The most popular AWS certification: design secure, resilient, high-performing and cost-optimized architectures on AWS.
Set by Amazon Web Services (AWS)
Free to start · 38 lessons · 3 mock exams · about 42 h of study
You’ll sign in or create a free account first.
The AWS Certified Solutions Architect – Associate (SAA-C03) is the most widely held AWS certification. Cloud engineers, developers, sysadmins and aspiring architects take it to show they can design workloads on AWS that are secure, resilient, fast and cost-effective, following the AWS Well-Architected Framework. Employers use it as the baseline credential for cloud architecture roles, and it is the usual step before the Solutions Architect – Professional exam.
The exam is 65 scenario questions in 130 minutes. Every question describes a business requirement and asks for the design that meets it best: the most secure, the most cost-effective, or the one with the least operational overhead. Passing needs a scaled score of 720. A top result of 850+ shows you can see straight through the distractors, which are always real AWS services used in the wrong place.
Courselo follows the official content outline: 4 domains, 16 task statements and 38 focused lessons. Each lesson teaches the service trade-offs the exam tests, the keywords that decide between two plausible answers, and the traps written into the wrong options. Topic banks, a diagnostic and two full-length mocks timed like the real exam show you exactly which domain is costing you points. Your plan then works on those weak domains until you score 850 or more on every mock.
Format
2 h 10 min in total · 1 section
One continuous section of 65 scenario-based questions across the four content domains, in random domain order. You can flag, skip and return to any question until time expires. 50 questions are scored and 15 unscored items are mixed in without being identified.
Question types
Scoring
100–1000 · pass 720
Syllabus
4 units · 38 topics · about 42 h of lessons and core practice
≈ 3%1 h 15 min
IAM users, groups, roles and the policy types that grant or limit permissions. Covers how AWS evaluates a request, protecting the root user, and designing least-privilege authorization (task 1.1).
Your course
Lessons
38
One for every syllabus topic, written and answer-checked by our team
Practice questions
503
Each with a worked explanation, plus 400 flashcards. New ones are generated when you’ve seen them all.
Mock exams
3
1 diagnostic · 2 full-length, timed and scored like the real test
Strategy guides
10
Pacing, section strategy and test-day guides
Questions
Yes. As of September 2026 the official AWS exam guide is still SAA-C03, and AWS has not announced a successor exam. The guide is kept current with service renames (for example Amazon Quick, Amazon Data Firehose and Amazon SageMaker AI), and the course uses the current names. One change is scheduled: the Italian-language version retires after 31 December 2026. Before you book, check the AWS certification exam updates page for any newly announced version.
AWS does not publish a raw cut score. Your answers on the 50 scored questions are converted to a scaled score from 100 to 1,000, and 720 passes. In practice, about 70% correct on a realistic exam form is close to the pass line. Courselo’s curve uses that estimate. Aim for 78%+ on full mocks before booking and 85%+ for an 850+ result.
Set a target and a test date. You’ll take a diagnostic, see a predicted score with its range, and get a plan for every week until the exam.
Domain weighting of scored content: D1 Secure 30%, D2 Resilient 26%, D3 High-Performing 24%, D4 Cost-Optimized 20%. Multiple response items are all-or-nothing in practice: pick exactly the requested number. Non-native English speakers can request +30 minutes (ESL accommodation) once in their AWS Certification account before registering.
Delivery. Computer-based via Pearson VUE: at a test centre or online proctored (OnVUE). Available in English, Japanese, Korean, Simplified and Traditional Chinese, French, Portuguese (Brazil) and Spanish; the Italian version retires after 31 December 2026.
SAA-C03 is one timed, computer-based section of 65 questions in 130 minutes, which works out to exactly 2 minutes per question. 50 questions are scored and 15 are unscored. The unscored items are trial questions that AWS does not identify, so treat every question as if it counts.
Nearly every question is a short business scenario of 2 to 6 sentences. It ends with a requirement qualifier such as MOST cost-effective, LEAST operational overhead, MOST secure or highest availability. You can flag questions and review them before you submit. Unanswered questions are marked wrong and there is no penalty for guessing. No calculator is needed or provided.
