AWS SAA-C03 Multiple choice 65 questions 130 minutes

AWS Certified Solutions Architect - Associate

Scenario questions on designing AWS architectures that are secure, resilient, fast and cost-aware, and on choosing between services that all look plausible.

The blueprint

A mock exam here has 65 questions in 130 minutes, split across the domains in the same proportions as the official exam guide. The official pass mark is 720 of 1,000 (scaled). FixOps scores practice against a target of 75%.

  1. 01

    Design Secure Architectures

    30%

  2. 02

    Design Resilient Architectures

    26%

  3. 03

    Design High-Performing Architectures

    24%

  4. 04

    Design Cost-Optimized Architectures

    20%

Sample questions

Three of the 10 questions in the free diagnostic. Open one to see the answer and why.

An application on Amazon EC2 instances in an Auto Scaling group must read objects from one S3 bucket. The security team forbids long-term credentials on the instances. What should a solutions architect do?
  • Attach an IAM role with read access to the bucket to the instances through an instance profile
  • Create an IAM user, and store its access keys in the instance user data
  • Make the bucket public and restrict it with a bucket naming convention
  • Store access keys in an encrypted file on the AMI

Answer: Attach an IAM role with read access to the bucket to the instances through an instance profile. An IAM role delivered through an instance profile gives the instances temporary credentials that rotate automatically, so nothing long-lived is stored. Keys in user data or baked into an AMI are still long-term credentials that can leak, and a public bucket removes access control entirely.

A three-tier web application has a load balancer, application servers and a database. Which placement follows security best practice?
  • Everything in one private subnet with an internet gateway route
  • Everything in public subnets with strict security groups
  • The database in a public subnet so administrators can reach it; the rest private
  • The load balancer in public subnets; application servers and the database in private subnets

Answer: The load balancer in public subnets; application servers and the database in private subnets. Only the component that must accept internet traffic, the load balancer, belongs in public subnets. Application and database tiers in private subnets have no direct route from the internet. A public database widens the attack surface, and a subnet with an internet gateway route is public by definition.

A company must encrypt objects in Amazon S3 and be able to audit every use of the encryption key, while controlling who may use the key. Which option meets these requirements?
  • Client-side Base64 encoding
  • No encryption, with a restrictive bucket policy
  • Server-side encryption with AWS KMS keys (SSE-KMS) using a customer managed key
  • Server-side encryption with Amazon S3 managed keys (SSE-S3)

Answer: Server-side encryption with AWS KMS keys (SSE-KMS) using a customer managed key. SSE-KMS with a customer managed key gives a key policy to control use and CloudTrail records of each key operation. SSE-S3 encrypts but offers no per-key access control or key usage audit, a bucket policy is not encryption, and Base64 is an encoding rather than encryption.

Revision notes: Design Secure Architectures

The notes for one domain, free to read here and in the app. FixOps Pro has them for all 4 domains.

Designing access for people, applications and accounts, protecting networks and applications in layers, and choosing how data is encrypted and who holds the keys.

Access to AWS

  • Workloads use IAM roles with temporary credentials: instance profiles, task roles, Lambda execution roles. Access keys in code are the wrong answer.
  • Cross-account access is a role with a trust policy, assumed through STS.
  • IAM Identity Center gives workforce single sign-on to many accounts from one identity source.
  • Service control policies in AWS Organizations set the maximum permissions of member accounts; they grant nothing by themselves.
  • A permissions boundary caps what an identity can be granted.
  • An explicit Deny wins over any Allow; across accounts both the identity policy and the resource policy must allow.
  • Amazon Cognito signs application users in (user pools) and exchanges identities for AWS credentials (identity pools).

Network protection

  • Security groups are stateful and attached to resources; a rule can name another security group as its source. Network ACLs are stateless, apply to a subnet and can deny.
  • Private subnets reach the internet through a NAT gateway; nothing from outside can start a connection to them.
  • Gateway endpoints (S3, DynamoDB) and interface endpoints (PrivateLink) keep traffic to AWS services off the internet.
  • AWS WAF blocks web exploits and rate-limits at CloudFront, an Application Load Balancer or API Gateway; Shield Advanced adds DDoS response; Network Firewall filters VPC traffic.
  • Systems Manager Session Manager replaces bastion hosts and open SSH ports.

Data protection

  • S3: Block Public Access, bucket policies, and server-side encryption with S3-managed keys, KMS keys or customer-provided keys.
  • CloudFront serves a private bucket through origin access control; signed URLs and cookies restrict who may fetch content.
  • KMS keys are customer managed (you control policy and rotation) or AWS managed. CloudHSM gives dedicated hardware.
  • Secrets Manager stores and rotates credentials; Parameter Store holds configuration and encrypted strings.
  • Encryption at rest for EBS and RDS is chosen at creation; an unencrypted database is encrypted by restoring an encrypted copy of a snapshot.
  • ACM issues TLS certificates for load balancers, CloudFront and API Gateway.

Detection and governance

  • CloudTrail records API activity; Config records configuration and checks rules; GuardDuty detects threats; Macie finds sensitive data; Inspector finds vulnerabilities.
  • Security Hub collects findings across accounts.
  • AWS Control Tower sets up a multi-account landing zone with guardrails.
  • S3 Object Lock and Glacier Vault Lock make data write-once for retention requirements.

Easy to mix up

  • A security group references another group to allow tier-to-tier traffic; a network ACL works on address ranges and needs rules in both directions.
  • Gateway endpoints are route table entries for S3 and DynamoDB; interface endpoints are network interfaces for most other services.
  • An SCP limits an account; an IAM policy grants to an identity inside it.
  • Secrets Manager rotates secrets; Parameter Store does not.

Practice questions written by FixOps from the public SAA-C03 exam guide. They are not real exam questions. FixOps is not affiliated with or endorsed by Amazon Web Services.

Your pager is ready.

Free, instant, and it works on your phone. No signup: start as a guest and save your progress later.