Amazon

SAA-C03 Practice Test: 10 Original Questions

Ten scenario questions covering the four SAA-C03 domains: secure, resilient, high-performing and cost-optimized architectures. Each one asks you to pick the design an AWS solutions architect would defend in a review, and each answer links to the AWS documentation page it rests on.

These questions were written for CertBlaze from the official AWS Certified Solutions Architect - Associate exam guide, with AI assistance. They are not taken from the real exam, an exam dump or any other question bank. Each answer names the official page it is based on; if you spot a mistake, please tell us.

What this set covers

  • Design Secure Architectures: 2 questions
  • Design Resilient Architectures: 3 questions
  • Design High-Performing Architectures: 3 questions
  • Design Cost-Optimized Architectures: 2 questions

Question 1

Design Secure Architectures

A video-sharing startup stores user uploads in a private Amazon S3 bucket. The mobile app must upload files straight to S3 instead of streaming them through the app servers, and an upload should only be possible for a few minutes after the backend has approved it. The bucket must stay private. What should the solutions architect recommend?

A. Allow public PutObject on the bucket and scan new objects with an AWS Lambda function.
B. Create an IAM user with s3:PutObject permission and ship its access keys inside the mobile app.
C. Have the backend generate a presigned URL for the PUT request with a short expiration and return it to the app.
D. Enable S3 Transfer Acceleration and let the app upload anonymously to the accelerate endpoint.
Show Answer
Correct Answer: C
Explanation:
A presigned URL carries the permissions of the identity that signed it, applies to one object and operation, and expires after the time the backend sets, so the bucket stays private and uploads skip the app servers. Public write access (A) invites abuse. Long-term access keys embedded in a mobile app (B) can be extracted and reused. Transfer Acceleration (D) speeds up transfers but does not authorize them.
Source: Uploading objects with presigned URLs (Amazon S3 User Guide)

Question 2

Design Secure Architectures

Amazon EC2 instances in private subnets read objects from an S3 bucket in the same AWS Region. The security team requires that this traffic stays off the internet and that the bucket rejects requests that do not come through the company's VPC. Which solution meets both requirements?

A. Route the traffic through a NAT gateway and allow only the NAT gateway's Elastic IP address in the bucket policy.
B. Enable S3 Transfer Acceleration and restrict the bucket with an aws:SourceVpc condition.
C. Attach an internet gateway and restrict the bucket policy with an aws:SourceIp condition listing the instances' private IP addresses.
D. Create an S3 gateway VPC endpoint, add it to the private subnets' route tables, and add a bucket policy that denies requests whose aws:SourceVpce is not that endpoint.
Show Answer
Correct Answer: D
Explanation:
A gateway endpoint gives the private subnets a route to S3 that never leaves the AWS network and needs no NAT device. The aws:SourceVpce condition key lets the bucket policy deny anything that did not arrive through that endpoint. A NAT gateway (A) sends traffic to S3's public endpoints. aws:SourceIp (C) cannot match private addresses of requests made through a VPC endpoint. Transfer Acceleration (B) uses public edge locations.
Source: Controlling access from VPC endpoints with bucket policies (Amazon S3 User Guide)

Question 3

Design Resilient Architectures

An online shop's checkout service calls an inventory service synchronously. During promotions the inventory service falls behind, requests time out, and some orders are lost. The team can change how checkout hands orders off, but the inventory service must keep processing at its own pace and no order may be dropped. What should the solutions architect do?

