AWS SAA-C03 Cheat Sheet 2026
A practical, scenario-focused revision reference for the AWS Certified Solutions Architect – Associate exam.
Scenario-Based · Architecture-Focused · Free to UseWhat This Cheat Sheet Covers
SAA-C03 is scenario-based: most questions describe a business situation and ask you to pick the best architectural fit, not just recall a service name. This page focuses on the comparisons and decision points that frequently matter in SAA-C03 scenario questions.
High-Yield Architectural Decisions
The format below matches how SAA-C03 scenario questions are evaluated: a requirement, a solution, and the core architectural reason it wins.
SCP vs Permission Boundary vs Identity Policy
See: "org-wide maximum permissions" → SCP. See: "cap what one user/role can do" → Permission boundary. Why: SCPs and boundaries constrain the ceiling; identity policies grant within it — an explicit Deny anywhere always wins.
VPC Peering vs Transit Gateway
See: a handful of VPCs, direct connectivity → Peering. See: many VPCs, transitive routing → Transit Gateway. Why: Peering is non-transitive; TGW is a routing hub built for scale.
ALB vs NLB
See: HTTP routing, path/host rules → ALB. See: static IP, raw TCP/UDP, extreme throughput → NLB. Why: ALB is Layer 7; NLB is Layer 4 passthrough.
KMS vs CloudHSM
See: standard managed encryption → KMS. See: "must own key material," FIPS 140-3 Level 3 → CloudHSM. Why: KMS is multi-tenant managed; CloudHSM is dedicated, customer-controlled hardware.
Lambda vs EC2 vs Fargate
See: short, event-driven, stateless → Lambda. See: full OS control, long-running → EC2. See: containers, no fleet management → Fargate.
EBS vs EFS vs FSx
See: single-instance block storage → EBS. See: shared Linux file system → EFS. See: Windows/AD or HPC file needs → FSx.
gp2 vs gp3
See: flexible IOPS/throughput without over-provisioning storage → gp3. Why: gp2 ties IOPS to volume size; gp3 configures IOPS and throughput independently — generally better price-to-performance.
RDS Multi-AZ vs Read Replica
See: "automatic failover / HA" → Multi-AZ (standby is not readable). See: "scale read traffic" → Read Replica (readable, async). These solve different problems.
RDS vs Aurora
See: read scaling + fast automatic failover in one design → Aurora. Why: Aurora Replicas (up to 15) can serve as automatic failover targets, while Aurora storage can automatically scale up to 256 TiB on supported engine versions.
DAX vs ElastiCache
See: microsecond DynamoDB reads with DynamoDB-compatible APIs → DAX. See: general caching, persistence, pub/sub → ElastiCache (Redis).
Geolocation vs Latency-Based Routing
See: compliance/localization by user location → Geolocation. See: fastest response time → Latency-based. Why: one routes by where the user is; the other by which Region responds fastest.
VPN vs Direct Connect
See: fast, low-cost setup → VPN. See: consistent dedicated bandwidth → Direct Connect. Trap: Direct Connect is not encrypted by default — pair it with VPN if encryption is required.
SQS vs SNS vs EventBridge
See: one producer, pull-based queue → SQS. See: fan-out to many subscribers → SNS. See: complex event routing/SaaS → EventBridge.
Backup & Restore → Multi-Site
See: "lowest cost" → Backup & Restore. See: "near-zero downtime" → Multi-Site Active/Active. Pilot Light and Warm Standby sit between them, trading cost for faster recovery.
Bedrock vs SageMaker
See: build on existing foundation models, no ML infra → Bedrock. See: train/fine-tune a custom model → SageMaker.
Top SAA-C03 Exam Traps
RDS Multi-AZ standby is for high availability, not read scaling — it isn't readable.
Read Replicas scale reads; they are not a high-availability failover mechanism by default.
SCPs set the maximum available permissions — they never grant permissions on their own.
Security Groups are stateful; Network ACLs are stateless and can explicitly deny traffic.
ALB operates at Layer 7 (HTTP-aware); NLB operates at Layer 4 (TCP/UDP passthrough).
S3 Standard-IA enforces a 30-day minimum storage duration before transition.
gp3 lets you configure IOPS and throughput independently of provisioned volume size.
Geolocation routing is based on the user's physical location, not response time.
Latency-based routing sends users to whichever AWS Region currently responds fastest.
Spot Instances can be interrupted when EC2 needs capacity back, typically with a 2-minute interruption notice.
Lambda's maximum execution timeout is 15 minutes; API Gateway times out at 29 seconds.
Direct Connect does not encrypt traffic by default — add a VPN if encryption is required.
S3 / EBS / Database Quick Reference
S3
- Versioning keeps prior object versions recoverable
- Object Lock (WORM) enforces compliance/governance retention
- Cross-Region Replication requires versioning enabled
- Presigned URLs grant time-limited private access
- Lifecycle rules move objects between tiers on a schedule
EBS
- gp3 decouples IOPS/throughput from volume size
- io2 Block Express: highest IOPS, sub-millisecond latency
- gp2 IOPS scale with volume size (3 IOPS/GiB)
RDS / Aurora
- Multi-AZ standby = HA only, not readable
- Read Replicas = readable, async, for read scaling
- Aurora Replicas double as automatic failover targets
- Aurora storage can automatically scale up to 256 TiB on supported engine versions
How to Work Through a Scenario Question
Identify the business requirement — restate it in plain terms.
Identify the constraints — budget, compliance, existing infrastructure.
Identify the priority — security, reliability, performance, or cost.
Eliminate technically valid but suboptimal answers — this is usually where points are lost.
Choose the solution that best matches the stated requirement.
Ready to Test Your SAA-C03 Knowledge?
Reading a cheat sheet is useful. Testing yourself reveals what you actually know.
Frequently Asked Questions
What is the AWS SAA-C03 Cheat Sheet?
A condensed, scenario-focused revision reference covering high-yield architectural decisions, service comparisons, and common exam traps for the AWS Certified Solutions Architect – Associate exam.
Is the SAA-C03 Cheat Sheet free?
Yes. This page and the downloadable PDF are both free to use.
Can I download the SAA-C03 Cheat Sheet as a PDF?
Yes, use the download button at the top of this page to get a print-friendly PDF version.
What topics does the cheat sheet cover?
IAM, networking, load balancing, compute, storage, databases, caching, DNS, hybrid connectivity, messaging, disaster recovery, cost optimization, and AI/ML service selection.
Is a cheat sheet enough to pass SAA-C03?
No. SAA-C03 is scenario-based, so a cheat sheet works best alongside hands-on practice and full-length practice exams — not as your only study material.
Where can I practice SAA-C03 scenario questions?
Take CloudExamPro's free 25-question SAA-C03 practice exam to test what you've reviewed here.
Study Smarter. Practice Smarter.
Use this cheat sheet for fast revision, then confirm what you know with real scenario questions.