# Passing the exam: focus areas

What shifted in the current exam and where the marks concentrate — storage, compute, networking, databases, encryption and integration — as a final revision sweep.

Design-level notes for **AWS Certified Solutions Architect – Associate (SAA-C03)**. The course notes build the mental model, the study-guide page covers the blueprint fundamentals, and the exam-tips page is your last pass before the test centre.

**7 topics, 27 study points.** Everything here is exam-oriented: each point is a fact or a distinction that SAA-C03 items are built on. Test yourself against the [practice exam](/aws/practice-exam/) once you can explain a section without re-reading it.

## 1. High Level Changes in the Current Exam

The current AWS Solutions Architect — Associate exam (SAA-C03) is focused entirely on architectural decision-making. Unlike earlier versions of the exam, it does not test development skills or implementation details like writing code. Every question presents a scenario and asks you to select the best architectural option — the one that best satisfies the stated requirements for scalability, availability, security, performance, and cost. "Best" is a deliberate word: multiple answers may technically work, but only one optimally satisfies all the constraints.

Modern cloud-native technologies feature heavily in the current exam: API Gateway and Lambda for serverless architectures, ECS and EKS for containerized workloads, SQS and SNS for decoupled messaging, and Step Functions for workflow orchestration. You should be comfortable reasoning about event-driven architectures and understanding when serverless patterns outperform traditional EC2-based designs. The exam rewards candidates who think architecturally rather than operationally — focus on which services to use and how they fit together, not on configuration syntax.

The exam format is 65 questions (multiple choice and multiple response) with 130 minutes. For multiple-response questions, you must select all correct answers — partial credit is not awarded. A passing score is 720 out of 1000 (on a scaled scoring model). The exam consistently rewards applying the Well-Architected Framework pillars — Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability — to scenario-based questions.

## 2. Storage Focus Areas

Storage is one of the most heavily tested domains in the SA exam. You must understand the fundamental characteristics — latency, throughput, IOPS, persistence, and sharing model — of each storage option and know exactly when to use each. EBS provides persistent block storage for a single EC2 instance. EFS provides a shared NFS file system accessible by multiple EC2 instances simultaneously. S3 provides virtually unlimited object storage accessible from anywhere. Instance Store provides ephemeral, ultra-fast local storage that disappears when the instance stops.

For EBS, understand the difference between gp3 (general purpose SSD), io2 (provisioned IOPS SSD for databases requiring consistent high IOPS), st1 (throughput-optimized HDD for sequential big data workloads), and sc1 (cold HDD for infrequently accessed large data). Know how to calculate required IOPS and throughput, and understand that EBS performance depends on both volume type and the EC2 instance type — some instances have EBS-optimized networking specifically for storage I/O. Understand steady-state vs burst performance: gp2 volumes burst to 3,000 IOPS for smaller volumes but only sustain baseline IOPS at scale.

For S3, master the different access control mechanisms: IAM policies control what users and roles can do with S3; bucket policies are resource-based policies attached to the bucket and support cross-account access; ACLs (Access Control Lists) are a legacy mechanism for object-level access control and are now generally discouraged in favor of bucket policies. CORS configuration is required when a web application hosted on one domain accesses S3 resources from a different domain. Know when to use Pre-signed URLs (time-limited, single-object access without AWS credentials) versus S3 signed cookies (multiple objects) versus OAC/OAI with CloudFront (restrict S3 access to only come through CloudFront).

Storage Gateway connects on-premises environments to AWS cloud storage. File Gateway presents S3 buckets as NFS or SMB file shares to on-premises applications — files are stored as S3 objects. Volume Gateway presents block storage volumes to on-premises servers via iSCSI — backed by EBS snapshots. Tape Gateway emulates a physical tape library, enabling existing backup software to write to virtual tapes stored in S3 Glacier. Understanding which Storage Gateway type fits which migration or hybrid scenario is frequently tested.

