Subnet placement
Public subnets have a route to an internet gateway. Private subnets do not. Load balancers that receive internet traffic sit in public subnets. Application instances and databases sit in private subnets.
Study guide · Core notes
Reference notes for SAA-C03: who can reach a resource, how the design survives failure, which storage and database meet the speed, and which lever actually changes the bill.
How to read these notes: Items tagged Extra are outside the SAA-C03 in-scope list, such as Amazon Lightsail and the AWS CDK. Learn the unmarked items first. New to the exam? Start with the overview for the format and domain weights. Foundational service names are in the Cloud Practitioner notes.
Domain 1 starts with who is allowed to call an API. Least privilege means the identity can do the task in front of it and nothing else. The AWS account root user is for a few account-level tasks only: turn on MFA, do not use it daily, and do not create access keys for it.
| Tool | Use it when | It does not |
|---|---|---|
| IAM user | A long-lived identity in one account. Prefer a role for anything that can assume one. | Travel cleanly across accounts. Access keys on users are a common finding. |
| IAM role and STS | An application, a federated user, or another account needs temporary credentials. | Stay valid forever. The credentials expire. |
| Identity-based policy | You attach allow or deny to a user, group, or role. | By itself, cross a resource policy or an SCP that denies the same action. |
| Resource policy | The resource must name who can use it, such as an S3 bucket policy or a role trust policy. | Replace the identity policy. Both sides can be required. |
| IAM Identity Center | Your workforce needs single sign-on into many AWS accounts. | Sign up customers of your application. That is Amazon Cognito. |
| Service control policy | A member account must be blocked from an action even if an IAM policy allows it. | Grant access. SCPs do not apply to the management account, and they never add a permission that IAM did not allow. |
| Permission boundary | A delegated admin may create roles, but those roles must not exceed a ceiling you set. | Grant access by itself. It is another maximum. |
Cross-account access is a role in the destination account, a trust policy that names the source account, and an identity policy in the source account that allows sts:AssumeRole. AWS Resource Access Manager shares a supported resource, such as a subnet or a resolver rule, instead of copying it. AWS Control Tower is the landing zone that sets up the multi-account structure. AWS Config records whether resources drift from a rule. AWS CloudTrail records who called which API.
Place the resource, then decide which traffic is allowed to reach it.
Public subnets have a route to an internet gateway. Private subnets do not. Load balancers that receive internet traffic sit in public subnets. Application instances and databases sit in private subnets.
A security group is stateful, attached to the elastic network interface, and supports allow rules. Return traffic is allowed automatically. A network ACL is stateless, attached to the subnet, and can deny. You must allow both directions.
Systems Manager Session Manager reaches an instance through the AWS API. You do not open port 22 to the internet, and the session can be recorded. A bastion host is the older pattern and adds an instance to patch.
AWS WAF inspects HTTP and can block SQL injection, cross-site scripting, and rate spikes. AWS Shield Standard is included and covers common DDoS. Shield Advanced is the paid plan with more visibility and response support. Amazon GuardDuty reports suspicious activity. It does not drop the packet for you.
AWS Secrets Manager stores a secret and can rotate it, including database credentials. Systems Manager Parameter Store is the lighter place for configuration and for secrets that you rotate yourself.
A site-to-site VPN encrypts over the internet. AWS Direct Connect is a dedicated connection and is not encrypted by itself. AWS PrivateLink exposes a service through an interface endpoint so the traffic stays on the AWS network.
Amazon Inspector looks for vulnerabilities and unintended network exposure. Amazon Macie looks for sensitive data in Amazon S3. AWS Security Hub collects findings. Amazon Detective helps you investigate a finding. These are different jobs.
Encrypt where the data sits, and encrypt the path it travels. AWS KMS is the default for keys that AWS services can use. A customer managed key lets you write the key policy and turn on yearly automatic rotation. An AWS managed key is rotated for you and is tied to one service. AWS CloudHSM is a dedicated hardware module when you must control the key material more directly than KMS allows.
AWS Certificate Manager issues public TLS certificates for services that integrate with it, including Elastic Load Balancing, Amazon CloudFront, and Amazon API Gateway. Those public certificates are not exportable, so you cannot install one on an EC2 instance yourself. Data in transit between your users and those integrated services uses TLS. Data at rest uses KMS encryption on S3, EBS, RDS, and similar services.
Protect the copy as well as the original. S3 Versioning and replication, RDS automated backups, and AWS Backup are how you recover from deletion or corruption, which is a security outcome as well as a resilience one. Rotate keys and renew certificates before they expire. Amazon Macie is how you find which S3 buckets already hold sensitive data so you can tighten the bucket policy.
