Home › SAA-C03 › Practice questions
SAA-C03 · AWS · Updated September 2026

SAA-C03 practice questions

Original & expert-reviewed · explanation for every option · no dumps

Practise SAA-C03 with original, expert-reviewed questions — each with an explanation for every option, linked to the source, across the full exam blueprint. No dumps, no ads, 6 free to start.

Try 6 free SAA-C03 questions → See the SAA-C03 bank

Free: 6 questions in study mode, no card. Full SAA-C03 bank with mock exams and the error log: $15 one-time, or every exam with All-Access for $19/mo or $119/yr.

6
Free to start
65
On the real exam
4
exam domains
$0
To begin

What makes these different from dumps

📚 An explanation for every option

Not just the right answer — why each wrong option is wrong, linked to the source. Wrong answers teach the most.

⏱️ Real-format timed mocks

Sit full 65-question, 130-minute exams and get a readiness report by area — know when you're ready.

↻ Spaced-repetition error log

Every miss comes back on a 1 → 3 → 7 → 16-day schedule, so the fixes actually stick.

🔖 Original & reviewed

Every question is written to test the concepts and reviewed before it ships — never copied or leaked “dumps”.

Try 10 real SAA-C03 questions — free, no sign-up

A representative slice of the bank: every exam domains, mixed difficulty (hard ones included). Answers are one tap away — no email wall.

