CertKeen
AWSBeta · expanding bank

AWS Solutions Architect Associate (SAA-C03) Practice Exam

Practice questions for the AWS Certified Solutions Architect – Associate (SAA-C03) exam, weighted to the official exam guide domains: secure architectures (IAM, Organizations and SCPs, KMS, Secrets Manager, security groups and network ACLs, WAF and Shield, S3 access controls), resilient architectures (Multi-AZ, Auto Scaling, Elastic Load Balancing, SQS/SNS/EventBridge decoupling, Route 53 routing, backup and disaster recovery, RDS and Aurora replicas), high-performing architectures (storage, database and compute selection, ElastiCache and CloudFront caching, DynamoDB, Kinesis, EBS volume types) and cost-optimized architectures (purchase options and Savings Plans, S3 storage classes and lifecycle, right-sizing, NAT and data transfer costs). Every question includes a written explanation.

100 questions · 12 free preview

$19 · lifetime access
Try free sample

Studying more than one? All AWS exams for $29 · every exam for $79

Free sample questions

  1. Sample · question 1 · IAM explicit deny overrides allow

    An IAM user at Larkspur Media belongs to a group with this policy: {"Version": "2012-10-17", "Statement": [{"Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::larkspur-reports/*"}]}. The user also has this inline policy: {"Version": "2012-10-17", "Statement": [{"Effect": "Deny", "Action": "s3:DeleteObject", "Resource": "arn:aws:s3:::larkspur-reports/*"}]}. No other policies apply. What happens when the user tries to delete an object in the larkspur-reports bucket?

    • A.The request is allowed because the group policy grants s3:*
    • B.The request is denied because an explicit Deny overrides any Allowcorrect
    • C.The request is allowed because group policies take precedence over inline policies
    • D.The request is denied only if the bucket has versioning enabled

    Why: In IAM policy evaluation, an explicit Deny in any applicable policy always overrides an Allow, so the delete is refused even though the group policy allows s3:*. There is no precedence of group policies over inline policies, and versioning does not affect how IAM evaluates the request.

    Open this question on its own page →
  2. Sample · question 2 · VPC Flow Logs for connectivity troubleshooting

    Users report that an application server at Birchfield Clinics intermittently cannot reach a database in another subnet of the same VPC. The network team wants to see whether the traffic is being accepted or rejected by security groups or network ACLs, including source and destination IPs and ports. Which feature should they enable?

    • A.AWS CloudTrail data events
    • B.Amazon Route 53 Resolver query logging
    • C.Elastic Load Balancing access logs
    • D.VPC Flow Logs on the relevant subnets or network interfacescorrect

    Why: VPC Flow Logs capture metadata about IP traffic to and from network interfaces, including addresses, ports, and whether traffic was accepted or rejected. CloudTrail records API calls rather than packet flows, Resolver query logs show DNS queries, and load balancer access logs only cover requests that pass through a load balancer.

    Open this question on its own page →
  3. Sample · question 3 · Transit Gateway instead of peering mesh

    Marston Group has 25 VPCs in one Region and has connected them with a growing mesh of VPC peering connections. Engineers are frustrated that traffic does not pass from one VPC through a peered VPC to a third VPC, and the number of peering connections is becoming hard to manage. Which solution simplifies connectivity for all VPCs?

    • A.Attach all VPCs to an AWS Transit Gateway and use its route tables to control routingcorrect
    • B.Add more peering connections so every VPC is peered with every other VPC and route through a central VPC
    • C.Create a VPN connection between each pair of VPCs
    • D.Enable transitive routing on the existing peering connections

    Why: A Transit Gateway acts as a regional hub that VPCs attach to once, and its route tables control which attachments can reach each other, replacing a complex peering mesh. VPC peering is non-transitive and has no setting to make it transitive, a full mesh grows quadratically, and per-pair VPNs add even more overhead.

    Open this question on its own page →
  4. Sample · question 4 · Scheduled scaling for predictable peaks

    Traffic to the payroll portal at Kellerman Services rises sharply every weekday at 8:00 AM and falls at 6:00 PM, following the same pattern every week. Reactive scaling adds instances too slowly, so employees see slow responses in the first minutes of each morning. What should a solutions architect configure for the Auto Scaling group?

    • A.A step scaling policy with a lower CPU alarm threshold
    • B.A longer health check grace period
    • C.Scheduled scaling actions that raise capacity shortly before 8:00 AM and lower it after 6:00 PM on weekdayscorrect
    • D.A larger default instance warmup value

    Why: Scheduled scaling changes capacity at specified times, so the group can scale out before a known daily surge instead of reacting to it. A lower alarm threshold still reacts after load begins, and health check grace periods and warmup settings affect how new instances are evaluated rather than when they are launched.

    Open this question on its own page →
  5. Sample · question 5 · RDS point-in-time restore

    At 2:47 PM, a faulty deployment at Quimby Travel corrupted rows in an Amazon RDS for MySQL database that has automated backups enabled with a 7-day retention period. The team wants to recover the database to its state at 2:45 PM. What should they do?

    • A.Promote a read replica created before the deployment
    • B.Perform a point-in-time restore to 2:45 PM, which creates a new DB instance, and point the application to itcorrect
    • C.Restore the most recent manual snapshot over the existing DB instance
    • D.Reboot the DB instance with failover to the Multi-AZ standby

    Why: Automated backups plus transaction logs allow a point-in-time restore to any second within the retention period, and the restore creates a new DB instance that the application must be pointed to. A read replica would already have received the corrupting changes, snapshot restores cannot overwrite an existing instance and return only to the snapshot time, and a Multi-AZ standby is synchronously replicated so it holds the same corrupted data.

