AWS SAA-C03 Cheat Sheet 2026

A practical, scenario-focused revision reference for the AWS Certified Solutions Architect – Associate exam.

Scenario-Based · Architecture-Focused · Free to Use
65Questions
130 minDuration
720/1000Passing Score
$150Exam Cost
AWS / ITRecommended
Exam Domains

What This Cheat Sheet Covers

SAA-C03 is scenario-based: most questions describe a business situation and ask you to pick the best architectural fit, not just recall a service name. This page focuses on the comparisons and decision points that frequently matter in SAA-C03 scenario questions.

30%Design Secure Architectures
26%Design Resilient Architectures
24%Design High-Performing Architectures
20%Design Cost-Optimized Architectures
Core Reference

High-Yield Architectural Decisions

The format below matches how SAA-C03 scenario questions are evaluated: a requirement, a solution, and the core architectural reason it wins.

IAM

SCP vs Permission Boundary vs Identity Policy

See: "org-wide maximum permissions" → SCP. See: "cap what one user/role can do" → Permission boundary. Why: SCPs and boundaries constrain the ceiling; identity policies grant within it — an explicit Deny anywhere always wins.

Networking

VPC Peering vs Transit Gateway

See: a handful of VPCs, direct connectivity → Peering. See: many VPCs, transitive routing → Transit Gateway. Why: Peering is non-transitive; TGW is a routing hub built for scale.

Load Balancing

ALB vs NLB

See: HTTP routing, path/host rules → ALB. See: static IP, raw TCP/UDP, extreme throughput → NLB. Why: ALB is Layer 7; NLB is Layer 4 passthrough.

Encryption

KMS vs CloudHSM

See: standard managed encryption → KMS. See: "must own key material," FIPS 140-3 Level 3 → CloudHSM. Why: KMS is multi-tenant managed; CloudHSM is dedicated, customer-controlled hardware.

Compute

Lambda vs EC2 vs Fargate

See: short, event-driven, stateless → Lambda. See: full OS control, long-running → EC2. See: containers, no fleet management → Fargate.

Storage

EBS vs EFS vs FSx

See: single-instance block storage → EBS. See: shared Linux file system → EFS. See: Windows/AD or HPC file needs → FSx.

EBS

gp2 vs gp3

See: flexible IOPS/throughput without over-provisioning storage → gp3. Why: gp2 ties IOPS to volume size; gp3 configures IOPS and throughput independently — generally better price-to-performance.

Database

RDS Multi-AZ vs Read Replica

See: "automatic failover / HA" → Multi-AZ (standby is not readable). See: "scale read traffic" → Read Replica (readable, async). These solve different problems.

Database

RDS vs Aurora

See: read scaling + fast automatic failover in one design → Aurora. Why: Aurora Replicas (up to 15) can serve as automatic failover targets, while Aurora storage can automatically scale up to 256 TiB on supported engine versions.

Caching

DAX vs ElastiCache

See: microsecond DynamoDB reads with DynamoDB-compatible APIs → DAX. See: general caching, persistence, pub/sub → ElastiCache (Redis).

DNS

Geolocation vs Latency-Based Routing

See: compliance/localization by user location → Geolocation. See: fastest response time → Latency-based. Why: one routes by where the user is; the other by which Region responds fastest.

Hybrid

VPN vs Direct Connect

See: fast, low-cost setup → VPN. See: consistent dedicated bandwidth → Direct Connect. Trap: Direct Connect is not encrypted by default — pair it with VPN if encryption is required.

Messaging

SQS vs SNS vs EventBridge

See: one producer, pull-based queue → SQS. See: fan-out to many subscribers → SNS. See: complex event routing/SaaS → EventBridge.

Disaster Recovery

Backup & Restore → Multi-Site

See: "lowest cost" → Backup & Restore. See: "near-zero downtime" → Multi-Site Active/Active. Pilot Light and Warm Standby sit between them, trading cost for faster recovery.

AI/ML

Bedrock vs SageMaker

See: build on existing foundation models, no ML infra → Bedrock. See: train/fine-tune a custom model → SageMaker.

Watch For These

Top SAA-C03 Exam Traps

✕

RDS Multi-AZ standby is for high availability, not read scaling — it isn't readable.

✕

Read Replicas scale reads; they are not a high-availability failover mechanism by default.

✕

SCPs set the maximum available permissions — they never grant permissions on their own.

✕

Security Groups are stateful; Network ACLs are stateless and can explicitly deny traffic.

✕

ALB operates at Layer 7 (HTTP-aware); NLB operates at Layer 4 (TCP/UDP passthrough).

✕

S3 Standard-IA enforces a 30-day minimum storage duration before transition.

✕

gp3 lets you configure IOPS and throughput independently of provisioned volume size.

✕

Geolocation routing is based on the user's physical location, not response time.

✕

Latency-based routing sends users to whichever AWS Region currently responds fastest.

✕

Spot Instances can be interrupted when EC2 needs capacity back, typically with a 2-minute interruption notice.

✕

Lambda's maximum execution timeout is 15 minutes; API Gateway times out at 29 seconds.

✕

Direct Connect does not encrypt traffic by default — add a VPN if encryption is required.

Memorize This

S3 / EBS / Database Quick Reference

S3

  • Versioning keeps prior object versions recoverable
  • Object Lock (WORM) enforces compliance/governance retention
  • Cross-Region Replication requires versioning enabled
  • Presigned URLs grant time-limited private access
  • Lifecycle rules move objects between tiers on a schedule

EBS

  • gp3 decouples IOPS/throughput from volume size
  • io2 Block Express: highest IOPS, sub-millisecond latency
  • gp2 IOPS scale with volume size (3 IOPS/GiB)

RDS / Aurora

  • Multi-AZ standby = HA only, not readable
  • Read Replicas = readable, async, for read scaling
  • Aurora Replicas double as automatic failover targets
  • Aurora storage can automatically scale up to 256 TiB on supported engine versions
Exam Strategy

How to Work Through a Scenario Question

Identify the business requirement — restate it in plain terms.

Identify the constraints — budget, compliance, existing infrastructure.

Identify the priority — security, reliability, performance, or cost.

Eliminate technically valid but suboptimal answers — this is usually where points are lost.

Choose the solution that best matches the stated requirement.

Ready to Test Your SAA-C03 Knowledge?

Reading a cheat sheet is useful. Testing yourself reveals what you actually know.

FAQ

Frequently Asked Questions

What is the AWS SAA-C03 Cheat Sheet?

A condensed, scenario-focused revision reference covering high-yield architectural decisions, service comparisons, and common exam traps for the AWS Certified Solutions Architect – Associate exam.

Is the SAA-C03 Cheat Sheet free?

Yes. This page and the downloadable PDF are both free to use.

Can I download the SAA-C03 Cheat Sheet as a PDF?

Yes, use the download button at the top of this page to get a print-friendly PDF version.

What topics does the cheat sheet cover?

IAM, networking, load balancing, compute, storage, databases, caching, DNS, hybrid connectivity, messaging, disaster recovery, cost optimization, and AI/ML service selection.

Is a cheat sheet enough to pass SAA-C03?

No. SAA-C03 is scenario-based, so a cheat sheet works best alongside hands-on practice and full-length practice exams — not as your only study material.

Where can I practice SAA-C03 scenario questions?

Take CloudExamPro's free 25-question SAA-C03 practice exam to test what you've reviewed here.

Study Smarter. Practice Smarter.

Use this cheat sheet for fast revision, then confirm what you know with real scenario questions.

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access