Where the points between 720 and 850 are lost
Candidates who stall in the 720–780 range almost never fail on raw service knowledge. They lose points in four predictable ways:
| Loss pattern | What it looks like | Typical cost |
|---|---|---|
| Qualifier blindness | Picks a design that works but ignores MOST cost-effective or LEAST operational overhead | 3–5 questions |
| Over-engineering | Chooses multi-Region active-active when pilot light meets the stated RTO, or a custom Lambda script when a native feature exists | 2–4 questions |
| Near-miss knowledge | Knows SQS but not that FIFO is needed for “exactly once, in order”; knows KMS but not that cross-account use needs the key policy and IAM | 3–6 questions |
| Multiple response errors | Gets one of the two answers right and the item still scores zero | 2–3 questions |
Top scorers remove all four. None of these is fixed by reading more documentation. They are fixed by practising decisions.
Score bands: what each level looks like
| Courselo mock score | Percent correct | What you can do at this level |
|---|---|---|
| Below 610 | under 55% | You recognise service names but cannot map a requirement to a service. Security groups vs NACLs and S3 classes still cause errors. |
| 610–719 | 55–69% | You know the core services. On two-plausible-answer items you are right about half the time, and most multiple response items are wrong. |
| 720–779 | 70–77% | A pass, with little margin. One or two domains (often networking and cost) regularly score needs improvement. |
| 780–849 | 78–84% | A safe pass. You lose points mainly on hard items: KMS and cross-account policy logic, DR nuance, data-transfer cost, hybrid networking. |
| 850–899 | 85–89% | Top marks. Every domain is at 75% or more, you read qualifiers automatically, and you get most multiple response items right. |
| 900+ | 90%+ | Elite. You reliably pick the cheapest or simplest option when every option works. |
The six habits that separate 850+ scorers
1. Learn decision rules, not facts
“SQS has a visibility timeout” is a fact. “Messages are processed twice → the visibility timeout is shorter than the processing time → raise it” is a decision rule, and the exam tests the rule. Every Courselo lesson ends with rules like this. Write your own on flashcards in the form trigger → answer:
- Shared POSIX file system across AZs for Linux → EFS
- SMB + Active Directory → FSx for Windows File Server
- Static IPs + UDP + global users → Global Accelerator
- Stateless + interruptible + cheapest → Spot
- Private subnet → S3 without NAT charges → S3 gateway endpoint
2. Read the qualifier first
Read the final sentence before the scenario. The qualifier (MOST cost-effective, LEAST operational overhead, MOST secure, highest availability, fewest code changes) tells you which of the working answers wins. The Decoding scenario questions guide gives the full method.
3. Eliminate by violated requirement
Each wrong option breaks a specific stated requirement. Name the requirement it breaks: “B needs code changes, and the stem says none”, or “D is single-AZ, and the stem says highly available”. If you cannot name one, the option is still in play. This habit alone fixes most over-engineering errors.
4. Study in proportion to the weights
Domain 1 (Secure) is 30% of scored content, about 15 of 50 questions. Domain 4 (Cost) is 20%, about 10. Several single topics carry more marks than whole service families: VPC security, KMS, decoupling, load balancing and Auto Scaling, multi-AZ HA, DR, purchasing options and network cost. Master those first.
5. Run an error log with causes, not just answers
After every bank set and mock, log each miss under one cause:
- K (knowledge gap): you did not know the feature. Fix: reread the lesson section and add a flashcard.
- Q (qualifier): you picked a working answer that failed the qualifier. Fix: redo the item and say the qualifier out loud.
- R (misread): you missed a constraint such as “existing Kafka” or “without managing servers”. Fix: slow down on stems.
- C (changed answer): you switched from right to wrong on review. Fix: only change an answer when you find new evidence in the stem.
By week 6 your log should be mostly Q and R entries. Those are the cheapest points to recover.
6. Build a small amount of hands-on memory
You do not need to build production systems. You do need to have seen the key pieces: an IAM role assumed across accounts, a bucket policy that denies non-TLS requests, a private subnet route table with a NAT gateway and a gateway endpoint, an ALB with an Auto Scaling group, an RDS Multi-AZ failover, and an SQS queue with a dead-letter queue. About 6–8 hours of guided labs in a sandbox account make scenario questions noticeably faster.
Timing plan
You have 130 minutes for 65 questions, 2 minutes each. Plan your first pass at 1 minute 40 seconds per question so you keep a review buffer:
| Checkpoint | Question | Clock time used |
|---|---|---|
| 1 | 15 | 25 min |
| 2 | 30 | 50 min |
| 3 | 45 | 75 min |
| 4 | 60 | 100 min |
| End of pass 1 | 65 | about 108 min |
| Review of flagged items | — | about 20 min |
Short items take about 1 minute; long multiple response items up to 3. Stuck after 2 minutes? Pick your best remaining option, flag it and move on. Never leave a blank.
Week-by-week plan to 850+
This plan assumes about 8–10 hours a week and some AWS experience. The 8-week study plan guide has the day-by-day version and a 4-week fast track.
| Week | Focus | Checkpoint target |
|---|---|---|
| 1 | Diagnostic (24 questions, 48 min). D1: IAM, roles and federation, Organizations and SCPs, VPC security, endpoints | Baseline recorded; D1 banks 70%+ |
| 2 | D1: WAF and Shield, threat detection, secrets, KMS, S3 protection, TLS and auditing | All D1 banks 75%+ on first attempt |
| 3 | D2: decoupling, serverless, containers, load balancing and Auto Scaling, stateless design | D2 banks 75%+ |
| 4 | D2: multi-AZ HA, Route 53, DR, observability. Timed mixed set of D1 and D2 items | Mixed set 75%+ |
| 5 | D3: EBS, EFS and FSx, S3 performance, compute, RDS and Aurora, DynamoDB, caching | D3 banks 75%+ |
| 6 | D3: CloudFront and Global Accelerator, network topology, streaming, data lakes, migration | Mixed D1–D3 set 80%+ |
| 7 | D4: all seven cost topics. Full mock 1 at the end of the week | Mock 1: 780+ |
| 8 | Fix the error log, full mock 2 mid-week, final flashcard review, exam | Mock 2: 850+ |
Common traps
Quick recap
- The 720-to-850 gap is about 7–8 questions, lost mostly to qualifiers, over-engineering and near-miss knowledge.
- Drill trigger-to-answer rules; read the qualifier first; eliminate by naming the broken requirement.
- Study in proportion to domain weight, log misses by cause, and pace at 1:40 per question.