    Open this question on its own page →
  6. Sample · question 6 · Route 53 geolocation routing

    Vireo Streaming must show region-specific catalogs and comply with licensing rules: users in Germany must always be sent to the eu-central-1 deployment and users in Japan to the ap-northeast-1 deployment, regardless of network latency. Which Route 53 routing policy should be used?

    • A.Geolocation routingcorrect
    • B.Latency-based routing
    • C.Weighted routing
    • D.Multivalue answer routing

    Why: Geolocation routing answers DNS queries based on the geographic location of the user, such as country, so licensing rules can be enforced per country, with a default record for other locations. Latency-based routing chooses by network performance and could send users across borders, and weighted and multivalue routing do not consider location.

    Open this question on its own page →
  7. Sample · question 7 · Data Lifecycle Manager for EBS snapshots

    Operations staff at Holloway Dental create EBS snapshots of about 80 volumes by hand each night and delete old snapshots when they remember. The company wants snapshots created daily for volumes with the tag Backup=true and kept for 14 days, fully automated with native EBS tooling. What should a solutions architect use?

    • A.A cron job on a bastion host that calls the AWS CLI
    • B.S3 lifecycle rules applied to the snapshots
    • C.Amazon EventBridge rules that copy volumes to Amazon S3
    • D.Amazon Data Lifecycle Manager policies targeting volumes by tagcorrect

    Why: Amazon Data Lifecycle Manager automates the creation, retention, and deletion of EBS snapshots based on policies that target resources by tag. A cron job must be maintained and monitored, S3 lifecycle rules do not manage EBS snapshots, and EventBridge rules cannot copy volumes to S3 on their own.

    Open this question on its own page →
  8. Sample · question 8 · DynamoDB Streams with Lambda

    Whenever an item is added or updated in a DynamoDB table at Orchard Rewards, the company wants to send a notification to the customer and update a search index within seconds. The team prefers a serverless design that does not poll the table. Which approach should be used?

    • A.A scheduled Lambda function that scans the table every minute
    • B.DynamoDB point-in-time recovery with an export to S3
    • C.DynamoDB Streams on the table with a Lambda function as the stream consumercorrect
    • D.A global secondary index that projects all attributes

    Why: DynamoDB Streams records item-level changes, and a Lambda event source mapping processes those change records shortly after they occur, without the application polling the table. Scanning every minute is slow and consumes read capacity, point-in-time recovery and exports are for backup and analytics, and a GSI provides an alternate query pattern rather than change events.

    Open this question on its own page →
  9. Sample · question 9 · Amazon MQ for broker migrations

    Fitzgerald Insurance is moving an on-premises application that relies on Apache ActiveMQ with standard protocols such as JMS, AMQP, and MQTT to AWS. The team wants a managed message broker and does not want to rewrite the messaging code. Which service should a solutions architect recommend?

    • A.Amazon SQS
    • B.Amazon MQcorrect
    • C.Amazon SNS
    • D.Amazon Kinesis Data Streams

    Why: Amazon MQ is a managed message broker for Apache ActiveMQ and RabbitMQ that supports industry-standard APIs and protocols, allowing migration with little or no code change. SQS, SNS, and Kinesis are AWS-native services with their own APIs, so adopting them would require rewriting the messaging layer.

    Open this question on its own page →
  10. Sample · question 10 · Graviton instances for price-performance

    Treadwell Apps runs a fleet of Linux-based microservices on x86 EC2 instances. The services are written in interpreted languages and are compiled for no specific CPU architecture. The team wants to improve price-performance for the fleet without changing the application's design. What should a solutions architect suggest evaluating first?

    • A.Moving the fleet to Dedicated Hosts
    • B.Moving the fleet to larger x86 instance sizes
    • C.Moving the fleet to storage optimized instances
    • D.Moving the fleet to AWS Graviton-based instancescorrect

    Why: AWS Graviton processors are Arm-based and are designed to offer better price-performance for many workloads, and applications in interpreted languages often run on them with minimal changes once dependencies support Arm. Dedicated Hosts and larger instances increase cost, and storage optimized instances target local disk I/O rather than general compute efficiency.

    Open this question on its own page →
  11. Sample · question 11 · Amazon Inspector vulnerability scanning

    The security team at Penrose Logistics wants continuous, automated scanning of its EC2 instances and container images in Amazon ECR for known software vulnerabilities and unintended network exposure, with findings prioritized by severity. Which service should be enabled?

    • A.AWS Shield Advanced
    • B.AWS Security Token Service
    • C.Amazon Inspectorcorrect
    • D.AWS Artifact

    Why: Amazon Inspector automatically discovers and continuously scans EC2 instances, ECR container images, and Lambda functions for software vulnerabilities and network exposure, and it scores findings by risk. Shield Advanced protects against DDoS attacks, STS issues temporary credentials, and Artifact provides compliance reports.

    Open this question on its own page →
  12. Sample · question 12 · Root user protection best practices

    A new AWS account has been created for Harrowgate Foods. The security lead wants to follow best practices for protecting the account's root user. Which TWO actions should be taken? (Select TWO.)

    • A.Enable multi-factor authentication for the root usercorrect
    • B.Use the root user for daily administrative tasks to avoid permission issues
    • C.Store the root user password in a shared team document so that several leads can use it
    • D.Create access keys for the root user so automation scripts can run with full permissions
    • E.Avoid creating root user access keys and use IAM Identity Center users or IAM roles for everyday workcorrect

    Why: AWS recommends protecting the root user with MFA and not creating root access keys, using federated or IAM identities with least privilege for everyday work and reserving the root user for the few tasks that require it. Using the root user daily, sharing its password, or giving it access keys for automation all greatly increase the impact of a credential compromise.

    Open this question on its own page →

Like the sample?

Other practice exams