The scored content is weighted by domain: Design Secure Architectures 30%, Design Resilient Architectures 26%, Design High-Performing Architectures 24% and Design Cost-Optimized Architectures 20%. You get a pass or fail result on a 100–1,000 scaled score (pass = 720). The score is compensatory, so you do not have to pass each domain separately.
Elite
About 90% or more correct. You beat almost every distractor, including the hardest multiple response items.
900
Top marks
The Courselo target. About 85% correct on full mocks, with no domain rated weak on the score report.
850
Safe pass
Buffer against a harder exam form. Book the exam once you score this on both full mocks.
780
Pass
The official minimum. About 70% correct on a Courselo full mock.
720
How AWS scores SAA-C03. Only 50 of your 65 answers count. The 15 unscored trial items are hidden among them. Your raw result on the scored items is converted to a scaled score from 100 to 1,000. The conversion is equated so that candidates who get a slightly harder mix of questions are not penalised. The pass mark is 720. Scoring is compensatory, so a strong Domain 1 can make up for a weak Domain 4. Your score report shows only whether each domain meets or needs improvement, not a per-domain score. There is no negative marking, so never leave a question blank.
How Courselo estimates your score. AWS does not publish the raw-to-scaled conversion. The Courselo curve is a realistic, slightly conservative estimate built from how scaled certification scores usually behave. About 70% correct maps to 720, 78% to about 780, 85% to about 850 and 90% to about 900. Every question in a Courselo mock is scored (no hidden trial items), so the curve uses the fraction of all mock questions you got right. Multiple response questions earn credit only when your selection matches every correct option exactly.
What the targets mean. A mock score of 720 means you would pass on a typical form, but with no margin. Aim for 780+ on both full mocks before you book. For top marks, keep practising until you reach 850+. At that level no domain drops below about 75%, and you consistently pick the right option when two answers are both technically possible.
| Band | From |
|---|---|
| PassMeets the AWS minimum standard; certification awarded. | 720+ |
| FailBelow 720. Retake after a 14-day wait and pay the full fee again. | 100+ |
≈ 3%1 h 15 min
Role-based access with AWS STS: instance profiles, role switching, cross-account roles and resource policies. Also workforce federation through IAM Identity Center, SAML/OIDC and AWS Directory Service, and when to federate a directory instead of creating IAM users (task 1.1).
≈ 2.5%1 h 5 min
Security strategy for many accounts. Covers AWS Organizations and OUs, service control policies and resource control policies as permission guardrails, Control Tower landing zones and controls, AWS RAM sharing, and centralised logging and security accounts (task 1.1).
≈ 4%1 h 30 min
Designing secure VPC architectures. Covers public and private subnet tiers, route tables, internet and NAT gateways, stateful security groups versus stateless network ACLs, security-group referencing, bastion versus Session Manager access, and VPC Flow Logs (task 1.2).
≈ 3%1 h 15 min
Keeping traffic private. Covers gateway endpoints (S3, DynamoDB) versus interface endpoints (PrivateLink), endpoint policies and aws:SourceVpce bucket conditions, exposing services privately with PrivateLink, and securing links to on premises with Site-to-Site VPN, Client VPN and Direct Connect (tasks 1.2 and 3.4).
≈ 2.5%1 h
Defending against threats from outside AWS such as DDoS, SQL injection, XSS and bots. Covers AWS WAF rules on CloudFront, ALB and API Gateway, Shield Standard versus Advanced, AWS Network Firewall for VPC traffic inspection, and Firewall Manager for organisation-wide policy (task 1.2).
≈ 2%50 min
Choosing the right managed security service for each job. GuardDuty detects threats, Inspector scans for vulnerabilities, Macie finds sensitive data, Detective investigates incidents and Security Hub aggregates findings. Automated response is built with EventBridge (task 1.2).
≈ 2.5%1 h
Securing application configuration and access. Covers Secrets Manager with automatic rotation versus Systems Manager Parameter Store, workload IAM roles instead of hard-coded keys, Cognito user pools versus identity pools, and ALB and API Gateway authentication options (task 1.2).
