0%

Get ready! Once you start, the timer will begin and cannot be paused. Good luck with your exam!

⏰ Time’s up! Your exam has ended.


AWS Solutions Architect Associate-saa-c03

Prepare with confidence using our AWS Solutions Architect Associate (SAA-C03) practice exam. Aligned to the official SAA-C03 blueprint, it covers the four exam domains: Design Secure Architectures, Design Resilient Architectures, Design High-Performing Architectures, and Design Cost-Optimized Architectures.

65 real exam-style questions

Timer-enabled practice to simulate the real exam

Detailed explanations for correct and incorrect answers

Instant results with score report

Passing score: 70%

Use this practice exam to assess your readiness, identify weak areas, and build the confidence you need to succeed in your AWS certification journey.

1 / 65

1. A company that manages multiple AWS accounts for different departments through AWS Organizations wants to restrict access to an Amazon S3 bucket containing project reports to only users from accounts within the organization.

2 / 65

2. A company recently deployed a RESTful API with Amazon API Gateway and AWS Lambda. The company uses API Gateway and Lambda to upload reports that are in PDF format and JPEG format. The company needs to modify the Lambda code to identify protected health information (PHI) in the reports.

Which solution will meet these requirements with the LEAST operational overhead?

3 / 65

3. A company that is moving its Windows workloads to AWS and has more than 5 TB of file data on Windows file servers that run on premises and needs access to AWS and on-premises file storage with minimum latency and minimal operational overhead and requires no significant changes to the existing file access patterns. The company uses an AWS Site-to-Site VPN connection for connectivity to AWS.

What should a solutions architect do to meet these requirements?

4 / 65

4. A company runs its infrastructure on AWS and has a registered base of 700,000 users for its document management application. The company intends to create a product that converts large .pdf files to .jpg image files. The .pdf files average 5 MB in size. The company needs to store the original files and the converted files. A solutions architect must design a scalable solution to accommodate demand that will grow rapidly over time. Which of the following solutions is the MOST cost-effective?

5 / 65

5. A company is deploying a new public web application to AWS. The application will run behind an Application Load Balancer (ALB). The application needs to be encrypted at the edge with an SSL/TLS certificate that is issued by an external certificate authority (CA). The certificate must be rotated each year before the certificate expires.

6 / 65

6. A company is developing a two-tier web application on AWS. The company's developers have deployed the application on an Amazon EC2 instance that connects directly to a backend Amazon RDS database. The company must not hardcode database credentials in the application. The company must also implement a solution to automatically rotate the database credentials on a regular basis.

7 / 65

7. A company has a website hosted on AWS behind an Application Load Balancer (ALB) that handles HTTP and HTTPS separately. The company wants to forward all requests to the website using HTTPS. Which of the following options should a solutions architect take to meet this requirement?

8 / 65

8. A company that hosts more than 300 global websites and applications needs to analyze more than 30 TB of clickstream data each day. Which of the following solutions should a solutions architect implement to transmit and process the clickstream data?

9 / 65

9. A company wants to run its critical applications in containers for scalability and availability, without managing the underlying infrastructure. The company prefers to focus on maintenance of the critical applications.

10 / 65

10. A company running a popular social media website is looking for a solution to prevent inappropriate content in user-uploaded images while minimizing development effort.

Which option should a solutions architect choose to meet the requirements?

11 / 65

11. A company has registered its domain name with Amazon Route 53 and is using Amazon API Gateway as a public interface for its backend microservice APIs. The company wants to design its API Gateway URL with the company's domain name and corresponding certificate so that the third-party services can use HTTPS.

12 / 65

12. A company needs to develop a VPC architecture for hosting applications that use Amazon EC2 instances and Amazon RDS DB instances. The architecture consists of six subnets in two Availability Zones, each having a public subnet, a private subnet, and a database-dedicated subnet. The company requires that only EC2 instances running in the private subnets can access the RDS databases.

13 / 65

13. A company running multiple Windows workloads on AWS needs to provide a highly available and durable storage solution for its employees using Windows file shares hosted on two Amazon EC2 instances. The file shares synchronize data between themselves and maintain duplicate copies. The company wants to preserve how users currently access the files.