A. Raise the Application Load Balancer idle timeout to the maximum value.
B. Have checkout send each order to an Amazon SQS queue and let the inventory service poll the queue.
C. Replace the Application Load Balancer with a Network Load Balancer.
D. Put Amazon CloudFront in front of the checkout service to cache order requests.
Show Answer
Correct Answer: B
Explanation:
An SQS queue decouples the two services: checkout writes orders durably, and the inventory service consumes them when it has capacity, so spikes queue up instead of failing. Messages are kept until a consumer deletes them (up to the retention period). A longer idle timeout (A) only delays the failure. A Network Load Balancer (C) does not buffer work. CloudFront (D) does not cache order submissions.
Source: What is Amazon Simple Queue Service? (Amazon SQS Developer Guide)

Question 4

Design Resilient Architectures

A company runs a MySQL database on Amazon RDS in a single Availability Zone. The business now requires that the database survives the loss of an Availability Zone with automatic failover and without losing committed transactions. Read scaling is not needed. What should the solutions architect do?

A. Modify the instance to a Multi-AZ DB instance deployment.
B. Create a read replica in another Availability Zone and promote it manually during an outage.
C. Take a manual snapshot every 5 minutes and copy it to another Availability Zone.
D. Move the database to Amazon EC2 and attach one Amazon EBS volume to instances in two Availability Zones.
Show Answer
Correct Answer: A
Explanation:
A Multi-AZ DB instance deployment keeps a standby in a second Availability Zone with synchronous replication and fails over automatically, so committed data is not lost. Read replicas (B) replicate asynchronously and need a manual promotion. Snapshots (C) leave a gap between copies and require a restore. An EBS volume (D) lives in one Availability Zone.
Source: Multi-AZ DB instance deployments (Amazon RDS User Guide)

Question 5

Design Resilient Architectures

A critical web application runs in us-east-1 with its data in Amazon Aurora MySQL. The disaster recovery plan must achieve a recovery point objective (RPO) of seconds and a recovery time objective (RTO) of minutes in another Region, at a lower cost than running full production capacity in two Regions. Which strategy fits?

A. Backup and restore: copy daily Aurora snapshots to us-west-2.
B. Multi-site active/active: run full production capacity in both Regions.
C. Pilot light: copy only the AMIs to us-west-2 and recreate the database from scratch during a disaster.
D. Warm standby: an Aurora global database with a secondary cluster in us-west-2 and a scaled-down copy of the application tier there.
Show Answer
Correct Answer: D
Explanation:
An Aurora global database replicates to the secondary Region with typical lag under a second, which meets an RPO of seconds, and a scaled-down but running application tier can be scaled up within minutes. Daily snapshots (A) mean an RPO of up to a day. Recreating the database (C) cannot meet either objective. Active/active (B) meets the objectives but at the cost the company wants to avoid.
Source: Disaster recovery options in the cloud (AWS whitepaper)

Question 6

Design High-Performing Architectures

A news site serves images, CSS and JavaScript from an S3 bucket in us-east-1 to readers around the world. Readers in Asia and Europe report slow page loads. The company wants lower latency for these static assets while keeping the bucket private. What should the solutions architect do?

A. Enable S3 Transfer Acceleration on the bucket.
B. Replicate the bucket to one bucket per continent and use Amazon Route 53 latency routing to the buckets' website endpoints.
C. Create an Amazon CloudFront distribution with the bucket as its origin, restrict the bucket to CloudFront with origin access control, and serve the assets through CloudFront.
D. Copy the assets to Amazon EBS volumes on EC2 web servers in several Regions.
Show Answer
Correct Answer: C
Explanation:
CloudFront caches the assets at edge locations close to readers, and origin access control lets the bucket refuse every request that does not come from the distribution. Transfer Acceleration (A) speeds long-distance transfers to the bucket but caches nothing. S3 website endpoints (B) require public read access. Running EC2 web servers per Region (D) adds cost and operations for no benefit over a CDN.
Source: Restricting access to an Amazon S3 origin (Amazon CloudFront Developer Guide)

Question 7

Design High-Performing Architectures

A mobile game stores player profiles in an Amazon DynamoDB table. The same popular items are read thousands of times per second, writes are rare, and the game needs read latency in microseconds rather than milliseconds. Which change achieves this with the least application rework?