≈ 3.5%1 h 25 min
Encryption and key management. Covers KMS key types, key policies and grants, envelope encryption, rotation, multi-Region keys, CloudHSM for single-tenant FIPS keys, and how S3, EBS, RDS, DynamoDB and other services encrypt data. Includes encrypting an existing unencrypted resource (task 1.3).
≈ 2%55 min
Protecting data in Amazon S3. Covers bucket policies, Block Public Access, Object Ownership, access points, presigned URLs, versioning, MFA Delete, Object Lock retention modes and legal holds, replication for protection, and CloudFront origin access control (task 1.3).
≈ 2%1 h
Data in transit and governance. Covers TLS with AWS Certificate Manager (renewal, Region rules for CloudFront), enforcing HTTPS, auditing with CloudTrail, compliance with AWS Config rules and AWS Artifact, and protected backups with AWS Backup Vault Lock (task 1.3).
About 12 h 30 min of study, lessons and core practice
≈ 3.5%1 h 25 min
Loose coupling with queues, publish/subscribe and event buses. Covers SQS standard versus FIFO, visibility timeout, dead-letter queues, long polling, SNS fan-out, EventBridge rules, schedules and pipes, and Amazon MQ for existing protocols (task 2.1).
≈ 3%1 h 20 min
Serverless technologies and patterns. Covers Lambda triggers, limits, concurrency, memory sizing and VPC access; API Gateway REST, HTTP and WebSocket APIs with throttling and caching; and Step Functions Standard versus Express workflows for orchestration (task 2.1).
≈ 2.5%1 h 5 min
When and how to run containers. Covers ECS versus EKS, the EC2 and Fargate launch types, ECR, task roles, service auto scaling, ECS/EKS Anywhere for on-premises, and migrating monoliths or Kubernetes workloads into containers (task 2.1).
≈ 3.5%1 h 25 min
Horizontal scaling behind load balancers. Covers ALB, NLB and GWLB features, listeners, target groups, health checks, sticky sessions and cross-zone balancing, plus Auto Scaling groups, launch templates and scaling policies (target tracking, step, scheduled, predictive) with lifecycle hooks and warm pools (tasks 2.1 and 3.2).
≈ 2%55 min
Architectural principles and choosing managed services. Covers multi-tier and microservice design, stateless versus stateful components, externalising session state, horizontal versus vertical scaling, and purpose-built managed services such as Transfer Family, AppFlow, Amplify and the managed AI services (Rekognition, Textract, Comprehend, Transcribe, Translate, Polly, Lex, SageMaker AI) (tasks 2.1 and 2.2).
≈ 3.5%1 h 25 min
Highly available and fault-tolerant design inside a Region. Covers multi-AZ deployments, RDS Multi-AZ (instance vs cluster), Aurora failover, RDS Proxy, per-AZ NAT gateways, EFS and S3 regional durability, immutable infrastructure, and making legacy applications more reliable without code changes (task 2.2).
≈ 2.5%1 h
DNS-based availability and traffic management. Covers Route 53 routing policies (simple, weighted, latency, failover, geolocation, geoproximity, multivalue, IP-based), health checks, alias records, private hosted zones, and Resolver inbound and outbound endpoints for hybrid DNS (tasks 2.2 and 3.4).
≈ 3.5%1 h 25 min
Selecting and building a DR strategy that meets business RPO and RTO at the lowest cost. Covers backup and restore, pilot light, warm standby and multi-site active-active, cross-Region data replication (S3 CRR, Aurora Global Database, DynamoDB global tables, cross-Region read replicas), AWS Backup, and standby service quotas (task 2.2).
≈ 2%55 min
Visibility and automation that keep workloads healthy. Covers CloudWatch metrics, alarms, logs, dashboards and the unified agent, X-Ray tracing, the Health Dashboard, CloudFormation and Systems Manager for repeatable infrastructure, and service quotas and throttling (task 2.2).
About 10 h 55 min of study, lessons and core practice
≈ 3%1 h 15 min
Matching storage to performance demands. Covers EBS volume types (gp3, io2 Block Express, st1, sc1) and IOPS versus throughput, instance store, EBS Multi-Attach, EFS performance and throughput modes, and the four FSx file systems (Windows File Server, Lustre, NetApp ONTAP, OpenZFS) (task 3.1).
