AWS Certified Solutions Architect – Associate Practice Test

Studying in order?

Practice stays free. The full AWS Solutions Architect Associate (SAA-C03) study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $14.99
AWS Certified Solutions Architect – Associate (SAA-C03) — Exam facts
Administering bodyAmazon Web Services (AWS Certification) — exam delivered by Pearson VUE

Source: AWS Certification — AWS Certified Solutions Architect - Associate (Exam overview)

Questions65 questions (50 scored, 15 unscored pretest)

Source: AWS — AWS Certified Solutions Architect - Associate (SAA-C03) Exam Guide

Time limit130 minutes

Source: AWS Certification — AWS Certified Solutions Architect - Associate (Exam overview)

Passing scoreScaled score of 720 on a 100–1,000 scale

Source: AWS — AWS Certified Solutions Architect - Associate (SAA-C03) Exam Guide

Fees
  • $150 — Exam fee (AWS, per attempt)

Source: AWS Certification — AWS Certified Solutions Architect - Associate (Exam overview)

Languages offeredEnglish · French (France) · Italian · Japanese · Korean · Portuguese (Brazil) · Spanish (Latin America) · Spanish (Spain) · Simplified Chinese · Traditional Chinese

Source: AWS Certification — AWS Certified Solutions Architect - Associate (Exam overview)

Exam facts, with a source for every line

Frequently asked questions

How many AWS Certified Solutions Architect – Associate practice questions are here?+

A full bank of original AWS Certified Solutions Architect – Associate practice questions across the official content areas, weighted like the real exam, with explanations. Free, no signup.

What is the AWS Certified Solutions Architect – Associate exam like?+

About 65 questions, 130 minutes, and you need 720 / 1000% to pass. Practice by topic here, then take the full timed mock exam to gauge readiness.

Are these the real exam questions?+

No. Every question is 100% original, written from public primary sources with explanations. We never copy real exam questions or paid prep material.

Can I study in Chinese or Spanish?+

PrepPass practice is in English, 中文 and Español. The official exam is in English — switch the question language to English any time to rehearse the exact terminology you'll see on test day.

Is there a study guide for the AWS Certified Solutions Architect – Associate?+

Yes. PrepPass sells AWS Solutions Architect Associate (SAA-C03) — Complete Study Guide (2026), a PDF + EPUB download, $14.99 one-time; the practice on this page stays free without it. See the study guide →

Sample practice questions

A few real questions from this free bank, with full explanations. Use the practice tool above for the whole set.

  1. 1. Design Secure Architectures

    An application running on EC2 instances needs to read objects from an S3 bucket. What is the most secure way to grant this access?

    • a.Store long-lived credentials in a file on the instance
    • b.Make the S3 bucket public and filter by source IP
    • c.Attach an IAM role to the EC2 instances with a policy granting least-privilege S3 read access
    • d.Embed an IAM user's access keys in the application code

    Answer: c

    Explanation: IAM roles provide temporary, automatically rotated credentials to EC2 instances via the instance metadata service, eliminating the need to store long-lived keys. Scoping the role's policy to only the required bucket and actions follows the principle of least privilege. Hard-coded access keys and public buckets create serious security risks and violate the Security pillar of the Well-Architected Framework.

  2. 2. Design Resilient Architectures

    A workload must process uploaded jobs asynchronously and automatically scale processing with the backlog, without managing servers. Which decoupled design fits best?

    • a.Run a single always-on EC2 instance polling a database
    • b.Store jobs in DynamoDB and process them manually
    • c.Place jobs in an SQS queue that triggers a Lambda function to process each message
    • d.Have clients call a Lambda function synchronously and wait for completion

    Answer: c

    Explanation: An SQS queue as an event source for Lambda decouples producers from processing and scales the number of concurrent Lambda executions with the queue backlog, all serverless. A single EC2 poller is a bottleneck and single point of failure, synchronous invocation removes the buffering benefit, and manual processing does not scale.

  3. 3. Design Secure Architectures

    A Lambda function needs permission to write records to a specific DynamoDB table and nothing else. Which approach follows least privilege?

    • a.Store an IAM user's access keys in a Lambda environment variable and reference them in the code
    • b.Run the function with the same IAM role that the account administrators use for day-to-day console operations
    • c.Attach the AmazonDynamoDBFullAccess AWS managed policy to the function's execution role so it never lacks a permission it might need later
    • d.Create an execution role with an inline policy scoped to dynamodb:PutItem on that table's ARN only

    Answer: d

    Explanation: A scoped execution role granting only dynamodb:PutItem on the specific table ARN gives the function exactly the access it needs and nothing more, which is least privilege. Full-access managed policies and admin roles grant far more than required, and embedding long-lived access keys in environment variables is insecure and unnecessary because Lambda assumes its execution role automatically.

  4. 4. Design Secure Architectures

    A security team wants to guarantee that any newly created S3 bucket in the account cannot be made public, as an account-wide setting that individual bucket owners cannot relax. What should be enabled?

    • a.Default encryption at the account level so that public objects are unreadable without the encryption key
    • b.Account-level S3 Block Public Access, which applies to all current and future buckets in the account
    • c.An IAM policy denying s3:CreateBucket unless the request includes a private ACL specified by the caller
    • d.A bucket policy template that developers are asked to copy into each new bucket they create manually

    Answer: b

    Explanation: Enabling S3 Block Public Access at the account level applies to every current and future bucket and prevents them from being made public, a guardrail bucket owners cannot override. A copied policy template relies on manual discipline, denying CreateBucket without a private ACL is fragile and awkward, and encryption does not stop an object from being served publicly.

