Lesson 202 · AWS Learning Path

AWS 202: SAA-C03 domain review and timed scenario set

· Published · 11 min read

Labelled process diagram for AWS 202: Scenario facts to Requirements and constraints to Eliminate and select to Timed score and targeted remediation, with decision, proof and rejection evidence.

Why this lesson matters

Architecture exams do not reward isolated definitions. A scenario mixes business requirements, failure boundaries, security rules, performance targets, operations and price; several answers may work technically, but only one best satisfies the stated priorities. This checkpoint measures whether you can make that decision under time pressure and explain why the distractors lose.

The current SAA-C03 blueprint has four scored domains: secure architectures 30%, resilient architectures 26%, high-performing architectures 24% and cost-optimized architectures 20%. AWS reports a scaled score, not a raw percentage, so this course's practice threshold is a learning gate rather than a prediction of the certification result.

What you will be able to do

By the end, you can:

  • turn a paragraph into mandatory requirements, preferences and irrelevant facts;
  • identify whether a question asks for one response or multiple responses;
  • eliminate options that violate an explicit constraint before comparing features;
  • distinguish availability, durability, scalability, performance and disaster recovery;
  • compare identity, network and data controls without treating them as substitutes;
  • classify every miss by cause and produce a targeted remediation and changed retest;
  • decide honestly whether to continue studying or schedule an official exam.

Exam facts and ethical boundary

As of this review, AWS lists 65 multiple-choice or multiple-response questions and 130 minutes for SAA-C03. The exam guide says 50 questions affect the score and 15 unscored questions are not identified; unanswered questions are incorrect and there is no penalty for guessing. The reported score range is 100–1,000 with a minimum passing score of 720.

Do not use stolen questions, recalled live-exam content or “dumps.” This lesson contains original practice scenarios. Use the current official exam guide and AWS Official Practice material to check format and scope because exam details can change.

The decision method

For each scenario:

  1. Read the final sentence first: identify the requested outcome and response count.
  2. Mark hard constraints such as RPO, RTO, protocol, consistency, compliance, Region, operational effort and cost priority.
  3. Translate symptoms into the responsible layer: identity, network, compute, data, integration or operations.
  4. Eliminate any answer that violates one hard constraint, even if it contains a familiar service.
  5. Compare the remaining choices against the stated optimization word: most secure, most resilient, highest performance, lowest cost or least operational effort.
  6. Select every required response, then explain one sentence for the winner and one concrete reason for each rejected distractor.
  7. Flag uncertain items and move on. Reserve the final minutes for unanswered and flagged questions.

At 130 minutes for 65 questions, the overall average is two minutes per question. Some questions take 30 seconds and others need three minutes; the average is a pacing control, not a forced limit.

Domain map and common confusions

DomainWeightYou must distinguish
1. Design Secure Architectures30%identity policy vs resource policy; authentication vs authorization; SG vs NACL; encryption at rest vs in transit; KMS key policy; public reachability vs public access
2. Design Resilient Architectures26%Multi-AZ vs read scaling; queue buffering vs synchronous coupling; backup vs replication; RPO vs RTO; zonal vs Regional failure
3. Design High-Performing Architectures24%latency vs throughput; block/file/object; cache vs replica; vertical vs horizontal scaling; CloudFront vs Global Accelerator
4. Design Cost-Optimized Architectures20%utilization vs commitment; data-transfer path; storage lifecycle; idle capacity; managed-service operational cost vs infrastructure price

Cross-domain questions are normal. Classify each item by its primary decision objective, then note secondary effects.

Timed original scenario set

Set a 40-minute timer for 20 questions. Do not open the answer key until the timer ends. Record one answer per item except where the prompt says Select TWO.

Domain 1 - secure architectures

  1. A company workforce uses an external identity provider. Employees need temporary, role-based access to several AWS accounts, and administrators want one place for assignment and removal. Which design best fits?

A. Create one IAM user per employee in every account B. Use IAM Identity Center with federation and permission sets C. Share one administrator role credential file D. Put employee IP addresses in S3 bucket policies

  1. EC2 instances in private subnets must read only s3://reports-prod/app/*. Traffic must not require NAT. Select TWO.

A. Attach a bucket-scoped role to an instance profile B. Store an IAM access key in user data C. Add an S3 gateway VPC endpoint with a restrictive endpoint policy D. Add 0.0.0.0/0 inbound HTTPS to the instance SG E. Make the bucket public and restrict by object name

  1. An application receives AccessDenied even though its identity policy allows s3:GetObject. A permissions boundary also allows it. CloudTrail identifies the expected role. What should be checked first?