≈ 2%55 min
Scaling object storage and extending it to on premises. Covers S3 request-rate scaling by prefix, multipart upload, byte-range fetches, Transfer Acceleration, S3 Express One Zone, and the Storage Gateway types (S3 File, FSx File, Volume cached/stored, Tape) for hybrid storage (tasks 3.1 and 4.1).
≈ 2.5%1 h 5 min
Selecting and sizing compute for performance. Covers EC2 instance families and sizes, Graviton, enhanced networking (ENA) and EFA, cluster, spread and partition placement groups, AWS Batch and EMR for large jobs, Lambda memory sizing, and Outposts, Local Zones and Wavelength for low latency (task 3.2).
≈ 3%1 h 15 min
High-performing relational design. Covers RDS engines and storage (gp3, Provisioned IOPS), read replicas versus Multi-AZ, Aurora architecture (shared storage, reader/custom endpoints, auto scaling replicas, Serverless v2, Global Database), RDS Proxy connection pooling, and choosing between MySQL and PostgreSQL-compatible engines (task 3.3).
≈ 2.5%1 h 10 min
Non-relational and specialised databases. Covers DynamoDB keys, GSIs and LSIs, capacity modes, DAX, Streams, TTL, global tables and point-in-time recovery, and choosing DocumentDB, Neptune, Keyspaces, Redshift, OpenSearch or ElastiCache when the access pattern calls for it (task 3.3).
≈ 1.5%45 min
Integrating caches to meet performance requirements. Covers lazy loading versus write-through, TTLs and invalidation, ElastiCache (Redis OSS/Valkey vs Memcached), DAX, API Gateway and CloudFront caching layers, and session stores (tasks 2.1 and 3.3).
≈ 2.5%1 h 5 min
Using the AWS edge for global performance. Covers CloudFront origins, behaviours, cache keys and TTLs, signed URLs and cookies, origin failover, Lambda@Edge versus CloudFront Functions, and AWS Global Accelerator (anycast static IPs, TCP/UDP, fast Regional failover), including when to choose each (task 3.4).
≈ 2.5%1 h 15 min
Designing global, hybrid and multi-VPC topologies that scale. Covers CIDR planning and IP addressing (including IPv6), VPC peering (non-transitive) versus Transit Gateway hub-and-spoke, Direct Connect options (dedicated vs hosted, DX gateway, resilient designs, SiteLink), VPN as backup and ECMP, and shared VPCs (task 3.4).
≈ 1.5%50 min
Designing data streaming architectures. Covers Kinesis Data Streams (shards, ordering, retention, on-demand mode, replay), Amazon Data Firehose (managed delivery, buffering, format conversion to Parquet), Amazon MSK for Kafka, Kinesis Video Streams, and choosing streaming or queuing (task 3.5).
≈ 1.5%55 min
Building, securing and querying data lakes. Covers S3 as the lake, Glue crawlers, Data Catalog and ETL (CSV to Parquet), Athena serverless SQL, Lake Formation fine-grained permissions, EMR for Spark/Hadoop, Redshift and Redshift Spectrum, OpenSearch and Amazon Quick for visualisation (task 3.5).
≈ 1.5%55 min
Moving data and applications into AWS. Covers online transfer with DataSync, offline transfer with the Snow Family, SFTP/FTPS with Transfer Family, database migration with DMS and Schema Conversion (homogeneous vs heterogeneous), server rehosting with Application Migration Service, and the migration strategies (rehost, replatform, refactor and others) (tasks 3.5, 4.1 and 4.3).
About 11 h 25 min of study, lessons and core practice
≈ 2.5%55 min
The AWS cost-management toolkit that appears across all four Domain 4 tasks. Covers Cost Explorer, Budgets and budget actions, the Cost and Usage Report, cost allocation tags, consolidated billing and volume discounts, Trusted Advisor, Compute Optimizer and Savings Plans recommendations.