14 / 65

14. A company needs to store its accounting records in Amazon S3. The records must be immediately accessible for 1 year and then must be archived for an additional 9 years. No one at the company, including administrative users and root users, can be able to delete the records during the entire 10-year period. The records must be stored with maximum resiliency.

15 / 65

15. A company is looking to migrate its on-premises application to AWS. The application generates output files of varying sizes, ranging from tens of gigabytes to hundreds of terabytes. The company requires a solution that scales automatically, is highly available, and requires minimal operational overhead, while also storing data in a standard file system structure. Which of the following solutions will meet these requirements?

16 / 65

16. A company is developing an application that generates shipping statistics for a REST API. The statistics need to be sent as an easy-to-read HTML report to multiple email addresses every morning. Which two steps should a solutions architect take to meet these requirements? (Choose two.)

17 / 65

17. A company needs to store call transcript files on a monthly basis. Users randomly access the files within 1 year of the call, but users access the files infrequently after 1 year. The company wants to optimize its solution by giving users the ability to query and retrieve files that are less than 1-year-old as quickly as possible. Retrieving older files may be delayed.

18 / 65

18. A company's website uses an Amazon EC2 instance store for its catalog of items, and they want to ensure high availability and durability for the catalog. Which of the following should a solutions architect do to meet these requirements?

19 / 65

19. A company needs to ensure Amazon EC2 capacity in three specific Availability Zones within a particular AWS Region for a week-long event.

Which of the following options should the company choose to guarantee the EC2 capacity?

20 / 65

20. A company provides marketing services to stores based on previous purchases by store customers. These stores upload transaction data to the company through SFTP, and the data is processed and analyzed to generate new marketing offers. However, the company discovered that some of the stores have uploaded files with personally identifiable information (PII) that should not have been included. The company wants administrators to be alerted if PII is shared again and wants to automate remediation. The solutions architect needs to meet these requirements with the least development effort.

Which option should the solutions architect choose?

21 / 65

21. A company has a data ingestion workflow that involves an Amazon SNS topic and an AWS Lambda function. The workflow occasionally fails due to network connectivity issues, and the Lambda function does not ingest data until a manual rerun is done.

22 / 65

22. A company has an Amazon S3 bucket that contains critical data. The company wants to ensure that the data is protected from accidental deletion. Which two steps should a solutions architect take to meet these requirements? (Choose two.)

23 / 65

23. A company's on-premises application generates a large amount of time-sensitive data that is backed up to Amazon S3. Due to the application's growth, users are complaining about internet bandwidth limitations. The solutions architect needs to design a long-term solution that allows for timely backups to Amazon S3 while minimizing the impact on internal user internet connectivity.

Which of the following solutions meets these requirements?

24 / 65

24. A company has a highly available image-processing application running on Amazon EC2 instances in a single VPC. The EC2 instances are spread across multiple Availability Zones and are located within several subnets. These instances do not communicate with each other, but they download and upload images to Amazon S3 through a single NAT gateway. The company wants to avoid Regional data transfer charges and is looking for a cost-effective solution.

Which of the following options will help the company achieve this goal?

25 / 65

25. A company's application integrates with multiple SaaS sources for data collection and uses Amazon EC2 instances to receive and upload the data to an Amazon S3 bucket. The company wants to improve application performance with minimal operational overhead.

26 / 65

26. A company that generates 1 TB of status alerts daily from thousands of edge devices needs a solution to ingest and store the alerts. Each alert is approximately 2 KB in size, and the company wants to keep 14 days of data available for immediate analysis and archive any data older than 14 days. The company also wants a highly available solution and wants to minimize costs while avoiding managing additional infrastructure.

27 / 65

27. A company maintains a searchable repository of items on its website. The data is stored in an Amazon RDS for MySQL database table that contains more than 10 million rows. The database has 2 TB of General Purpose SSD storage. There are millions of updates against this data every day through the company's website.The company has noticed that some insert operations are taking 10 seconds or longer. The company has determined that the database storage performance is the problem.

