Maximum versus grant
An SCP and a permission boundary set a ceiling. An IAM allow is what grants. An explicit deny wins.
Study guide · Flashcards & memory notes
40 recall cards for the distinctions SAA-C03 keeps testing: who is allowed, what failure you survive, which service meets the speed, and which choice changes the bill.
How to use these cards: Say the answer out loud before you flip the card, and mark it honestly. Revisit the cards you missed tomorrow rather than rereading them right away. Progress is kept only while this page is open. For the full explanations behind each card, see the core notes.
Choose a deck, flip each card, and mark what you already know.
You marked every card in this deck as known. Shuffle and run through it again, or choose another deck.
Select a question to reveal its answer.
Identity limits, network controls, and the service that detects or encrypts.
Grant only the access an identity needs for its task, and nothing more.
An identity policy is attached to a user, group, or role. A resource policy is attached to the resource, such as an S3 bucket.
No. It sets the maximum permissions in a member account. IAM must still allow the action.
When it needs temporary credentials, including access to another account. Prefer that over a long-lived access key.
Identity Center is workforce single sign-on to AWS accounts. Cognito is sign-in for your application's users.
A security group is stateful and attached to the network interface. A network ACL is stateless, can deny, and is attached to the subnet.
When you need a dedicated hardware security module and more direct control of the key material. KMS is the usual choice for keys that AWS services use.
Amazon Macie. AWS WAF inspects requests. It does not scan objects at rest.
Shield protects against DDoS. WAF filters HTTP. GuardDuty reports suspicious activity and does not block traffic by itself.
No. Public ACM certificates are not exportable. Use them with integrated services such as a load balancer or CloudFront.
Decoupling, Availability Zones, and how much downtime or data loss you accepted.
Horizontal scaling adds instances. Vertical scaling moves the workload to a larger instance.
SQS holds a message for a consumer. SNS publishes one message to many subscribers.
Messages that failed processing too many times, so you can inspect them without blocking the main queue.
Multi-AZ survives an Availability Zone failure inside one Region. Multi-Region is for a regional outage, distant users, or data residency.
RPO is how much data you can lose, in time. RTO is how long the service can be down.
Backup and restore, pilot light, warm standby, and active-active.
Multi-AZ is a synchronous standby for failover, and the standby is not a read endpoint. A read replica is asynchronous and serves reads.
Pooling database connections, especially when many short-lived clients such as Lambda would otherwise exhaust the database.
So any instance can serve any request. Keep session data in a shared store, or scale-in will drop it.
Pilot light runs a small critical core and scales the rest at failover. Warm standby already runs a reduced copy of the full system.
The storage, database, and network path that match a speed requirement.
io2. gp3 is the general-purpose SSD. st1 is throughput HDD and is not a boot volume.
When many instances need a shared file system. EBS is a block volume for an instance.
CloudFront caches HTTP at the edge. Global Accelerator uses static anycast addresses and the AWS network. It is not a cache.
When access is a key lookup at any scale and you do not need relational joins. Aurora is the relational, MySQL- and PostgreSQL-compatible choice.
Hot data in memory so repeated reads do not hit the database. It is not the system of record.
For TCP or UDP at high packet rates, or when you need a static IP. An ALB routes HTTP by host or path.
Data Streams is a stream you consume and can replay. Firehose loads streaming data into a destination such as S3 with less for you to manage.
More memory also allocates more CPU. Raise memory when the function is CPU-bound, not only when it needs RAM.
They add read capacity. They do not provide the automatic Multi-AZ failover standby.
When you need a consistent dedicated connection. A VPN encrypts traffic over the internet and is simpler to start. Direct Connect is not encrypted by itself.
Purchasing, storage class, and the network path that changes the bill.
For fault-tolerant work that can be interrupted. AWS can reclaim the capacity.
A Compute Savings Plan is more flexible across EC2, Fargate, and Lambda. An EC2 Instance Savings Plan is limited to a family in a Region and can discount more.
It moves or expires objects as they age, for example from Standard to a colder class.
When private subnets only need S3 or DynamoDB. The gateway endpoint avoids NAT data-processing charges for that traffic.
AWS Compute Optimizer. AWS Cost Explorer shows what you already spent.
When the data set is so large that copying it online would take too long or cost too much.
When the workload does not need sustained very high IOPS. io2 costs more and is justified by that IOPS requirement.
Work that is short-lived or unpredictable, with no usage commit.
Data transfer out of AWS, and data transfer between Regions. Data transfer in is generally free.
One NAT gateway costs less and is a single point of failure. One per Availability Zone costs more and survives a zone failure.
Groupings that make the highest-yield SAA-C03 distinctions easier to recall.
An SCP and a permission boundary set a ceiling. An IAM allow is what grants. An explicit deny wins.
Backup and restore, pilot light, warm standby, active-active.
CloudFront caches HTTP. Global Accelerator steers the network path. A gateway endpoint reaches S3 without a NAT gateway.
Spot if it can stop. Savings Plans if it runs steadily. Lifecycle if the object goes cold. One NAT gateway is cheaper and is a single point of failure.
Test what you have learned with a timed practice exam.
Exam format, the 720 passing score, domain weights, and a study plan.
Reference notes for access, resilience, performance choices, and cost levers.
40 recall cards in four decks, plus memory notes for controls, recovery, and cost.
200 original questions with custom exams, explanations, and a score report by domain.
Useful companions while you study.
Generate strong random passwords with custom length, characters, symbols, and security options.
Convert structured data between JSON and YAML with formatting and validation.
Encode text and files to Base64 or decode Base64 data with UTF-8 support.
Compare two text blocks and highlight added, removed, and changed content.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. Amazon Web Services, AWS, and related marks are trademarks of Amazon.com, Inc. or its affiliates. NodnWebTools is not affiliated with, endorsed by, or sponsored by Amazon.