A tier that can grow on its own should not wait on a tier that cannot.
| Need | Service | Design point |
|---|---|---|
| Hold work until a consumer is free | Amazon SQS | Standard queues are at-least-once. FIFO queues add ordering and deduplication. A dead-letter queue keeps messages that failed too many times. |
| Tell many subscribers at once | Amazon SNS | Fan-out. A common pattern is one topic and a queue per downstream service. |
| Route events from AWS services | Amazon EventBridge | Rules match events and send them on. It is also the scheduler when you do not want a server waking up to check the clock. |
| A workflow with retries and branches | AWS Step Functions | Orchestration. It is not a buffer for a traffic spike. |
| An HTTP API in front of code | Amazon API Gateway and AWS Lambda | Use this when each request is short. Lambda has a 15-minute maximum. |
| Containers without managing servers | AWS Fargate on Amazon ECS or Amazon EKS | Fargate is the compute. ECS and EKS are the orchestrators. Amazon ECR stores the image. |
Horizontal scaling adds instances. Vertical scaling replaces an instance with a larger one and usually involves downtime. Stateless instances belong in an Auto Scaling group behind a load balancer: any instance can serve any request because session data lives in Amazon ElastiCache or Amazon DynamoDB, not on the instance disk. Put session state on the instance and scale-in will drop users.
An Availability Zone failure and a Region failure are different designs. Multi-AZ means at least two zones in one Region, a load balancer or a managed Multi-AZ database, and an Auto Scaling group that can replace an instance. Multi-Region means you have decided the business can pay for a second copy because a whole Region might be unavailable, users are far away, or data must stay in a specific geography.
| Strategy | What is already running | Tradeoff |
|---|---|---|
| Backup and restore | Backups only | Lowest cost. Highest RPO and RTO, because you rebuild after the event. |
| Pilot light | The critical core, small | You scale the rest when you fail over. Faster than a restore, still not instant. |
| Warm standby | A full environment at reduced size | You scale up the copy that is already serving or ready to serve. |
| Active-active | Full capacity in more than one place | Lowest RTO. Highest cost. Both sides take traffic. |
RPO is how much data you can afford to lose, measured in time. RTO is how long the service can be down. A synchronous Multi-AZ database aims at a very small RPO inside one Region. A cross-Region read replica is asynchronous, so the RPO is the replication lag, and promotion is a step you plan.
Amazon RDS Multi-AZ keeps a standby and fails over the endpoint. That standby is not a read endpoint. Read replicas are for read traffic and are asynchronous. Amazon Aurora stores six copies across three Availability Zones and can fail over to a replica. Amazon RDS Proxy pools connections so a fleet of Lambda functions does not exhaust the database. Amazon Route 53 failover routing plus health checks sends users to the healthy endpoint. Immutable infrastructure means you launch a new image rather than patching one server in place.
Name the access pattern before you name the service.
Amazon S3 is object storage. Amazon EBS is a block volume for one instance, except multi-attach on supported io1 and io2 volumes. Amazon EFS is a shared POSIX file system. Amazon FSx is the managed file system when you need Windows, Lustre, NetApp ONTAP, or OpenZFS.
gp3 is the general SSD and lets you set IOPS separately from size. io2 is for sustained high IOPS. st1 is a throughput HDD for large sequential data and is not a boot volume. Instance store is local and disappears when the instance stops.
C is compute optimized. R is memory optimized. I and D are storage optimized. M is general purpose. T is burstable and a poor fit for steady high CPU. P and G are for GPU work.
Target tracking follows a metric such as CPU. Scheduled scaling matches a known clock, such as office hours. Step scaling reacts to the size of the breach. Decouple with a queue when the workers should scale on queue depth, not on the web tier's CPU.
Lambda performance is tied to memory: more memory also means more CPU. Raise memory when the function is slow, and watch the timeout. For a long-running or always-on container, Fargate or EC2 is the better compute. AWS Batch fits large job queues. Amazon EMR fits Spark or Hadoop clusters you want to size yourself.
Use Amazon RDS or Amazon Aurora when you need relational joins and transactions. Aurora is the higher-throughput MySQL- and PostgreSQL-compatible option, with many read replicas and storage that already spans Availability Zones. Use Amazon DynamoDB when the access is a key lookup at any scale and you do not need joins. Amazon DocumentDB is the document database. Amazon Neptune is the graph database. Amazon Keyspaces is the Cassandra-compatible service. Amazon Redshift is the warehouse, not the transactional store.
Read replicas scale reads. They do not replace Multi-AZ failover. Amazon ElastiCache holds hot query results. Redis gives you replication and richer data structures. Memcached is the simpler cache. DynamoDB Accelerator (DAX) is the cache in front of DynamoDB. RDS Proxy is for connection spikes, especially from Lambda.
On-demand capacity on DynamoDB or Aurora Serverless fits a spiky or unpredictable load. Provisioned capacity is cheaper when you know the rate. A cache is the first thing to add when the same reads hit a database that is otherwise the right engine.