Which of the following solutions addresses this performance issue?

28 / 65

28. A company hosting a static website on Amazon S3 and using Amazon Route 53 for DNS is facing increased demand from around the world. The company needs to reduce latency for users accessing the website while keeping the cost low.

Which of the following solutions is the MOST cost-effective?

29 / 65

29. A company has launched new workloads on Amazon EC2 instances and needs a secure way to remotely access and administer them. They want a solution that follows the AWS Well-Architected Framework and has minimal operational overhead.

Which of the following options will meet the company's requirements?

30 / 65

30. A company is developing an AWS Cloud-based application that will utilize Amazon S3 buckets in two different AWS Regions to store data. The company requires the use of an AWS Key Management Service (AWS KMS) customer-managed key to encrypt all data stored in these buckets. The same KMS key must be used to encrypt and decrypt data in both S3 buckets, and the data and key must be stored in both regions. A company is developing an AWS Cloud-based application that will utilize Amazon S3 buckets in two different AWS Regions to store data. The company requires the use of an AWS Key Management Service (AWS KMS) customer-managed key to encrypt all data stored in these buckets. The same KMS key must be used to encrypt and decrypt data in both S3 buckets, and the data and key must be stored in both regions.

31 / 65

31. A company is planning to launch a public-facing web application in AWS Cloud. The web application will consist of Amazon EC2 instances in a VPC, behind an Elastic Load Balancer (ELB), with a third-party DNS service. The company's solutions architect needs to suggest a solution to detect and protect against large-scale DDoS attacks.

Which of the following solutions is the best fit for this scenario?

32 / 65

32. A company is hosting its multi-tier applications on AWS and needs to track configuration changes and record a history of API calls for compliance, governance, auditing, and security purposes.

33 / 65

33. A company runs an online marketplace web application on AWS. The application serves hundreds of thousands of users during peak hours. The company needs a scalable, near-real-time solution to share the details of millions of financial transactions with several other internal applications. Transactions also need to be processed to remove sensitive data before being stored in a document database for low-latency retrieval.

What should a solutions architect recommend to meet these requirements?

34 / 65

34. A team is planning to host a website that contains HTML, CSS, client-side JavaScript, and images. The website will be accessed by other teams, and they are looking for the most cost-effective hosting method.

35 / 65

35. A company that hosts its web application on AWS wants to ensure all Amazon EC2 instances, Amazon RDS DB instances, and Amazon Redshift clusters are configured with tags. The company wants to minimize the effort of configuring and operating this check.
What should a solutions architect do to accomplish this?

36 / 65

36. A company is running monthly resource-intensive tests on its general purpose Amazon RDS for MySQL DB instance with Performance Insights enabled. The testing lasts for 48 hours once a month and is the only process that uses the database. The company wants to reduce the cost of running the tests without reducing the compute and memory attributes of the DB instance.

Which of the following solutions is the MOST cost-effective?

37 / 65

37. A company that provides a Voice over Internet Protocol (VoIP) service over UDP connections needs to route users to the Region with the lowest latency and also require automated failover between Regions. Which of the following solutions should the company use to meet these requirements?

38 / 65

38. A company is migrating applications to AWS and managing the accounts centrally through AWS Organizations. They need a single sign-on (SSO) solution across all accounts using their self-managed Microsoft Active Directory.
Which solution will meet their requirements?

39 / 65

39. A company is launching a new application that will display application metrics on an Amazon CloudWatch dashboard. The product manager needs to access this dashboard periodically, but does not have an AWS account. The solution must follow the principle of least privilege.

40 / 65

40. A company needs to ensure that its Amazon S3 buckets do not have unauthorized configuration changes in its AWS Cloud deployment.

Which of the following should a solutions architect do to accomplish this goal?

41 / 65

41. A company is developing an application that receives data through Amazon API Gateway, which is then stored in an Amazon Aurora PostgreSQL database using an AWS Lambda function. During the proof-of-concept stage, the company needs to scale up Lambda quotas significantly to accommodate the high data volumes going into the database. The solutions architect must suggest a new design that enhances scalability and minimizes configuration effort.