≈ 3%1 h 5 min
Cheapest adequate object storage. Covers S3 Standard, Intelligent-Tiering, Standard-IA, One Zone-IA, Glacier Instant Retrieval, Glacier Flexible Retrieval and Glacier Deep Archive, with retrieval times, minimum durations and object-size charges, lifecycle transitions and expiration, Requester Pays and Storage Lens (task 4.1).
≈ 2%55 min
Rightsizing non-object storage and choosing economical backup and archive options. Covers gp2 to gp3 migration, HDD volume types, EBS snapshot lifecycle and the archive tier, EFS lifecycle to Infrequent Access/Archive, FSx deployment and storage options, AWS Backup retention, Tape Gateway archives, and the cheapest data-transfer paths into AWS (task 4.1).
≈ 3.5%1 h 15 min
Choosing how to pay for compute. Covers On-Demand, Compute versus EC2 Instance Savings Plans, Standard versus Convertible Reserved Instances, Spot Instances and interruption handling, Spot and mixed-instance Auto Scaling groups, On-Demand Capacity Reservations, and Dedicated Hosts versus Dedicated Instances for licensing (task 4.2).
≈ 2.5%1 h
Architecture choices that lower compute cost. Covers rightsizing instance family and size, Graviton, containers and serverless (Lambda, Fargate) versus EC2, scheduled scale-down and hibernation for non-production, availability levels by workload class, choosing ALB, NLB or GWLB, and edge or hybrid compute (Outposts) (task 4.2).
≈ 3%1 h 5 min
Database cost optimisation. Covers RDS versus Aurora versus DynamoDB cost trade-offs, reserved DB instances, Aurora Serverless v2 and I/O-Optimized, DynamoDB on-demand versus provisioned and Standard-IA table class, caching instead of scaling up, snapshot and backup retention, columnar and time-series storage, and migrating to lower-cost engines (task 4.3).
≈ 3.5%1 h 10 min
Minimising network and data-transfer cost. Covers data-transfer pricing (inter-AZ, inter-Region, internet egress), gateway endpoints to avoid NAT processing charges, NAT gateway versus NAT instance and shared versus per-AZ NAT, peering versus Transit Gateway cost, Direct Connect versus VPN versus internet, CloudFront to cut egress, throttling strategies, and bandwidth sizing (task 4.4).
About 7 h 25 min of study, lessons and core practice
Free to start
Every lesson and guide is free, with 40 practice questions a day and the diagnostic. Pro removes the limits.
Compare plansThere is no penalty for guessing, and unanswered questions are marked wrong, so answer every question. Multiple response questions tell you how many options to pick (“Choose two.” or “Choose three.”). Treat them as all-or-nothing: you get credit only if your selection contains every correct option.
15 of the 65 questions are unscored trial items that AWS is testing for future exams. They look exactly like scored questions and are not identified, so give every question full effort. They are one reason a question can seem unusually obscure. Answer it, flag it if you need to, and move on.
AWS recommends at least a year of hands-on experience designing on AWS. With a year of AWS experience, most candidates need 6–8 weeks at 8–10 hours a week. Complete beginners should plan 10–12 weeks and take AWS Certified Cloud Practitioner or its lessons first. Hands-on practice in a free-tier or sandbox account (VPCs, IAM roles, S3 policies, Auto Scaling, RDS failover) makes scenario questions much faster to answer. Courselo’s study plan combines both.
Yes. You can take the exam at a Pearson VUE test centre or online proctored from home with a webcam, a clean desk and a stable connection. Online, you may not leave the camera view at any time. If English is not your first language, request the ESL +30 minutes accommodation once in your AWS Certification account before you register. It then applies to every future exam booking.
You must wait 14 calendar days before retaking, and you pay the full fee again. There is no limit on the number of attempts. Your score report shows which domains need improvement. Take the Courselo diagnostic again, work through those domains’ topic banks, and score 780+ on both full mocks before you rebook.
The certification is valid for 3 years. To recertify, pass the current Solutions Architect – Associate exam again, or earn the AWS Certified Solutions Architect – Professional certification, which also renews the Associate. Once you pass, you cannot retake the same exam version for two years.