1/10 · Design Secure Architectures
An application runs on Amazon EC2 instances in an Auto Scaling group and reads objects from an Amazon S3 bucket in the same account. The AMI currently bakes in an IAM user's access key and secret key, and the security team wants those credentials off the instances. Which approach will meet the requirement with the LEAST operational overhead?
AMove the access key and secret key into AWS Secrets Manager, enable rotation on the secret, and have the application fetch the pair at startup before it calls Amazon S3.
BCreate an IAM role with the required Amazon S3 permissions and attach it to the instances through an instance profile in the launch template.
CStore the access key and secret key in AWS Systems Manager Parameter Store as SecureString parameters and read them from instance user data during boot.
DRemove the credentials from the AMI and add a bucket policy that allows s3:GetObject when the aws:SourceIp condition matches the VPC's CIDR range.
Show answer & explanation
B is correct. Task Statement 1.1 covers applying AWS security best practices and designing a flexible authorization model with roles. The Amazon EC2 User Guide topic 'IAM roles for Amazon EC2' states that roles let applications 'securely make API requests from your instances, without requiring you to manage the security credentials that the applications use', and that Amazon EC2 uses an instance profile as a container for the role, which is how the role reaches an instance launched by an Auto Scaling group.
↗ AWS SAA-C03 Exam Guide — Domain 1: Design Secure Architectures
2/10 · Design Resilient Architectures
A claims process runs as six AWS Lambda functions in which each function invokes the next one directly. Every function contains its own retry loop, timeout handling, and error branch, written slightly differently, and when a claim fails partway through, the operations team cannot tell which step stopped or what the input to that step was. Which solution will meet these requirements with the LEAST custom code?
ADefine an AWS Step Functions state machine that runs the six functions in sequence, with Retry and Catch configured on each state, and start one execution per claim.
BPut an Amazon SQS queue between each pair of functions, configure a dead-letter queue on each of those queues, and trigger each function from the queue in front of it.
CExpose the six functions through Amazon API Gateway and have the calling client invoke them in order, retrying whichever call happens to fail.
DCombine the six steps into a single AWS Lambda function that calls them as internal methods and logs which step it reached before a failure.
Show answer & explanation
A is correct. Task Statement 2.1 names workflow orchestration with AWS Step Functions. The Step Functions Developer Guide states that you can 'create workflows, also called State machines, to build distributed applications, automate processes, orchestrate microservices', and lists error handling in the service itself: 'You can retry failed tasks, or catch failed tasks and automatically run alternative steps.' Standard workflows record each execution, which is what gives the operations team the per-step history.
↗ AWS SAA-C03 Exam Guide — Domain 2: Design Resilient Architectures
3/10 · Design High-Performing Architectures
A video transcoding fleet writes large intermediate scratch files while a job runs and deletes them as soon as the output has been uploaded. Each instance works only on its own scratch data, nothing else reads it, and losing it when an instance goes away is acceptable. The team wants the fastest possible local read and write performance for that directory. Which storage option should the team use?
AThe instance store volumes that come with the chosen instance type, mounted as the scratch directory on each instance.
BA dedicated gp3 Amazon EBS volume attached to each instance and configured to be deleted when the instance terminates.
CAn Amazon EFS file system with Elastic throughput that the fleet's instances mount at the same path for scratch space.
DAn Amazon S3 bucket to which each instance writes the intermediate files and from which it reads them back during the job.
Show answer & explanation
A is correct. Task Statement 3.1 covers storage services with appropriate use cases and storage types with associated characteristics. The Amazon EC2 User Guide states that 'an instance store provides temporary block-level storage for your EC2 instance. This storage is provided by disks that are physically attached to the host computer' and that it 'is ideal for temporary storage of information that changes frequently, such as buffers, caches, scratch data, and other temporary content'. Its data does not persist when the instance stops, hibernates, or terminates.
↗ AWS SAA-C03 Exam Guide — Domain 3: Design High-Performing Architectures
Like these? Try 6 more SAA-C03 questions with instant feedback, free →
4/10 · Design Cost-Optimized Architectures
A bucket holds 80 TB of customer documents whose average size is about 4 MB. Some documents are opened several times a month for years; others are never opened again after their first week, and the team cannot tell the two groups apart in advance. A document has to come back in milliseconds whenever it is requested. Which solution will meet these requirements at the lowest total cost?
AAdd an S3 Lifecycle rule that moves each object to S3 Standard-IA after 30 days and to S3 Glacier Flexible Retrieval after 90 days.
BStore the objects in the S3 Intelligent-Tiering storage class with the Archive Access and Deep Archive Access tiers activated.
CStore the objects in the S3 Intelligent-Tiering storage class and leave the optional archive tiers deactivated.
DAdd an S3 Lifecycle rule that moves each object to S3 One Zone-IA after 30 days and leaves it there.
Show answer & explanation
C is correct. Task Statement 4.1 covers storage tiering, storage access patterns, and selecting the appropriate storage tier. The Amazon S3 User Guide states that 'For a low monthly object monitoring and automation charge, S3 Intelligent-Tiering monitors access patterns and automatically moves' objects between access tiers, lists 'No retrieval fees' for the class against 'Per-GB retrieval fees apply' for S3 Standard-IA and S3 One Zone-IA, and describes the Archive Instant Access tier as automatic. It also states that you should 'Activate the Archive Access and Deep Archive Access tiers only if your objects can be accessed asynchronously by your application' and that an object in either tier must first be restored 'by using the RestoreObject operation'.
↗ AWS SAA-C03 Exam Guide — Domain 4: Design Cost-Optimized Architectures
5/10 · Design Secure Architectures
An engineer replaces the default network ACL on a subnet with a custom one and adds inbound rule 100 to allow TCP port 443 from 0.0.0.0/0. Clients can open connections to instances in that subnet, but the instances' responses never arrive. Which characteristic of network ACLs explains this behavior?
ANetwork ACL rules are evaluated from the highest rule number down to the lowest, and a later rule with a higher number silently overrides rule 100 for return traffic.
BNetwork ACLs are stateless, and a response to an allowed inbound connection is not automatically permitted without an outbound rule covering the ephemeral port range.
CNetwork ACLs apply their inbound rule list to both directions of a connection, and the reply is evaluated against rule 100 again and denied on its source address.
DNetwork ACLs support allow rules without deny rules, and the reply traffic is matched by the implicit deny that closes each custom network ACL's outbound rule list.
Show answer & explanation
B is correct. Task Statement 1.2 covers controlling ports, protocols, and network traffic on AWS. The Amazon VPC User Guide states that network ACLs are stateless, 'which means that information about previously sent or received traffic is not saved', and that if you create a rule to allow specific inbound traffic, 'responses to that traffic are not automatically allowed'. It contrasts this with security groups, which are stateful.
↗ AWS SAA-C03 Exam Guide — Domain 1: Design Secure Architectures
6/10 · Design Resilient Architectures
A reporting dashboard runs long analytical SELECT statements against the same Amazon RDS for PostgreSQL instance that serves the transactional application. At month end the reports slow the application down for everyone. The analysts have confirmed that reports may run against data that is a few seconds behind the transactional data. Which solution will meet these requirements?