A. Add a global secondary index on the player ID.
B. Put a DynamoDB Accelerator (DAX) cluster in front of the table and point the reads at it.
C. Switch the table from provisioned to on-demand capacity mode.
D. Stream changes with DynamoDB Streams into an Amazon RDS read replica and read from the replica.
Show Answer
Correct Answer: B
Explanation:
DAX is an in-memory cache built for DynamoDB that serves eventually consistent reads in microseconds and uses an API compatible with DynamoDB, so the code change is small. A global secondary index (A) supports other query patterns, not lower latency. On-demand mode (C) changes how capacity is billed, not response time. Streaming into RDS (D) adds a second database and would be slower.
Source: In-memory acceleration with DynamoDB Accelerator (DAX) (Amazon DynamoDB Developer Guide)

Question 8

Design High-Performing Architectures

A genomics team runs a high-performance computing job on hundreds of Linux EC2 instances. The job needs a shared POSIX file system with sub-millisecond latency and very high aggregate throughput. Input data lives in an S3 bucket, and results must end up back in that bucket. Which storage option fits best?

A. Amazon FSx for Lustre linked to the S3 bucket
B. Amazon EFS with the Standard storage class
C. An S3 File Gateway mounted on every instance
D. Amazon FSx for Windows File Server
Show Answer
Correct Answer: A
Explanation:
FSx for Lustre is a parallel file system designed for HPC throughput, and it can be linked to an S3 bucket so objects appear as files and results can be exported back. EFS (B) is a general purpose NFS file system without the same HPC throughput profile or the S3 link. S3 File Gateway (C) is meant for on-premises access to S3. FSx for Windows File Server (D) serves SMB to Windows workloads.
Source: What is Amazon FSx for Lustre? (FSx for Lustre User Guide)

Question 9

Design Cost-Optimized Architectures

A nightly batch job transcodes files on a fleet of EC2 instances. The job writes checkpoints, can be interrupted and resumed, and only has to finish before 6 a.m. Which purchasing option gives the lowest compute cost?

A. On-Demand Instances
B. Dedicated Hosts
C. Three-year Standard Reserved Instances
D. Spot Instances
Show Answer
Correct Answer: D
Explanation:
Spot Instances use spare EC2 capacity at a steep discount and can be reclaimed with a two-minute warning, which suits interruptible, checkpointed work with a flexible deadline. On-Demand (A) costs more for the same work. Reserved Instances (C) pay off for steady 24/7 usage, not a nightly job. Dedicated Hosts (B) exist for licensing and compliance needs and cost the most.
Source: Spot Instances (Amazon EC2 User Guide)

Question 10

Design Cost-Optimized Architectures

An application writes logs to Amazon S3. Logs are read often for 30 days, then rarely until day 180 (when they are read, millisecond access is needed). After 180 days they are almost never read, retrieval within 12 hours is acceptable, and they must be kept for 7 years. Which S3 Lifecycle configuration costs the least?

A. S3 Standard, then S3 Glacier Flexible Retrieval after 30 days, and expire objects after 180 days.
B. S3 Standard, then S3 One Zone-IA after 30 days, then S3 Glacier Instant Retrieval after 180 days, and never expire objects.
C. Keep every object in S3 Intelligent-Tiering indefinitely.
D. S3 Standard, then S3 Standard-IA after 30 days, then S3 Glacier Deep Archive after 180 days, and expire objects after 7 years.
Show Answer
Correct Answer: D
Explanation:
Standard-IA keeps millisecond access at a lower storage price for the rarely read middle period, and Glacier Deep Archive is the cheapest class, with standard retrievals completing within 12 hours, for the long tail. An expiration rule ends storage charges after 7 years. Option B pays for instant retrieval nobody needs and never deletes. Option C keeps paying after the retention period. Option A deletes the logs 6 years too early.
Source: Managing the lifecycle of objects (Amazon S3 User Guide)