A. Whether the subnet has more free IP addresses B. Whether S3 Transfer Acceleration is enabled C. Whether the object uses Standard-IA D. Whether an applicable SCP, resource policy or session policy contains an explicit deny

  1. An internet-facing ALB sends HTTP health checks to EC2 targets on port 8080. The targets must never accept direct internet traffic. Which inbound design is best?

A. Both SGs allow all traffic from 0.0.0.0/0 B. Target SG allows TCP 8080 from the ALB SG; ALB SG allows client port from the approved CIDR C. Target SG allows TCP 8080 from the VPC CIDR, regardless of caller D. Remove all SG rules and rely only on the route table

  1. A regulated S3 archive must prevent object versions from being overwritten or deleted for seven years, including by administrators, under a compliance retention model. Which feature is central?

A. An S3 lifecycle expiration rule B. An EBS DeleteOnTermination setting C. S3 Object Lock compliance mode on a versioning-enabled bucket D. CloudFront Origin Shield

  1. An API uses an ACM certificate on an ALB. Which statement is correct?

A. TLS at the ALB protects the client-to-ALB path; target-side encryption is a separate design decision B. The certificate replaces application authorization C. ACM public certificates can be exported with their private keys from every integrated service D. The certificate makes a public subnet private

Domain 2 - resilient architectures

  1. A relational database must survive an Availability Zone outage with automatic failover. Read scaling is not required. Which primary choice fits?

A. One RDS read replica in the same AZ B. Daily manual snapshot only C. ElastiCache without a database D. RDS Multi-AZ deployment

  1. Order-processing requests arrive in bursts. Workers occasionally fail and producers must not wait for processing. Duplicate delivery is acceptable if workers are idempotent. Which design is best?

A. Producers synchronously call one fixed EC2 instance B. Producers place messages in SQS; workers scale on backlog and use a DLQ C. Store every request in instance memory D. Use a Route 53 private hosted zone as a queue

  1. A business requires no more than five minutes of lost transaction data and service restoration within one hour after a Regional disaster. What do the two numbers mean?

A. Both are availability percentages B. RTO 5 minutes; RPO 1 hour C. RPO 5 minutes; RTO 1 hour D. Both specify backup retention

  1. An Auto Scaling group spans two AZs behind an ALB with desired capacity two. One instance is terminated. What design behavior should be tested?

A. The ASG restores desired capacity and the ALB routes only to healthy registered targets B. The Elastic IP automatically moves to every instance C. The root EBS volume becomes a cross-Region replica D. The ALB converts the instance to Lambda

  1. Static website assets need protection from an entire Region failure. The business accepts asynchronous replication and DNS failover. Which combination directly addresses the data and traffic requirements?

A. S3 versioning in only the failed Region B. One larger EC2 instance C. An EBS volume in one AZ D. S3 Cross-Region Replication plus a tested failover origin/routing design

Domain 3 - high-performing architectures

  1. Millions of read requests repeatedly access a small set of database records with sub-millisecond latency requirements. Stale data for seconds is acceptable. Which addition best fits?

A. S3 Glacier Deep Archive B. ElastiCache C. AWS Backup vault D. VPC Flow Logs

  1. Linux EC2 instances across multiple AZs need concurrent access to the same POSIX file hierarchy. Which storage service fits?

A. Instance store on one instance B. One EBS volume attached read-write to arbitrary instances in all AZs C. EFS Regional file system D. S3 mounted as if every POSIX operation were native

  1. Global users download cacheable images from one Regional origin. The goal is lower HTTP latency and reduced origin load. Which service is the first choice?

A. CloudFront B. Direct Connect at every user's home C. NAT Gateway D. AWS Config

  1. A DynamoDB table has unpredictable traffic and the team does not want to forecast read/write capacity. Which capacity mode best matches?

A. Provisioned with no scaling and capacity one B. Reserved EC2 Instances C. Aurora I/O-Optimized D. On-demand

  1. A TCP application has static anycast IP requirements and must route users to healthy Regional endpoints over the AWS global network. Responses are not cacheable. Which service best fits?

A. CloudFront signed cookies only B. AWS Global Accelerator C. S3 Transfer Acceleration D. An internet gateway in one VPC

Domain 4 - cost-optimized architectures

  1. Stateless fault-tolerant batch jobs can stop and restart. Which EC2 purchasing option normally offers the strongest discount for that interruption-tolerant capacity?

A. Dedicated Hosts B. On-Demand Capacity Reservations with no discount instrument C. Spot Instances D. One permanently running On-Demand instance

  1. S3 objects are frequently read for 30 days, rarely read for 60 days, and must then remain for seven years with retrieval taking hours. Which design is most cost-aware?

