All certifications / Solutions Architect Associate / Lessons
Solutions Architect Associate SAA-C03 lessons
Study Solutions Architect Associate for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Solutions Architect Associate study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Design Secure Architectures
- IAM users, groups, roles and policies: least privilege, identity-based vs resource-based policies and policy evaluation logic
- Multi-account security: AWS Organizations, service control policies, IAM Identity Center and cross-account roles
- Federation and temporary credentials: STS AssumeRole, SAML and OIDC federation, Cognito user pools vs identity pools
- VPC security layers: security groups vs network ACLs, public and private subnets, NAT gateways, bastion hosts vs Session Manager
- Private access to AWS services: gateway endpoints, interface endpoints (PrivateLink) and endpoint policies
- Protecting the edge: AWS WAF, Shield Standard vs Shield Advanced, and CloudFront with origin access control
- Encryption at rest with AWS KMS: AWS managed vs customer managed keys, key policies, envelope encryption and S3 SSE-S3, SSE-KMS and SSE-C
- Encryption in transit: ACM certificates, TLS on ALB and CloudFront, and enforcing HTTPS with aws:SecureTransport
- Secrets management: Secrets Manager rotation vs Systems Manager Parameter Store SecureString
- S3 data protection: Block Public Access, bucket policies, presigned URLs, versioning, MFA Delete and Object Lock modes
- Detection and compliance services: CloudTrail, AWS Config rules, GuardDuty, Inspector, Macie and Security Hub
Domain 2: Design Resilient Architectures
- Multi-AZ web tiers: Elastic Load Balancing (ALB vs NLB), Auto Scaling groups and ELB health checks
- Decoupling with Amazon SQS (standard vs FIFO, visibility timeout, dead-letter queues) and SNS fan-out
- Event-driven and serverless patterns: EventBridge, Lambda, Step Functions and API Gateway
- Containers on AWS: ECS vs EKS, and the Fargate vs EC2 launch types
- Relational database resilience: RDS Multi-AZ, read replicas, Aurora replicas and Aurora Global Database
- DynamoDB resilience: global tables, point-in-time recovery and on-demand backups
- Route 53 routing policies and health checks: failover, weighted, latency, geolocation and multivalue
- Disaster recovery strategies: backup and restore, pilot light, warm standby and multi-site active-active, matched to RPO and RTO
- Backup and replication: AWS Backup plans, S3 Cross-Region Replication, EBS snapshot and AMI copies, AWS Elastic Disaster Recovery
- Resilient hybrid networking: Site-to-Site VPN, Direct Connect with VPN backup, and Transit Gateway
- Infrastructure as code and service quotas: CloudFormation, StackSets and planning for limits and throttling
Domain 3: Design High-Performing Architectures
- EC2 instance families and placement groups (cluster, spread, partition), and enhanced networking with ENA and EFA
- EBS volume types and instance store: gp3 vs io2 Block Express vs st1 and sc1
- Shared file systems: Amazon EFS vs FSx for Windows File Server, FSx for Lustre and FSx for NetApp ONTAP
- S3 performance: prefixes, multipart upload, byte-range fetches and S3 Transfer Acceleration
- Caching: ElastiCache for Redis vs Memcached, DynamoDB Accelerator (DAX), lazy loading vs write-through
- Content delivery and global networking: CloudFront caching and TTLs vs AWS Global Accelerator
- Choosing a database: RDS, Aurora, DynamoDB, Redshift, DocumentDB, Neptune, and RDS Proxy for connection pooling
- DynamoDB performance: partition key design, provisioned vs on-demand capacity, auto scaling and secondary indexes
- Streaming ingestion: Kinesis Data Streams vs Amazon Data Firehose vs Amazon MSK
- Analytics services: Athena, AWS Glue, Lake Formation, EMR, Redshift Spectrum and QuickSight
- EC2 Auto Scaling policies: target tracking, step, simple, scheduled and predictive scaling
- Data migration and hybrid storage: DataSync, Snow Family, Storage Gateway, Transfer Family, DMS and SCT
Domain 4: Design Cost-Optimized Architectures
- EC2 purchase options: On-Demand, Reserved Instances, Compute vs EC2 Instance Savings Plans, Spot, Dedicated Instances and Dedicated Hosts
- Spot Instances in practice: interruption notices, mixed-instances Auto Scaling groups and allocation strategies
- Right-sizing compute: AWS Compute Optimizer, Graviton instances, and serverless vs always-on cost models
- S3 storage classes: Standard, Intelligent-Tiering, Standard-IA, One Zone-IA and the three Glacier classes
- S3 Lifecycle rules, S3 Storage Lens and Requester Pays
- Cutting EBS and backup costs: gp2 to gp3, Data Lifecycle Manager, snapshot archive and unattached volumes
- Database cost choices: DynamoDB on-demand vs provisioned, Aurora Serverless v2, reserved DB instances and stopping idle databases
- Data transfer costs: inter-AZ, inter-Region and internet egress, NAT gateway charges vs gateway endpoints, and CloudFront
- Cost visibility tools: Cost Explorer, AWS Budgets, Cost and Usage Reports, cost allocation tags and Trusted Advisor
- Consolidated billing in AWS Organizations: volume discounts and sharing Reserved Instance and Savings Plans benefits