Skip to content

Solutions Architect - Associate Practice Questions

Prepare for SAA-C03 with more than an answer.

270 questions in the full set20 sample questionsUpdated Feb 3, 2026

Unlock the full exam and previous versions

  • v1AWS Certified Solutions Architect - Associate 270 questions Current
  • SAA-C02Legacy AWS Certified Solutions Architect - Associate 301 questions Locked
Exam fee
$150 USD
Level
Associate
Valid for
3 years
Domains covered on the exam 4
  1. Design Secure Architectures30%
  2. Design Resilient Architectures26%
  3. Design High-Performing Architectures24%
  4. Design Cost-Optimized Architectures20%
  1. 1

    A company wants to establish a private, dedicated connection from its on-premises data center to its AWS VPCs. The company has multiple VPCs in the us-east-1 region and needs a scalable way to connect them to the on-premises network without creating complex peering meshes or multiple connections. Which architecture provides the most scalable and manageable solution?

    Show answer details

    Correct answer: C

    AWS Transit Gateway acts as a cloud router and simplifies network architecture. By establishing a single Direct Connect connection with a transit virtual interface (VIF) to a Transit Gateway, the company can connect its on-premises network to hundreds or thousands of VPCs in a hub-and-spoke model. This is highly scalable and much easier to manage than creating multiple VIFs or a complex VPC peering mesh.

  2. 2

    An e-commerce platform uses an Amazon SQS standard queue to process new orders. The processing is handled by a fleet of Amazon EC2 instances in an Auto Scaling group. During peak holiday sales, the number of messages in the SQS queue grows significantly, but the Auto Scaling group is slow to add new instances, causing delays in order processing. CloudWatch metrics show that the CPU utilization of the existing EC2 instances remains below 30%. What is the MOST effective way to ensure the Auto Scaling group scales in response to the order volume?

    Show answer details

    Correct answer: B

    The root cause of the issue is that the scaling trigger (CPU utilization) does not accurately reflect the workload (number of orders to process). Since the CPU is low, the scaling policy isn't triggered. The most direct and effective metric for this decoupled architecture is the number of messages waiting in the SQS queue. A target tracking policy based on ApproximateNumberOfMessagesVisible will automatically scale the number of consumer instances up or down to keep the queue backlog at a desired level.

  3. 3

    A company is using Amazon S3 Intelligent-Tiering for a dataset with unpredictable access patterns. The data is rarely accessed after 90 days. To further reduce costs, the company wants to automatically archive data that has not been accessed for 180 days to the lowest-cost storage suitable for long-term retention, where retrieval times of several hours are acceptable. Which actions should be taken? (Select TWO)

    Show answer details

    Correct answer: B, C

    S3 Intelligent-Tiering has optional, opt-in capabilities to automatically archive data. The first step is to activate the Archive Access or Deep Archive Access tiers in the storage class configuration.

    Once activated, you can configure the Deep Archive Access tier to automatically move objects that have not been accessed for a specified period (e.g., 180 days) to S3 Glacier Deep Archive, which is the lowest-cost S3 storage class.

  4. 4

    A company is deploying an internal application on Amazon EC2 instances that needs to access several AWS services, including Amazon S3 and Amazon DynamoDB. According to security best practices, a solutions architect must provide credentials to the application without storing long-term access keys on the instances. What is the most secure and recommended method to grant these permissions?

    Show answer details

    Correct answer: B

    The best practice for granting permissions to applications running on EC2 instances is to use IAM roles. You create a role with the required permissions policies and then attach this role to the instance via an instance profile. The AWS SDKs and CLI on the instance can then automatically retrieve temporary credentials from the instance metadata service, eliminating the need to manage and store long-term access keys on the instance itself.

  5. 5

    A solutions architect is designing a networking strategy for a company that has hundreds of VPCs across multiple AWS accounts in a single region. The company needs to enable inter-VPC communication and also provide a single point of connectivity to their on-premises network via AWS Direct Connect. The solution must be scalable and avoid complex VPC peering configurations.

    Which service should be the central component of this design?

    Show answer details

    Correct answer: B

    AWS Transit Gateway is designed to solve this exact problem. It acts as a central hub (a cloud router) that connects VPCs and on-premises networks. This hub-and-spoke model simplifies management and scales easily, as each new VPC only needs to connect to the Transit Gateway instead of being peered with every other VPC. It also provides a single connection point for the on-premises network.

  6. 6

    A media company is streaming a major live event to a global audience. The company uses an Application Load Balancer (ALB) in front of a fleet of EC2 instances. During the event, a DDoS attack is detected. The company has AWS Shield Advanced. Which AWS service should be used in conjunction with the ALB to provide immediate, automated mitigation against common application-layer attacks like SQL injection and cross-site scripting?