The path is part of the latency budget.
| Choice | Pick it for |
|---|---|
| Application Load Balancer | HTTP and HTTPS, with routing by host or path. AWS WAF attaches here. |
| Network Load Balancer | TCP or UDP at high packet rates, and static IP addresses. |
| Gateway Load Balancer | Traffic that must pass through a fleet of virtual appliances. |
| Amazon CloudFront | Caching HTTP content at edge locations. |
| AWS Global Accelerator | Static anycast addresses and the AWS network path for TCP or UDP. Not a cache. |
| AWS Direct Connect | A consistent dedicated link. Add a VPN if you also need encryption. |
| AWS Transit Gateway | Many VPCs and on-premises networks in a hub. VPC peering is one-to-one and not transitive. |
Put the compute in the same Region as the data, and in the same Availability Zone when latency and cross-AZ data transfer both matter. Amazon Route 53 latency-based routing sends a user to the Region that answers faster. Geolocation routing follows rules you write about where the user is.
Amazon Kinesis Data Streams is the durable stream you consume at your own pace, with shards you size. Amazon Data Firehose loads a stream into Amazon S3, Amazon Redshift, or Amazon OpenSearch Service with less for you to run. AWS Glue catalogs data and transforms it, including from CSV to a columnar format such as Parquet. Amazon Athena queries data that already sits in S3. Amazon EMR is the cluster when Glue or Athena is not enough control. AWS Lake Formation adds permissions around that lake.
For moving data in, AWS DataSync copies files online to S3, EFS, or FSx. The AWS Snow Family moves large sets offline when the network would take too long. AWS Storage Gateway keeps a hybrid file, volume, or tape front end. AWS Transfer Family accepts SFTP, FTPS, or FTP into S3 or EFS. AWS Database Migration Service copies a database and can keep replicating changes. Secure the ingestion path the same way as any other path: private endpoints, least-privilege roles, and encryption.
Change the purchasing option, the storage class, or the network path. Do not drop a requirement the stem still states.
| Option | Fits | Watch out |
|---|---|---|
| On-Demand | Short-lived or unpredictable work | Steady production left on On-Demand is the expensive default. |
| Spot | Fault-tolerant, interruptible jobs | AWS can reclaim the capacity. Do not use it for the only copy of state. |
| Savings Plans | A commit to spend per hour. Compute Savings Plans cover EC2, Fargate, and Lambda. EC2 Instance Savings Plans are narrower and can discount more. | A commit you do not use is still billed. |
| Reserved Instances | A steady EC2 or RDS footprint with a one-year or three-year term | Standard reservations are less flexible than convertible ones. |
| Dedicated Host | A license that cares about sockets or cores | It is not the cheap way to get a normal instance. |
Storage follows the read pattern. S3 Standard for frequent reads. Standard-IA or Glacier Instant Retrieval when reads are rare and must still be fast. Glacier Flexible Retrieval and Deep Archive when waiting is acceptable and the object is cold. Intelligent-Tiering when you do not know the pattern. Lifecycle rules move objects for you. gp3 is the cost-effective general EBS volume. io2 is justified by an IOPS number, not by habit. Delete unattached volumes and snapshots you no longer need.
Network cost is often a NAT gateway. One NAT gateway is cheaper and is a single point of failure. One per Availability Zone is more resilient and costs more. A gateway VPC endpoint for S3 or DynamoDB removes that traffic from the NAT bill. CloudFront can stop repeated requests from all hitting the origin. Data transfer into AWS is generally free. Data transfer out, and data transfer between Regions, is charged. AWS Compute Optimizer suggests a smaller or better-fitting instance. AWS Cost Explorer reviews spend. AWS Budgets alerts. The Cost and Usage Report is the line-item export. Cost allocation tags make those tools useful across accounts.
Extra Amazon Lightsail, the AWS CDK, AWS CodeBuild, AWS CodeCommit, AWS CodeDeploy, and AWS Fault Injection Simulator are on the SAA-C03 out-of-scope list. CloudFormation remains the in-scope way to describe a stack.
No. A service control policy sets the maximum permissions for member accounts in AWS Organizations. An identity still needs an IAM policy that allows the action. An explicit deny in an SCP overrides an allow.
Multi-AZ keeps a workload available when one Availability Zone fails. A second Region is for a regional outage, a distant user base, or a data-residency split. Disaster-recovery strategies such as pilot light and warm standby are multi-Region designs.
Use a gateway VPC endpoint when private subnets need Amazon S3 or Amazon DynamoDB and do not need the public internet. A NAT gateway can reach those services too, and it charges for the data it processes.
Drill the distinctions, then test them under a timer.
Exam format, the 720 passing score, domain weights, and a study plan.
Reference notes for access, resilience, performance choices, and cost levers.
40 recall cards in four decks, plus memory notes for controls, recovery, and cost.
200 original questions with custom exams, explanations, and a score report by domain.
Useful companions while you study.
Generate strong random passwords with custom length, characters, symbols, and security options.
Convert structured data between JSON and YAML with formatting and validation.
Encode text and files to Base64 or decode Base64 data with UTF-8 support.
Compare two text blocks and highlight added, removed, and changed content.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. Amazon Web Services, AWS, and related marks are trademarks of Amazon.com, Inc. or its affiliates. NodnWebTools is not affiliated with, endorsed by, or sponsored by Amazon.