  5. 5. Design Secure Architectures

    A company runs a web application and wants to block traffic from countries where it does not operate while allowing everyone else, applied at the CDN edge for lowest latency. Which configuration achieves this?

    • a.A geo-match rule in AWS WAF associated with the CloudFront distribution to block the specified countries
    • b.Security group rules on the load balancer that reference the geographic region of each incoming request
    • c.Route 53 geolocation routing that returns no answer for users located in the countries to be blocked entirely
    • d.A network ACL on the origin subnet that denies the CIDR ranges belonging to the blocked countries directly

    Answer: a

    Explanation: A WAF geo-match rule attached to the CloudFront distribution blocks requests from specified countries at the edge, close to users and before they reach the origin. NACLs and security groups filter by IP/port and cannot evaluate geography natively, and Route 53 geolocation influences DNS answers but is not a reliable security block, since users can bypass DNS.

  6. 6. Design Resilient Architectures

    A company needs its ALB to distribute traffic evenly across targets in multiple Availability Zones even when the number of targets differs per AZ. Which load balancer behavior ensures traffic is balanced across all healthy targets regardless of AZ?

    • a.A Network Load Balancer, which is required because Application Load Balancers cannot balance across Availability Zones
    • b.Cross-zone load balancing, which distributes requests evenly across all healthy targets in every enabled AZ
    • c.Sticky sessions, which pin each client to one target so the overall distribution stays even across the zones
    • d.Connection draining, which reroutes traffic away from busy Availability Zones to less loaded ones automatically

    Answer: b

    Explanation: Cross-zone load balancing spreads incoming requests evenly across all healthy registered targets in every enabled AZ, correcting imbalance when target counts differ per zone (and it is enabled by default on ALBs). Sticky sessions pin clients and can worsen balance, ALBs can already span AZs, and connection draining handles graceful deregistration, not cross-AZ balancing.

  7. 7. Design High-Performing Architectures

    An in-memory analytics database needs EC2 instances with a very high ratio of RAM to vCPU to hold a large working dataset entirely in memory. Which instance family is the best fit?

    • a.General purpose (M family), which offers a balanced but not memory-heavy ratio of resources
    • b.Storage optimized (I family), which prioritizes high local NVMe throughput over RAM capacity
    • c.Memory optimized (R family)
    • d.Compute optimized (C family), which is tuned for CPU-bound workloads rather than large memory footprints

    Answer: c

    Explanation: Memory optimized R-family instances provide the highest RAM-to-vCPU ratio, ideal for in-memory databases and caches that must keep large datasets resident in memory. Compute optimized C instances favor CPU, storage optimized I instances favor local disk I/O, and general purpose M instances give a balanced ratio that wastes money or underperforms for memory-bound work.

  8. 8. Design High-Performing Architectures

    A globally accessed static website with images and scripts loads slowly for users far from the origin Region. Which change most improves delivery performance worldwide?

    • a.Serve the assets through Amazon CloudFront so content is cached at edge locations near users
    • b.Enable S3 Versioning on the bucket to improve global read speed
    • c.Move the origin bucket to a One Zone storage class to speed up delivery
    • d.Increase the size of the origin EC2 instance hosting the assets, so it would not meet the objective stated in the question

    Answer: a

    Explanation: CloudFront caches static assets at edge locations worldwide, so distant users are served from a nearby edge instead of the origin, reducing latency and origin load. A One Zone class is a durability/cost choice, a larger instance still serves from one Region, and versioning does not affect delivery latency.

  9. 9. Design High-Performing Architectures

    A relational database on RDS is CPU- and memory-constrained during peak load, and the team wants to improve performance quickly without changing the engine or re-architecting. What is the most direct action?

    • a.Increase the backup retention period to relieve CPU pressure
    • b.Add more read replicas even though the bottleneck is on writes and compute
    • c.Reduce the allocated storage to make the instance respond faster
    • d.Vertically scale the instance to a larger class with more vCPU and memory

    Answer: d

    Explanation: When a single database instance is compute- or memory-bound on write-heavy load, scaling it vertically to a larger instance class with more vCPU and memory is the most direct performance fix. Read replicas only help reads, shrinking storage does not add compute, and backup retention is unrelated to CPU load.

  10. 10. Design Cost-Optimized Architectures

    A steady production web tier runs continuously on a specific instance family the team has no plans to change, and management wants the maximum discount for a three-year commitment with the option to pay some or all upfront. Which purchasing option gives the deepest discount?

    • a.Spot Instances for the continuously running web tier
    • b.A three-year Standard Reserved Instance with an all-upfront payment
    • c.A one-year Compute Savings Plan paid monthly
    • d.On-Demand Instances to preserve flexibility

    Answer: b

    Explanation: A three-year Standard Reserved Instance with all-upfront payment yields the deepest discount for steady usage on a fixed instance family. A one-year Compute Savings Plan is more flexible but discounts less, On-Demand offers no discount, and Spot is unsuitable for a must-run production tier.

Own the complete AWS Solutions Architect Associate (SAA-C03) guide — PDF + EPUB, $14.99 →

Report