Study guide · Flashcards & memory notes

AWS Solutions Architect Flashcards & Memory Notes

40 recall cards for the distinctions SAA-C03 keeps testing: who is allowed, what failure you survive, which service meets the speed, and which choice changes the bill.

Exam guide: SAA-C034 decks · 40 cardsNo sign-up required

How to use these cards: Say the answer out loud before you flip the card, and mark it honestly. Revisit the cards you missed tomorrow rather than rereading them right away. Progress is kept only while this page is open. For the full explanations behind each card, see the core notes.

Study mode

Choose a deck, flip each card, and mark what you already know.

All flashcards

Select a question to reveal its answer.

Deck 1 · Secure access and controls

Identity limits, network controls, and the service that detects or encrypts.

10 cards
1.1What does least privilege mean?

Grant only the access an identity needs for its task, and nothing more.

1.2What is the difference between an identity policy and a resource policy?

An identity policy is attached to a user, group, or role. A resource policy is attached to the resource, such as an S3 bucket.

1.3Does a service control policy grant permissions?

No. It sets the maximum permissions in a member account. IAM must still allow the action.

1.4When should an application use an IAM role?

When it needs temporary credentials, including access to another account. Prefer that over a long-lived access key.

1.5What is IAM Identity Center for, compared with Amazon Cognito?

Identity Center is workforce single sign-on to AWS accounts. Cognito is sign-in for your application's users.

1.6What is the difference between a security group and a network ACL?

A security group is stateful and attached to the network interface. A network ACL is stateless, can deny, and is attached to the subnet.

1.7When do you choose AWS CloudHSM instead of AWS KMS?

When you need a dedicated hardware security module and more direct control of the key material. KMS is the usual choice for keys that AWS services use.

1.8Which service discovers sensitive data already stored in Amazon S3?

Amazon Macie. AWS WAF inspects requests. It does not scan objects at rest.

1.9What do AWS Shield, AWS WAF, and Amazon GuardDuty each do?

Shield protects against DDoS. WAF filters HTTP. GuardDuty reports suspicious activity and does not block traffic by itself.

1.10Can you install a public ACM certificate on an EC2 instance?

No. Public ACM certificates are not exportable. Use them with integrated services such as a load balancer or CloudFront.

Deck 2 · Resilience and recovery

Decoupling, Availability Zones, and how much downtime or data loss you accepted.

10 cards
2.1What is the difference between horizontal and vertical scaling?

Horizontal scaling adds instances. Vertical scaling moves the workload to a larger instance.

2.2What is the difference between Amazon SQS and Amazon SNS?

SQS holds a message for a consumer. SNS publishes one message to many subscribers.

2.3What is a dead-letter queue for?

Messages that failed processing too many times, so you can inspect them without blocking the main queue.

2.4What is the difference between Multi-AZ and multi-Region?

Multi-AZ survives an Availability Zone failure inside one Region. Multi-Region is for a regional outage, distant users, or data residency.

2.5What is the difference between RPO and RTO?

RPO is how much data you can lose, in time. RTO is how long the service can be down.

2.6Name the four disaster-recovery strategies from lowest cost to lowest recovery time.

Backup and restore, pilot light, warm standby, and active-active.

2.7What is the difference between RDS Multi-AZ and a read replica?

Multi-AZ is a synchronous standby for failover, and the standby is not a read endpoint. A read replica is asynchronous and serves reads.

2.8What is Amazon RDS Proxy for?

Pooling database connections, especially when many short-lived clients such as Lambda would otherwise exhaust the database.

2.9Why should instances behind an Auto Scaling group be stateless?

So any instance can serve any request. Keep session data in a shared store, or scale-in will drop it.

2.10What is the difference between pilot light and warm standby?

Pilot light runs a small critical core and scales the rest at failover. Warm standby already runs a reduced copy of the full system.

Deck 3 · Performance choices

The storage, database, and network path that match a speed requirement.

10 cards
3.1Which EBS type fits sustained high IOPS?

io2. gp3 is the general-purpose SSD. st1 is throughput HDD and is not a boot volume.

3.2When do you choose Amazon EFS instead of Amazon EBS?

When many instances need a shared file system. EBS is a block volume for an instance.

3.3What is the difference between Amazon CloudFront and AWS Global Accelerator?

