing. Match the commit to how steady the workload is.
OptionFitsWatch out
On-DemandShort-lived or unpredictable workSteady production left on On-Demand is the expensive default.
SpotFault-tolerant, interruptible jobsAWS can reclaim the capacity. Do not use it for the only copy of state.
Savings PlansA commit to spend per hour. Compute Savings Plans cover EC2, Fargate, and Lambda. EC2 Instance Savings Plans are narrower and can discount more.A commit you do not use is still billed.
Reserved InstancesA steady EC2 or RDS footprint with a one-year or three-year termStandard reservations are less flexible than convertible ones.
Dedicated HostA license that cares about sockets or coresIt is not the cheap way to get a normal instance.

Storage follows the read pattern. S3 Standard for frequent reads. Standard-IA or Glacier Instant Retrieval when reads are rare and must still be fast. Glacier Flexible Retrieval and Deep Archive when waiting is acceptable and the object is cold. Intelligent-Tiering when you do not know the pattern. Lifecycle rules move objects for you. gp3 is the cost-effective general EBS volume. io2 is justified by an IOPS number, not by habit. Delete unattached volumes and snapshots you no longer need.

Network cost is often a NAT gateway. One NAT gateway is cheaper and is a single point of failure. One per Availability Zone is more resilient and costs more. A gateway VPC endpoint for S3 or DynamoDB removes that traffic from the NAT bill. CloudFront can stop repeated requests from all hitting the origin. Data transfer into AWS is generally free. Data transfer out, and data transfer between Regions, is charged. AWS Compute Optimizer suggests a smaller or better-fitting instance. AWS Cost Explorer reviews spend. AWS Budgets alerts. The Cost and Usage Report is the line-item export. Cost allocation tags make those tools useful across accounts.

Extra Amazon Lightsail, the AWS CDK, AWS CodeBuild, AWS CodeCommit, AWS CodeDeploy, and AWS Fault Injection Simulator are on the SAA-C03 out-of-scope list. CloudFormation remains the in-scope way to describe a stack.

Frequently asked questions

Does a service control policy grant access?

No. A service control policy sets the maximum permissions for member accounts in AWS Organizations. An identity still needs an IAM policy that allows the action. An explicit deny in an SCP overrides an allow.

What is the difference between Multi-AZ and a second Region?

Multi-AZ keeps a workload available when one Availability Zone fails. A second Region is for a regional outage, a distant user base, or a data-residency split. Disaster-recovery strategies such as pilot light and warm standby are multi-Region designs.

When do you choose a gateway VPC endpoint instead of a NAT gateway?

Use a gateway VPC endpoint when private subnets need Amazon S3 or Amazon DynamoDB and do not need the public internet. A NAT gateway can reach those services too, and it charges for the data it processes.

Continue the AWS Solutions Architect study path

Drill the distinctions, then test them under a timer.

AWS Solutions Architect hub →
Available

Overview

Exam format, the 720 passing score, domain weights, and a study plan.

Available · You are here

Core Notes

Reference notes for access, resilience, performance choices, and cost levers.

Available

Practice Exams

200 original questions with custom exams, explanations, and a score report by domain.

Related Tools

Useful companions while you study.

All study topics →