    Show answer details

    Correct answer: C

    AWS WAF (Web Application Firewall) is the service designed to protect web applications from common web exploits. It integrates directly with Application Load Balancers, Amazon CloudFront, and API Gateway. By applying managed rule sets (e.g., for SQL injection) and custom rules, it can filter and block malicious traffic at the application layer (Layer 7). While AWS Shield Advanced provides DDoS protection, AWS WAF provides the specific application-layer filtering needed.

  7. 7

    Case Study

    A global shipping company, 'GlobalShip', runs its primary logistics management platform in the eu-west-1 AWS Region. The platform is critical for operations and consists of a web front end on Amazon EC2 instances behind an Application Load Balancer, an order processing service on AWS Fargate, and an Amazon Aurora PostgreSQL database. Static assets like shipping labels and documents are stored in Amazon S3.

    Business Requirements:
    Management has mandated a disaster recovery (DR) plan with a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of less than 1 second. The DR site will be in the us-east-1 Region. The solution must provide a single, consistent entry point for global users and automatically fail over in the event of a regional outage.

    Technical Constraints:

    • The database must support transactional consistency.
    • The solution should minimize data transfer costs during normal operations.
    • Failover must be automatic, requiring no manual intervention.

    Which architecture should the solutions architect propose to meet all these requirements?

    graph TD subgraph eu-west-1 (Primary) ALB1[ALB] Fargate1[Fargate] AuroraW[Aurora Writer] S3_EU[S3 Bucket] end subgraph us-east-1 (DR) ALB2[ALB] Fargate2[Fargate] AuroraR[Aurora Reader] S3_US[S3 Bucket] end User --> AGA AGA{AWS Global Accelerator} --> ALB1 AGA --> ALB2 AuroraW -- Replication --> AuroraR S3_EU -- CRR --> S3_US
    Show answer details

    Correct answer: C

    This solution meets all requirements. Amazon Aurora Global Database provides an RPO of less than 1 second through physical replication and an RTO of less than 1 minute, which fits the 15-minute RTO requirement. AWS Global Accelerator provides a static entry point and automatic, rapid failover (within a minute) based on health checks, satisfying the automatic failover requirement. S3 CRR handles the static assets. A pilot light or warm standby deployment in the DR region ensures resources are ready to be scaled up, meeting the RTO. Route 53 failover can have longer DNS propagation delays, and DynamoDB does not meet the transactional consistency requirement of a relational database like Aurora PostgreSQL.

  8. 8

    A financial services company is deploying a critical trading application on AWS that requires extremely low latency communication between a set of Amazon EC2 instances. The application is sensitive to network jitter and must be deployed in a way that minimizes the network path between instances. The architecture must also be resilient to the failure of a single underlying server rack within an Availability Zone. Which deployment strategy should a solutions architect recommend?

    Show answer details

    Correct answer: C

    A partition placement group provides the best balance for this scenario. It spreads instances across distinct underlying hardware (partitions/racks) within an Availability Zone, reducing correlated failures. At the same time, it keeps the instances geographically close within that AZ, which is crucial for low-latency communication. A cluster placement group offers the lowest latency but places instances on the same rack, making it vulnerable to a single rack failure. A spread placement group across multiple AZs would introduce higher latency, which is not suitable for the trading application's requirements.

  9. 9

    A company is migrating its on-premises data warehouse to Amazon Redshift. The security team has mandated that all data loaded into Redshift from Amazon S3 must be encrypted in transit and that the connection must not traverse the public internet. The EC2 instances that orchestrate the COPY commands are located in a private subnet within the same Region as the Redshift cluster and the S3 bucket.

    Which combination of actions will meet these security requirements? (Select TWO)

    Show answer details

    Correct answer: A, B

    A gateway VPC endpoint for Amazon S3 allows traffic from the VPC to S3 to travel over the AWS private network, avoiding the public internet. This is a critical component for meeting the security requirement.

    Enhanced VPC Routing forces all COPY and UNLOAD traffic between the Redshift cluster and data repositories (like S3) to go through the VPC. When used with a VPC endpoint, it ensures the traffic stays on the AWS private network.

  10. 10

    A healthcare provider uses an application that processes patient data. The application runs on Amazon EC2 instances and stores data in an Amazon RDS for PostgreSQL database. To comply with regulations, all database credentials must be rotated every 30 days without causing application downtime. The application code cannot be modified to handle credential rotation logic. Which solution provides the MOST secure and automated way to meet this requirement?

    Show answer details

    Correct answer: B

    AWS Secrets Manager is the ideal service for this use case. It provides native integration with Amazon RDS for automated credential rotation, which updates the secret in Secrets Manager and the password in the database simultaneously. Since the application cannot be modified, using IAM authentication or an RDS Proxy would not work. By granting the EC2 instance's IAM role permission to read the secret, the application can fetch the current credentials at runtime without hardcoding them.

Create an account to continue.