CloudFront caches HTTP at the edge. Global Accelerator uses static anycast addresses and the AWS network. It is not a cache.

3.4When do you choose Amazon DynamoDB instead of Amazon Aurora?

When access is a key lookup at any scale and you do not need relational joins. Aurora is the relational, MySQL- and PostgreSQL-compatible choice.

3.5What is Amazon ElastiCache for?

Hot data in memory so repeated reads do not hit the database. It is not the system of record.

3.6When do you choose a Network Load Balancer instead of an Application Load Balancer?

For TCP or UDP at high packet rates, or when you need a static IP. An ALB routes HTTP by host or path.

3.7What is the difference between Kinesis Data Streams and Data Firehose?

Data Streams is a stream you consume and can replay. Firehose loads streaming data into a destination such as S3 with less for you to manage.

3.8How does AWS Lambda memory affect performance?

More memory also allocates more CPU. Raise memory when the function is CPU-bound, not only when it needs RAM.

3.9What do read replicas change?

They add read capacity. They do not provide the automatic Multi-AZ failover standby.

3.10When do you choose AWS Direct Connect instead of a site-to-site VPN?

When you need a consistent dedicated connection. A VPN encrypts traffic over the internet and is simpler to start. Direct Connect is not encrypted by itself.

Deck 4 · Cost levers

Purchasing, storage class, and the network path that changes the bill.

10 cards
4.1When do you choose Spot Instances?

For fault-tolerant work that can be interrupted. AWS can reclaim the capacity.

4.2What is the difference between a Compute Savings Plan and an EC2 Instance Savings Plan?

A Compute Savings Plan is more flexible across EC2, Fargate, and Lambda. An EC2 Instance Savings Plan is limited to a family in a Region and can discount more.

4.3What does an S3 lifecycle rule do?

It moves or expires objects as they age, for example from Standard to a colder class.

4.4When is a gateway VPC endpoint cheaper than a NAT gateway?

When private subnets only need S3 or DynamoDB. The gateway endpoint avoids NAT data-processing charges for that traffic.

4.5Which tool recommends a better-fitting EC2 instance size?

AWS Compute Optimizer. AWS Cost Explorer shows what you already spent.

4.6When is the Snow Family a better transfer than the network?

When the data set is so large that copying it online would take too long or cost too much.

4.7When is gp3 a better default than io2?

When the workload does not need sustained very high IOPS. io2 costs more and is justified by that IOPS requirement.

4.8What is On-Demand for?

Work that is short-lived or unpredictable, with no usage commit.

4.9Which data transfer is usually charged?

Data transfer out of AWS, and data transfer between Regions. Data transfer in is generally free.

4.10What is the cost tradeoff of one NAT gateway versus one per Availability Zone?

One NAT gateway costs less and is a single point of failure. One per Availability Zone costs more and survives a zone failure.

Memory notes

Groupings that make the highest-yield SAA-C03 distinctions easier to recall.

Maximum versus grant

An SCP and a permission boundary set a ceiling. An IAM allow is what grants. An explicit deny wins.

Two failure maps

  • Multi-AZ one Region, zone loss
  • Multi-Region regional loss or distance
  • RPO data you can lose · RTO time you can be down

Recovery, cheap to fast

Backup and restore, pilot light, warm standby, active-active.

Hold, fan-out, orchestrate

  • SQS one consumer later
  • SNS many subscribers now
  • Step Functions a workflow, not a buffer

Path versus cache

CloudFront caches HTTP. Global Accelerator steers the network path. A gateway endpoint reaches S3 without a NAT gateway.

Bill levers

Spot if it can stop. Savings Plans if it runs steadily. Lifecycle if the object goes cold. One NAT gateway is cheaper and is a single point of failure.

Continue the AWS Solutions Architect study path

Test what you have learned with a timed practice exam.

AWS Solutions Architect hub →
Available

Overview

Exam format, the 720 passing score, domain weights, and a study plan.

Available

Core Notes

Reference notes for access, resilience, performance choices, and cost levers.

Available · You are here

Flashcards & Memory Notes

40 recall cards in four decks, plus memory notes for controls, recovery, and cost.

Available

Practice Exams

200 original questions with custom exams, explanations, and a score report by domain.

Related Tools

Useful companions while you study.

All study topics →