A. Lifecycle transitions from S3 Standard to an infrequent-access class and then an appropriate Glacier archive class B. Keep all versions in S3 Standard forever C. Copy every object to attached gp3 volumes D. Put the objects in ElastiCache

  1. A steady compute baseline runs continuously across instance families and Regions, while usage above baseline varies. Which commitment is usually more flexible for the baseline than an EC2 Instance Savings Plan?

A. Spot Fleet with a one-year payment B. Capacity Reservation alone C. S3 Intelligent-Tiering D. Compute Savings Plans

  1. A private workload downloads large volumes from S3 in the same Region through a NAT gateway. It needs no general internet egress. Which change can remove NAT processing charges for that S3 path?

A. Add another NAT gateway in the same AZ B. Use an S3 gateway VPC endpoint and validate route/endpoint/bucket policies C. Assign every instance an Elastic IP D. Send the traffic through an internet-facing ALB

Stop the timer and score

Answer key: 1 B; 2 A,C; 3 D; 4 B; 5 C; 6 A; 7 D; 8 B; 9 C; 10 A; 11 D; 12 B; 13 C; 14 A; 15 D; 16 B; 17 C; 18 A; 19 D; 20 B.

Re-score multiple-response item 2 as correct only when both required choices and no extra choice were selected.

DomainItemsPractice gate
Secure1–6at least 5/6
Resilient7–11at least 4/5
High-performing12–16at least 4/5
Cost-optimized17–20at least 3/4
Overall1–20at least 16/20 within 40 minutes

This 80% raw gate is deliberately conservative and is not equivalent to AWS's scaled score of 720. Do not average away a weak domain.

Rationale and distractor diagnosis

  • 1–3: federation centralizes temporary workforce access; an instance role plus S3 gateway endpoint removes long-term keys and NAT dependency; any applicable explicit deny wins over an allow.
  • 4–6: SG-to-SG references constrain the target caller; Object Lock compliance mode supplies retention enforcement; TLS termination covers a particular network hop and does not provide authorization.
  • 7–11: Multi-AZ is for availability, not primarily read scaling; SQS decouples bursty producers and workers; RPO is tolerated data loss while RTO is restoration time; ASG and ALB have different self-healing/routing jobs; Regional resilience needs both replicated data and tested traffic failover.
  • 12–16: a cache serves repeated low-latency reads; EFS provides Regional shared files; CloudFront caches HTTP content near users; DynamoDB on-demand absorbs unpredictable request rates; Global Accelerator is for non-cacheable TCP/UDP traffic with static anycast IPs and healthy endpoint routing.
  • 17–20: interruption-tolerant work fits Spot; lifecycle rules align storage price with access age; Compute Savings Plans offer broader compute flexibility; an S3 gateway endpoint avoids the NAT data-processing path for supported same-Region S3 traffic.

Miss classification and remediation

For every wrong, guessed or over-time answer, record:

FieldRequired entry
Scenario and domainitem number and primary domain
Error typeknowledge, requirement extraction, service boundary, distractor, unsafe assumption or time management
Missed wordsexact constraint you ignored or misunderstood
Correct ruleone service-neutral architecture rule
Service proofcurrent official documentation link and relevant control
Changed retesta new scenario with different names/numbers but the same decision boundary
Resultanswer, rationale and elapsed time after at least 24 hours

A memorized answer is not remediation. After missing Multi-AZ versus read replica, for example, create a changed scenario where availability, read scaling and cross-Region recovery appear as separate requirements and explain which feature owns each.

Exam-readiness decision

  • Ready for AWS203: overall and every domain gate pass, all guesses are reviewed, and you can explain rejected options without notes.
  • Remediate: overall passes but one domain misses its gate, or more than two correct answers were guesses.
  • Repeat under timed conditions: pacing exceeds 40 minutes, a response-count instruction was missed, or overall is below 16.
  • Do not schedule yet: results depend on dumps, answer memorization, unreviewed guesses or no hands-on evidence from AWS001–201.

Certification is external validation, not the end of architect development. Passing this course gate does not guarantee an exam pass or make someone an expert; repeated design, implementation, incident and stakeholder work builds expertise.

Lesson acceptance

  • Timer record, all 20 responses and response counts are preserved before opening the key.
  • Overall score is at least 16/20 and each domain meets its separate gate.
  • Every miss and guess has a cause, official source, corrected rule and changed retest.
  • The retest occurs after a delay and is passed from reasoning, not answer recall.
  • The learner can state current exam format, domain weights, scaled-score caveat and ethical boundary.

Official sources

Advertisement