## 3. Compute Focus Areas

The exam tests EC2 knowledge across four areas: instance selection (choosing the right family and size), purchasing options (On-Demand, Reserved, Spot, Dedicated), networking and placement (VPC, security groups, placement groups), and scaling (Auto Scaling groups, launch templates, scaling policies). Know the instance families by use case — T/M for general purpose, C for CPU-intensive, R/X for memory-intensive, I/D for storage-intensive, G/P for GPU workloads. Instance Reservations come in Standard (fixed instance type, maximum discount), Convertible (flexible instance type, smaller discount), and Scheduled (specific time windows) forms. Regional Reserved Instances apply to any AZ in the region; Zonal Reserved Instances reserve capacity in a specific AZ.

Serverless architectures with Lambda are heavily featured. Key Lambda characteristics to know: maximum execution timeout is 15 minutes (use Step Functions or ECS for longer-running processes); memory is configurable from 128 MB to 10 GB (CPU allocation scales proportionally with memory); billing is per 100ms of execution time and per million invocations; Lambda functions are stateless but can connect to stateful services (DynamoDB, S3, ElastiCache). Lambda functions run inside your VPC or in the AWS-managed Lambda service VPC — when running inside your VPC, they consume ENI capacity and require proper subnet and security group configuration.

The exam frequently asks you to choose between EC2, Elastic Beanstalk, ECS, and Lambda for a given scenario. Use EC2 when you need full OS-level control, specific licensing requirements, or long-running processes. Use Elastic Beanstalk when you want to deploy a web application quickly without managing infrastructure but still want access to the underlying EC2 instances. Use ECS/EKS when your application is containerized and you need orchestration, task scheduling, and service discovery. Use Lambda when your workload is event-driven, short-duration, and benefits from zero server management and per-execution billing.

CloudFormation expertise is expected at the associate level. Key concepts: templates define resources in JSON or YAML; Stacks instantiate a template into real resources; ChangeSets show exactly what will change before you execute an update; Drift detection identifies resources that have been modified outside of CloudFormation. The DependsOn attribute controls creation order for resources with implicit dependencies that CloudFormation cannot infer. cfn-init and cfn-signal are CloudFormation helper scripts that enable bootstrapping EC2 instances during stack creation.

## 4. Networking Focus Areas

VPC design is one of the deepest and most tested areas of the exam. You should be able to design a VPC from scratch without wizard assistance: define a CIDR block (/16 to /28), carve out subnets for different tiers (public, private, database), configure route tables with appropriate routes (IGW for public subnets, NAT Gateway for private subnets), set up security groups for each tier, and configure NACLs for subnet-level protection. Practice thinking in terms of CIDR notation — a /24 subnet provides 256 addresses (minus 5 reserved by AWS = 251 usable); a /16 VPC provides 65,536 addresses for subnets.

Load balancer selection is frequently tested. Application Load Balancer (ALB) is the right choice when you need URL path-based routing (/api → service A, /web → service B), host-based routing, or HTTP/HTTPS/gRPC support — ALB is ideal for microservices and containerized applications. Network Load Balancer (NLB) is the right choice when you need TCP/UDP support, extreme performance (millions of requests per second), static IP addresses, or TLS termination. Classic Load Balancer is the legacy option — use ALB or NLB for all new designs. Cross-zone load balancing distributes traffic evenly across instances in all enabled AZs, regardless of the number of instances per AZ.

NAT Gateways provide outbound internet access for private subnet resources. A single NAT Gateway in one AZ is a single point of failure for the AZs that depend on it — for production high availability, deploy a NAT Gateway in each AZ and update each private route table to use its local AZ's NAT Gateway. Never confuse Internet Gateways and NAT Gateways: an Internet Gateway enables two-way communication between your VPC and the internet (resources in the VPC need a public IP); a NAT Gateway enables one-way outbound communication from private resources (no public IP needed, internet cannot initiate connections in).