Which of the following solutions is appropriate for meeting these requirements?

42 / 65

42. A company faces an increase in Amazon EC2 costs in its latest bill due to unwanted vertical scaling of instance types for a couple of EC2 instances. The billing team wants a solutions architect to create a graph comparing the last two months of EC2 costs and perform a detailed analysis to identify the cause of the vertical scaling. Which option would help the solutions architect generate the required information with minimal operational overhead?

43 / 65

43. A company needs a cost-effective storage solution for backup files that are frequently accessed for one month but then need to be kept indefinitely on Amazon S3 Standard storage. The company can choose one of the following options to meet these requirements:

44 / 65

44. A company's solutions architect is designing the storage architecture for their new digital media application using Amazon S3. The media files need to be resilient to the loss of an Availability Zone, with some files being accessed frequently and others accessed rarely in an unpredictable pattern. The company aims to minimize the costs of storing and retrieving the media files.

45 / 65

45. A company is planning to launch a one-deal-a-day website on AWS. The website will feature one product on sale for a period of 24 hours, and the company expects to handle millions of requests every hour with millisecond latency during peak hours.
Which of the following solutions will have the least operational overhead to meet these requirements?

46 / 65

46. A company needs to clone their production data into a test environment in the same AWS Region without affecting the original environment. The data is accessed by software that requires steady I/O performance. The solutions architect must reduce the time it takes to replicate the data into the test environment. The data is saved in Amazon EC2 instances on Amazon Elastic Block Store (EBS) volumes. Which option would fulfill these requirements?

47 / 65

47. A company has a three-tier web application on AWS. The web servers deploy in a public subnet, and application servers and database servers use private subnets in the same VPC. They also use a third-party virtual firewall appliance which is configured to accept IP packets. To inspect all traffic to the application before it reaches the web server, a solutions architect is required to integrate the web application with the appliance while minimizing operational overhead.

Which solution is the best fit for this scenario?

48 / 65

48. A company wants to ensure that two Amazon EC2 instances running a business application can access an Amazon S3 bucket used for document storage.

What would be the appropriate action for the solutions architect to take to meet this requirement?

49 / 65

49. A company with a data lake on AWS consisting of data in Amazon S3 and Amazon RDS for PostgreSQL needs a reporting solution that can provide data visualization and integrate all data sources within the data lake. Access to all visualizations should only be given to the management team while the rest of the company should only have limited access.

50 / 65

50. A company that recently migrated to AWS is looking for a solution to secure traffic in and out of the production VPC. The company used to have an inspection server in their on-premises data center to inspect and filter traffic flow, and they want the same functionality in the AWS Cloud.
Which option will fulfill their requirements?

51 / 65

51. A company's ecommerce application is running on Amazon EC2 instances behind an Application Load Balancer across multiple Availability Zones. The instances are managed by an Amazon EC2 Auto Scaling group, scaling based on CPU utilization metrics. The application stores transaction data in a MySQL 8.0 database hosted on a large EC2 instance. However, the database's performance degrades with increasing application load, especially for read requests. The company needs an automatic solution that can scale the database to handle unpredictable read workloads and ensure high availability.

Which of the following solutions will meet the company's requirements?

52 / 65

52. A company needs to rotate the credentials for its Amazon RDS for MySQL databases during monthly maintenance activities across multiple AWS Regions.

Which AWS solution requires the LEAST operational overhead to accomplish this?

53 / 65

53. A company hosts a web application on Amazon EC2 instances with an ALB and has both static and dynamic data, with the static data stored in an S3 bucket. The company's goal is to improve performance and lower latency for both types of data. Additionally, the company is using its own domain name registered with Amazon Route 53.
What should a solutions architect do to meet these requirements?

The correct answer is: A. To achieve this goal, a solutions architect should use AWS Secrets Manager and turn on automatic rotation.

