AWS 197: Solutions Architect Associate knowledge check
Why this lesson matters
Prove SAA-level reasoning across secure, resilient, high-performing, and cost-optimized architectures with explanations and practical evidence.
What you will be able to do
By the end, you can:
- explain solutions architect associate knowledge check in plain language;
- locate the current service controls in the AWS Management Console;
- run the matching CloudShell or AWS CLI queries and explain every important field;
- draw the identity, network, data, failure, and monitoring path;
- choose the service from requirements and reject it when those requirements are absent;
- diagnose a failed or misleading result from evidence;
- state the cost owner and prove cleanup or a no-create result.
Before you start
- Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
- CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
- The course example Region is
ap-south-1. Global services and services with a required control Region are called out in their commands. - Run
aws sts get-caller-identityprivately. Redact the account number before sharing evidence. - Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
- This is a no-create lesson. Every Console action and AWS CLI command is read-only. Create the practical artifact locally.
- Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.
The core model
| Question | What it means in this lesson |
|---|---|
| Purpose | Prove SAA-level reasoning across secure, resilient, high-performing, and cost-optimized architectures with explanations and practical evidence. |
| Scope and boundary | The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for Solutions Architect Associate knowledge check. |
| Evidence of success | Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for Solutions Architect Associate knowledge check. |
| Cost model | Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design. |
| Safe rejection rule | Avoid copied exam dumps, answer-key memorization, or passing a learner who cannot explain failure and cost. |
How the request flows
+-------------------------+
| Scenario requirements |
+-------------------------+
|
v
+----------------------------------+
| Candidate architecture choices |
+----------------------------------+
|
v
+--------------------------+
| Trade-off and evidence |
+--------------------------+
|
v
+---------------------------------+
| Scored domain and remediation |
+---------------------------------+
What this checkpoint measures
The current SAA-C03 guide organizes scored content into four domains: secure, resilient, high-performing and cost-optimized architectures. Service lists are non-exhaustive and change. This checkpoint measures whether you can extract requirements, reject distractors and justify the best architecture, not recall names.
For each scenario, write hard requirements, failure scope, data/consistency need, selection, why alternatives fail, cost/operations consequence and confidence. Use 130 seconds initially, then review low-confidence responses.
Timed scenario set
- A private web tier needs S3 without NAT processing or internet. Choose an S3 gateway endpoint with scoped bucket/endpoint policies; NAT misses cost/path requirements.
- A database needs automatic AZ failover and read scaling. Select an RDS/Aurora design explicitly providing both; a Multi-AZ standby is not automatically a read endpoint and a replica alone is not the same HA contract.
- Bursty orders must be retained and processed at least once without coupling API to workers. Use SQS and idempotent consumers; SNS alone is not a work queue.
- Objects require seven-year privileged-deletion protection. Use governed S3 Object Lock/versioning plus required backup/replication; lifecycle is not immutability.
- Global users need cached static content and HTTP filtering. Use CloudFront with WAF and protected origin; Global Accelerator does not cache or provide WAF rules.
- A stable EC2/Fargate/Lambda baseline may move Regions/families. Evaluate Compute Savings Plans after rightsizing; it does not reserve capacity.
- Detect suspicious behavior and known package CVEs. GuardDuty supplies threat findings and Inspector vulnerability findings; Security Hub aggregates but does not replace both detectors.
- Regional DR requires minute-level RPO and tens-of-minutes RTO at low steady cost. Pilot light with replicated data, foundations, IaC activation and backups fits better than backup/restore, warm standby or active-active.
Answer-quality rubric
| Score | Evidence |
|---|---|
| 0 | Guess or service name only |
| 1 | Direction is plausible but misses a hard requirement or rejection rationale |
| 2 | Correct choice and requirement mapping with an operational/cost implication |
| 3 | Complete choice, rejection, failure/data path and validation evidence |
Pass at 19/24 with no zero in security/resilience. Remediate each miss in its prerequisite lesson and produce practical evidence before a changed retest.
Architecture decision table
| Situation | Direction | Reason |
|---|---|---|
| Requirement matches | Use the checkpoint to decide readiness and assign precise remediation before the capstone. | Select only after scope, behavior, security, recovery, operations, and price evidence agree. |
| Requirement does not match | Avoid copied exam dumps, answer-key memorization, or passing a learner who cannot explain failure and cost. | Rejecting an attractive service is a valid architecture result. |
| No create permission or cost approval | Use supplied evidence and local design work | Learning does not depend on creating an hourly resource. |
| Existing resource is unknown or unowned | Inspect only, then stop | Never change or delete a resource merely because it resembles a course example. |
AWS Management Console, step by step
Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.
- Use the Console service search and open Read-only service inventories used across AWS053 through AWS196; confirm the account and Region before reading the page.
- Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
- Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
- Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.
CloudShell and AWS CLI, step by step
Start with a known caller and Region:
export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list
Redact the account part of the ARN in shared evidence. Now run the topic queries:
aws sts get-caller-identity --query Arn --output text
aws ec2 describe-vpcs --query 'Vpcs[].VpcId' --output text
aws s3api list-buckets --query 'Buckets[].Name' --output text
aws rds describe-db-instances --query 'DBInstances[].DBInstanceIdentifier' --output text
aws lambda list-functions --query 'Functions[].FunctionName' --output text
aws cloudwatch describe-alarms --state-value ALARM --output table
Expected interpretation
The checkpoint combines knowledge, packet and data paths, Console and CLI interpretation, cost, failure diagnosis, and cleanup. Memorized service matching cannot pass alone.
Practical work
Complete 40 original scenario questions, four short architecture defenses, two CLI output interpretations, one packet path, one restore plan, and one cost analysis. Remediate every domain below 80 percent.
Diagnose this topic from its own evidence
- Domain clusters indicate concept gaps; repeated misses on “most cost-effective” indicate requirement-reading gaps.
- With two plausible options, test every hard requirement and reject unnecessary complexity.
- Fast low-confidence work needs architecture sketches; slow confident errors need distractor-rejection practice.
- Verify memorized capabilities against current official documentation.
Cost and cleanup
Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.
Knowledge check
- What operational purpose is this lesson solving?
Expected direction: Prove SAA-level reasoning across secure, resilient, high-performing, and cost-optimized architectures with explanations and practical evidence.
- Which scope or ownership boundary must be proved first?
Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for Solutions Architect Associate knowledge check.
- What evidence is strong enough to accept the result?
Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for Solutions Architect Associate knowledge check.
- Which tempting design or shortcut must be rejected?
Expected direction: Avoid copied exam dumps, answer-key memorization, or passing a learner who cannot explain failure and cost.
- Which cost dimensions and retained resources need an owner?
Expected direction: Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.
Lesson acceptance
- Complete eight scenarios under timebox without notes and review afterward.
- Score at least 19/24 with explicit rejection rationale.
- Produce remediation evidence for each miss and pass a changed retest.
- Explain cross-domain trade-offs in one integrated architecture.
- Do not claim readiness until AWS202–203 and the capstone also pass.