VPC Endpoints allow your resources to communicate privately with AWS services without traversing the internet. Interface Endpoints (powered by AWS PrivateLink) create an ENI in your subnet for services like SQS, SNS, KMS, and hundreds of others. Gateway Endpoints are a special type for S3 and DynamoDB — they add entries to your route table and do not require an ENI. When a scenario mentions security requirements for private connectivity between EC2 and S3 or DynamoDB, the answer is almost always a VPC Endpoint. Bastion hosts (also called jump boxes) are EC2 instances in a public subnet used as a secure entry point for SSH or RDP access to instances in private subnets — they should be hardened, with access restricted to known source IPs.

## 5. Database Focus Areas

Database selection questions follow a predictable pattern on the exam. The first question to ask is: is this relational (structured schema, SQL, joins, transactions) or non-relational (flexible schema, key-value, document, graph)? If relational: use RDS or Aurora. If key-value or document at massive scale with single-digit millisecond latency: use DynamoDB. If graph relationships: use Neptune. If analytics and OLAP queries on large datasets: use Redshift. If you need in-memory speed: use ElastiCache. Never use a database service that is designed for one purpose to solve a problem that another service handles natively.

RDS high availability has two distinct mechanisms. Multi-AZ provides automatic failover to a synchronous standby replica — it is an HA feature, not a read-scaling feature. Read Replicas provide asynchronous copies of the primary database that can serve read traffic — they do not participate in automatic failover and require application-level read routing. Aurora's architecture is different: it uses shared distributed storage replicated six ways across three AZs, with up to 15 low-latency read replicas that can be promoted in under 30 seconds. Aurora Serverless v2 automatically adjusts database capacity based on workload, making it cost-effective for variable or unpredictable traffic patterns.

DynamoDB is AWS's flagship NoSQL service and features prominently in every SA exam. Key concepts: tables store items (rows) with attributes (columns), accessed by a primary key (partition key alone, or partition key + sort key). DynamoDB distributes data across partitions based on the partition key hash — a poorly chosen partition key can create "hot partitions" that throttle performance. Global Secondary Indexes (GSIs) allow querying on non-primary-key attributes — they are eventually consistent and consume their own RCU/WCU. DynamoDB Streams captures a time-ordered sequence of item-level changes for event-driven processing. DynamoDB Global Tables provide multi-region, multi-active replication for globally distributed applications.

Session state storage is a recurring design pattern in the exam. When a web application needs to store user session data in a scalable, shared layer (so any server can serve any user request), the primary choices are ElastiCache (Redis) for low-latency in-memory session storage, or DynamoDB for highly available, durable session storage with automatic scaling. Never store session state on individual EC2 instances if you want horizontal scalability. DAX (DynamoDB Accelerator) is an in-memory cache purpose-built for DynamoDB that reduces read latency from milliseconds to microseconds — appropriate for read-heavy workloads where the application cannot tolerate even single-digit millisecond DynamoDB latency.

## 6. Security & Encryption

Encryption is a heavily tested topic. At the conceptual level: symmetric encryption uses the same key for encryption and decryption (fast, used for bulk data encryption — AES-256 is the standard). Asymmetric encryption uses a key pair: the public key encrypts, the private key decrypts (slower, used for key exchange and digital signatures — RSA and elliptic curve are common). Public Key Infrastructure (PKI) is the system of certificates, certificate authorities, and trust chains that enables HTTPS/TLS — AWS Certificate Manager (ACM) provides free, auto-renewing TLS certificates for use with ALB, CloudFront, and API Gateway.

AWS KMS (Key Management Service) is the central key management service for encrypting data at rest across AWS services. A Customer Master Key (CMK) is the top-level cryptographic key in KMS — it never leaves KMS unencrypted and is protected by FIPS 140-2 validated hardware. Envelope encryption is the pattern used by most AWS services: KMS generates a data encryption key (DEK), encrypts your data with the DEK, then encrypts the DEK with the CMK — only the encrypted DEK and encrypted data are stored, never the plaintext DEK. Key rotation for AWS-managed CMKs happens automatically every year; for customer-managed CMKs, you can enable automatic annual rotation or rotate manually.