This option is correct because AWS Secrets Manager is specifically designed to securely store, manage, and rotate credentials such as database usernames and passwords. It integrates natively with Amazon Aurora, supports automatic rotation without downtime, and provides secure API access for applications. This removes the need for storing credentials locally on EC2 instances, minimizing operational overhead and improving security.
More details: AWS Secrets Manager documentation

Option B: Incorrect because AWS Systems Manager Parameter Store can store secrets but does not natively provide automatic rotation. Implementing rotation would require additional Lambda and CloudWatch setup, increasing operational overhead.

Option C: Incorrect because storing credentials in Amazon S3 (even with KMS encryption) is not recommended for secret management. S3 lacks native credential rotation and fine-grained secret handling features.

Option D: Incorrect because using encrypted Amazon EBS volumes only secures credentials at rest. It does not address credential rotation, centralized storage, or application-level retrieval.

Summary: Option A is correct because AWS Secrets Manager provides the simplest, most secure, and automated way to handle Aurora database credentials with minimal operational effort.

54 / 65

54. A company running an application on Amazon EC2 instances with an Amazon Aurora database needs to simplify credential management. The EC2 instances use user names and passwords stored locally in a file. The company wants to minimize the operational overhead of credential management.
What is the recommended solution by the solutions architect to meet this objective?

55 / 65

55. A company is developing an e-commerce web application on AWS which transmits information regarding new orders to an Amazon API Gateway REST API for processing. The company's goal is to make certain that orders are processed as they arrive.
Which AWS solution would best address this requirement?

56 / 65

56. A company needs to increase its available storage space for frequently accessed large files that become rarely accessed after 7 days. The company's total data size is increasing and is close to its total storage capacity. To avoid future storage issues and maintain low-latency access to the most recently accessed files, a solutions architect must provide file lifecycle management. The company is currently running an SMB file server in its data center.

Which solution will meet these requirements?

57 / 65

57. A company planning to migrate a distributed application to AWS is seeking a modernized solution that ensures maximum resiliency and scalability. The application caters to variable workloads and comprises a primary server that coordinates jobs across several compute nodes on the legacy platform.

For this, how should a solutions architect design the architecture that meets the aforementioned requirements?

58 / 65

58. A company wants to enhance the scalability of its application that consumes incoming messages, which are then rapidly utilized by numerous microservices and applications. The message volume can greatly fluctuate, sometimes increasing to 100,000 per second.

59 / 65

59. A company wants to migrate large video files stored on an on-premises network attached storage via NFS to Amazon S3. The video files have a total storage of 70 TB and are of various sizes ranging from 1 MB to 500 GB. The company wants to migrate the data to S3 as soon as possible with the least possible network bandwidth usage. Which solution will satisfy these requirements?

60 / 65

60. A company is facing an issue in which users can only view a subset of their documents at a time on their web application hosted on AWS using two Amazon EC2 instances and EBS volumes behind an Application Load Balancer. The company wants a solution that ensures users can see all their documents at once.

61 / 65

61. An application hosted in an Amazon EC2 instance within a Virtual Private Cloud (VPC) needs to access log files stored in an S3 bucket without an internet connection.

Which of the following solutions provides private network connectivity to Amazon S3?

62 / 65

62. A company that manages multiple AWS accounts for different departments through AWS Organizations wants to restrict access to an Amazon S3 bucket containing project reports to only users from accounts within the organization.

63 / 65

63. A company has proprietary application log files stored in JSON format in an Amazon S3 bucket. The queries required for analysis are simple and run on demand without modifying the existing architecture.

64 / 65

64. A company's application development team is creating a microservice to compress and process large images stored in an Amazon S3 bucket. The company's solutions architect needs to design a solution using resilient, stateless components for automatic image processing.
Which two actions are needed for this requirement to be fulfilled? (Choose two.)

65 / 65

65. A company needs to aggregate data for temperature, humidity, and atmospheric pressure from multiple cities across continents in a single Amazon S3 bucket. The company wants to do it as quickly as possible while minimizing operational complexity. The average amount of data collected from each site daily is 500 GB, and each site has a high-speed internet connection.

Which solution meets these requirements?

Your score is

0%