AConvert the DB instance to a Multi-AZ deployment and point the reporting dashboard at the standby replica in the second Availability Zone.
BScale the DB instance up to a larger instance class and convert its storage to Provisioned IOPS SSD sized for the month-end peak.
CPut an Amazon ElastiCache cluster in front of the database and have the reporting dashboard read its results from the cache.
DCreate a read replica of the DB instance and change the reporting dashboard's connection string to the replica endpoint.
Show answer & explanation
D is correct. Task Statement 2.1 names when to use read replicas. The Amazon RDS User Guide states that RDS 'uses the asynchronous replication method for the DB engine to update the read replica' and that 'the read replica operates as a DB instance that allows only read-only connections'. The Multi-AZ page states the opposite for a standby: 'The high availability option isn't a scaling solution for read-only scenarios. You can't use a standby replica to serve read traffic.'
↗ AWS SAA-C03 Exam Guide — Domain 2: Design Resilient Architectures
7/10 · Design High-Performing Architectures
A product catalog page runs the same handful of expensive multi-table joins for every visitor. The Amazon RDS instance behind the page is processor bound at peak and queries begin to queue, although the catalog data itself is updated only two or three times a day by a back-office job. Which solution will most reduce the load on the database?
ACreate two read replicas of the DB instance and have the catalog page send each of its queries to one of the replicas in rotation.
BMigrate the catalog tables to an Amazon DynamoDB table that is designed around the catalog page's access pattern, and query that table from the page directly.
CPut an Amazon ElastiCache cluster between the page and the database and refresh the cached catalog results when the back-office job runs.
DMove the DB instance to a larger instance class with considerably more vCPUs.
Show answer & explanation
C is correct. Task Statement 3.3 names caching strategies and services and asks about integrating caching to meet business requirements. Amazon ElastiCache provides an in-memory cache that sits in front of a database so that repeated reads of the same result are answered from memory rather than recomputed. The access pattern here, identical expensive queries for every visitor over data that changes a few times a day, is what makes caching more effective than adding read capacity.
↗ AWS SAA-C03 Exam Guide — Domain 3: Design High-Performing Architectures
8/10 · Design Cost-Optimized Architectures
A research institute publishes a 40 TB open dataset from one Amazon S3 bucket. Hundreds of laboratories, each with its own AWS account, download subsets every week, and the line item for data transfer out of that bucket has grown past what the institute's research budget can absorb. The same bucket also holds a 2 GB starter extract that is linked from a public web page and downloaded by visitors who send no AWS credentials at all, and those downloads have to keep working. Which solution will meet these requirements?
ATurn on Requester Pays for the bucket, and add a bucket policy that grants anonymous s3:GetObject on the prefix that holds the starter extract.
BTurn on Requester Pays for the dataset bucket, and move the starter extract into a second bucket that is left without Requester Pays.
CCreate S3 Access Grants for each laboratory's AWS account and have the laboratories download the dataset through those grants.
DMove the dataset into the S3 One Zone-IA storage class and keep serving both the dataset and the starter extract from the bucket they are in today.
Show answer & explanation
B is correct. Task Statement 4.1 names access options and gives an S3 bucket with Requester Pays object storage as its example. The Amazon S3 User Guide states that 'With Requester Pays buckets, the requester instead of the bucket owner pays the cost of the request and the data download from the bucket. The bucket owner always pays the cost of storing data', that 'If you enable Requester Pays on a general purpose bucket, anonymous access to that bucket is not allowed. You must authenticate all requests involving Requester Pays buckets', and that requesters must include the x-amz-request-payer header or the RequestPayer parameter. Turning the setting on moves the transfer charge and closes the anonymous path in the same step, which is why the two audiences cannot share one bucket.
↗ AWS SAA-C03 Exam Guide — Domain 4: Design Cost-Optimized Architectures
9/10 · Design Secure Architectures · hard
A retailer serves a public API through an Amazon CloudFront distribution in front of an Application Load Balancer. Twice this quarter the API was hit by floods of valid-looking HTTP requests from thousands of rotating source addresses, each address staying below any per-address threshold the team could set. Leadership wants mitigation that starts without an engineer, an expert team it can engage during an event, and protection against the scaling charges those events generate. The company already subscribes to AWS Business Support. Which solution will meet these requirements?
AAssociate an AWS WAF web ACL with the distribution that contains a rate-based rule for the API paths and the Amazon IP reputation list managed rule group.
BRely on AWS Shield Standard and add an Amazon CloudWatch alarm on the DDoS detection metric that pages the on-call engineer when an event begins.
CSubscribe to AWS Shield Advanced, add the distribution and the load balancer as protected resources, and turn on automatic application layer DDoS mitigation for them.
DAssociate an AWS WAF web ACL with the distribution that contains the Bot Control managed rule group at the targeted protection level and a rate-based rule aggregated on the session cookie.
Show answer & explanation
C is correct. Task Statement 1.2 names threat vectors external to AWS such as DDoS and integrating AWS Shield and AWS WAF to secure applications. The AWS WAF, AWS Firewall Manager, and AWS Shield Advanced Developer Guide lists 'Automatic application layer DDoS mitigation' as a Shield Advanced capability: 'you can configure Shield Advanced to respond automatically to mitigate application layer (layer 7) attacks against your protected resources', that 'as an AWS Shield Advanced customer, you can contact the SRT at any time for assistance during a DDoS attack', that 'to use the services of the SRT, you must also be subscribed to the Business Support plan or the Enterprise Support plan', and that Shield Advanced 'offers some cost protection against spikes in your AWS bill'. AWS WAF rate-based rules aggregate 'based on the request IP address' unless a different aggregation key is configured.
↗ AWS SAA-C03 Exam Guide — Domain 1: Design Secure Architectures
10/10 · Design Secure Architectures · hard
A company with 400 employees in an on-premises Microsoft Active Directory is growing from 3 AWS accounts to 60 accounts under AWS Organizations. Today every employee has a separate IAM user in each account they work in. The identity team wants one place to define job-function permissions, assign them to directory groups across all accounts, and have AWS access end when an employee is disabled in Active Directory. Which solution will meet these requirements with the LEAST operational overhead?
ARegister a SAML 2.0 identity provider for the organization's AWS accounts and create an IAM role for each job function that the directory's SAML assertions are mapped to.
BDeploy AWS Directory Service AD Connector for the organization and create IAM users in the accounts that mirror each employee's Active Directory group membership.
CKeep IAM users in the management account, create an IAM role for each job function in the member accounts, and have employees switch roles into the accounts they work in.
DEnable AWS IAM Identity Center for the organization, connect the existing Active Directory as the identity source, and assign permission sets to directory groups in the accounts.
Show answer & explanation
D is correct. Task Statement 1.1 names AWS federated access and identity services and asks when to federate a directory service with IAM roles. The IAM Identity Center User Guide describes connecting an existing identity provider and synchronizing users and groups, and defines permission sets as a way to 'centrally create permissions for common job functions', provision them across AWS accounts, and assign them to users and groups, providing 'one point of federation'.
↗ AWS SAA-C03 Exam Guide — Domain 1: Design Secure Architectures
Try 6 more free SAA-C03 questions → See the whole SAA-C03 bank