For S3 encryption, know all four options precisely. SSE-S3 (Server-Side Encryption with S3-Managed Keys): AWS manages keys entirely, AES-256, no overhead, the simplest option. SSE-KMS (Server-Side Encryption with KMS-Managed Keys): KMS manages keys, provides CloudTrail audit logs of key usage, allows key policies and cross-account access — required when you need visibility into who decrypted what and when. SSE-C (Server-Side Encryption with Customer-Provided Keys): you provide the key with each request, AWS encrypts/decrypts but never stores your key — you are fully responsible for key management. Client-Side Encryption: you encrypt before upload and decrypt after download — AWS never sees plaintext data.

IAM policy evaluation is a critical security concept. Policies can explicitly allow or explicitly deny actions. An explicit deny in any policy always overrides any allow — this is the foundational rule. In the absence of an explicit allow, access is implicitly denied by default. When evaluating access for a resource within the same AWS account, IAM evaluates all applicable policies (identity-based policies, resource-based policies, SCPs, and permission boundaries) and applies the most restrictive result. Understanding the difference between identity-based policies (attached to users, groups, or roles), resource-based policies (attached to the resource like an S3 bucket or SQS queue), and service control policies (SCPs in AWS Organizations that set maximum permission boundaries for entire accounts) is essential for exam questions about cross-account access patterns.

## 7. Architecture & Integration

SQS is the primary tool for absorbing traffic spikes and decoupling components in AWS architectures. When a frontend service receives unpredictable bursts of requests that a downstream service cannot process in real time, SQS buffers those requests in a queue. The downstream service pulls messages at its own pace, and the SQS queue absorbs the difference. This "smoothing" pattern prevents downstream services from being overwhelmed. SQS visibility timeout prevents the same message from being processed by multiple consumers simultaneously — if a consumer fails to delete the message within the visibility timeout window, it becomes visible again for reprocessing.

The choice between SQS and Kinesis Data Streams depends on the use case. SQS is designed for decoupling application components and distributing work among workers — messages are consumed by one consumer and deleted. Kinesis Data Streams is designed for real-time data streaming where multiple consumers process the same data independently — a log aggregation pipeline, click-stream analytics, and IoT sensor data are Kinesis use cases. Kinesis retains data for up to 365 days, enabling replay of historical data. SQS FIFO queues guarantee ordering and exactly-once processing but have a throughput limit (3,000 messages/sec with batching) — use standard SQS when ordering is not required and throughput is the priority.

Disaster recovery planning requires understanding the four standard strategies and their trade-offs on Recovery Time Objective (RTO) and Recovery Point Objective (RPO). Backup and Restore (cheapest, longest RTO/RPO): regularly back up data to S3 and restore when needed — no standing infrastructure in the DR region. Pilot Light (low cost, moderate RTO): replicate data continuously to a DR region and keep a minimal set of core infrastructure running — scale it out when disaster strikes. Warm Standby (moderate cost, fast RTO): run a reduced-capacity version of the full production environment in the DR region — scale it to full capacity during a disaster. Multi-Site / Active-Active (highest cost, near-zero RTO/RPO): run full production in multiple regions simultaneously — Route 53 or Global Accelerator routes traffic to both, with instant failover.

Route 53 is the primary tool for global high availability and routing. Health checks enable DNS-level failover: Route 53 continuously checks your endpoints and removes unhealthy endpoints from DNS responses. Combining a Failover routing policy with health checks creates an active-passive HA setup. Weighted routing supports blue-green deployments and gradual traffic migration. Latency-based routing automatically routes users to the lowest-latency region. DNS TTL is critical for failover speed — if your TTL is 300 seconds (5 minutes) and a failure occurs, DNS clients may continue sending traffic to the failed endpoint for up to 5 minutes before their cache expires. For fast failover, use low TTLs (60 seconds or less), but understand the trade-off: lower TTLs increase DNS query volume and load on Route 53.

---

## Where to go next

- Back to the [AWS Solutions Architect overview](/aws/solutions-architect/).
- Look up any service you could not name in the [AWS services glossary](/aws/services-glossary/).
- Sit the [80-item practice exam](/aws/practice-exam/) once two or three note pages are solid.