Practice by knowledge area

Five more free questions for each section of the SAA-C03 bank, drawn from that area only, with the answer explained and linked to the source:

Design Secure Architectures32 qDesign Resilient Architectures29 qDesign High-Performing Architectures25 qDesign Cost-Optimized Architectures21 q

Covering every exam domains

The bank spans the whole SAA-C03 blueprint, weighted toward what the exam tests most:

Design Secure Architectures30%Design Resilient Architectures26%Design High-Performing Architectures24%Design Cost-Optimized Architectures20%

Start practising SAA-C03 free

6 free questions in study mode · no card · full SAA-C03 bank: $15 one-time · no dumps, no ads.

Start SAA-C03 free →

SAA-C03 practice — FAQ

Is SAA-C03 still the current version of the exam?

Yes — as of September 2026 aws.amazon.com lists SAA-C03 (exam guide v1.1) with no retirement notice. Blog posts predicting an 'SAA-C04' date are not confirmed by AWS; check the official exam page before you book.

How is SAA-C03 different from Cloud Practitioner?

Cloud Practitioner tests whether you know what AWS services are for; SAA-C03 tests whether you can choose between them under constraints — security, resilience, performance and cost. Expect long scenarios and several plausible options.

Are there hands-on labs in SAA-C03?

No — SAA-C03 is a written exam (multiple choice and multiple response). Hands-on experience matters because the scenarios describe real configurations, but you are never asked to build anything during the exam.

How many questions is the SAA-C03 exam and how long is it?

65 questions (50 scored plus 15 unscored pilot items) in 130 minutes, at a Pearson VUE test centre or online with a proctor.

What is the passing score for SAA-C03?

The passing score is 720 on a scaled score of 100–1,000 (roughly 72%). Aim for a consistent 80–85% on realistic practice exams before booking.

What is the SAA-C03 pass rate?

AWS does not publish official pass rates, so any exact percentage quoted online is unverified. The readiness signal that actually predicts passing: consistently holding 80–85% on realistic, full-length practice exams before you book.

What are the SAA-C03 eligibility requirements?

No prerequisites and no required lower-level certification — you can book SAA-C03 directly. AWS's target candidate has at least 1 year of hands-on experience designing cloud solutions that use AWS services.

How much does SAA-C03 cost?

The exam fee is $150 USD (regional pricing may differ — verify on aws.amazon.com). A 50% recertification voucher applies when you renew, and you must wait 14 days before retaking a failed attempt.

How long should I study for SAA-C03?

For most candidates, commonly reported 80–120 hours, less with daily hands-on AWS work (AWS publishes no official figure). What matters most is practising questions and analysing why each option is right or wrong — not just reading.

Does the SAA-C03 certification need recertification?

valid for 3 years; renew by passing the latest version of SAA or a Professional-level AWS exam (50% voucher), or maintain for 1 year at a time through AWS Skill Builder.

Are ExamDeck's SAA-C03 questions exam dumps?

No — every question is original, written to test the concepts and reviewed before it ships, with an explanation linked to the source for every option. Dumps are stale, often wrong, and against AWS's policies.

ExamDeck is an independent study tool, not affiliated with, endorsed by, or sponsored by AWS. SAA-C03 and related marks are trademarks of their respective owners, used for identification only. Exam facts checked against official AWS materials (as of September 2026); always confirm current details with the vendor before booking.