AWSAssociate

AWS Certified Solutions Architect – Associate

SAA-C03

Design secure, resilient, high-performing and cost-optimised architectures on AWS. The most popular cloud certification worldwide.

Duration
130 min
Exam questions
65
Passing score
720 / 1000
Exam fee
$150
Question formats:Multiple choiceMultiple response
Free plan
3 free papers
Free account
Mocks locked
Pro only
Upgrade to Pro
Every paper and mock exam.
See Pro

Start with free papers Free

You get 3 free practice papers with your plan.

Free
Mixed paper 1
Domain 1 · 25 questions
Free
Mixed paper 2
Domain 1 · 25 questions
Free
Mixed paper 3
Domain 1 · 25 questions

Domain papers 824 questions

Free
Mixed paper 1
25 questions · 60 min
Free
Mixed paper 2
25 questions · 60 min
Free
Mixed paper 3
25 questions · 60 min
Pro
Mixed paper 4
25 questions · 60 min
Pro
Mixed paper 5
25 questions · 60 min
Pro
Mixed paper 6
25 questions · 60 min
Pro
Mixed paper 7
16 questions · 39 min
Pro
Mixed paper 8
15 questions · 36 min

Mock exams Pro

Full-length, exam-like practice tests. Available with Pro.

Mock exam 1
65 questions · 130 min
Mock exam 2
65 questions · 130 min
Mock exam 3
65 questions · 130 min

Try a sample question

All 10 sample questions →
Question 1Design Secure Architectures

A compliance standard requires that the people who administer encryption keys must not be able to decrypt data with them, and that the application which decrypts data must not be able to change key configuration. Which two policy arrangements implement this separation? (Choose TWO.)

Choose 2.

  1. A.

    Place the key in a separate AWS account and give both groups the account's root credentials for emergencies.

  2. B.

    Grant both groups full access to the key and review CloudTrail monthly for inappropriate use.

  3. C.

    Grant the key administrators management actions such as key policy and rotation changes, without cryptographic actions.

  4. D.

    Grant the key administrators cryptographic actions as well, so they can test the key after every change.

  5. E.

    Grant the application role only cryptographic actions such as Decrypt and GenerateDataKey on the key.

Show answer

Answer: C, E

A KMS key policy separates management actions from cryptographic actions, so administrators can configure the key without using it and the application can use it without configuring it.

  • A. Sharing root credentials concentrates privilege and destroys individual accountability.
  • B. Monthly review is detective and leaves the prohibited capability in place the whole time.
  • C. Management actions let administrators configure the key without any ability to decrypt data.
  • D. Giving administrators cryptographic actions removes the separation the standard requires.
  • E. Cryptographic actions let the application use the key without changing its configuration.

What's on the exam

4 domains · 14 task statements, straight from the official exam guide (as of 2026-09-29).

  1. 1.1Design secure access to AWS resources
    • Access controls and management across multiple accounts
    • AWS federated access and identity services (for example, IAM, AWS IAM Identity Center)
    • AWS global infrastructure (for example, Availability Zones, AWS Regions)
    • AWS security best practices (for example, the principle of least privilege)
    • The AWS shared responsibility model
    • Applying AWS security best practices to IAM users and root users (for example, multi-factor authentication [MFA])
    • Designing a flexible authorization model that includes IAM users, groups, roles, and policies
    • Designing a role-based access control strategy (for example, AWS STS, role switching, cross-account access)
    • Designing a security strategy for multiple AWS accounts (for example, AWS Control Tower, service control policies [SCPs])
    • Determining the appropriate use of resource policies for AWS services
    • Determining when to federate a directory service with IAM roles
  2. 1.2Design secure workloads and applications
    • Application configuration and credentials security
    • AWS service endpoints
    • Control ports, protocols, and network traffic on AWS
    • Secure application access
    • Security services with appropriate use cases (for example, Amazon Cognito, Amazon GuardDuty, Amazon Macie)
    • Threat vectors external to AWS (for example, DDoS, SQL injection)
    • Designing VPC architectures with security components (for example, security groups, route tables, network ACLs, NAT gateways)
    • Determining network segmentation strategies (for example, using public subnets and private subnets)
    • Integrating AWS services to secure applications (for example, AWS Shield, AWS WAF, IAM Identity Center, AWS Secrets Manager)
    • Securing external network connections to and from the AWS Cloud (for example, VPN, AWS Direct Connect)
  3. 1.3Determine appropriate data security controls
    • Data access and governance
    • Data recovery
    • Data retention and classification
    • Encryption and appropriate key management
    • Aligning AWS technologies to meet compliance requirements
    • Encrypting data at rest (for example, AWS KMS)
    • Encrypting data in transit (for example, AWS Certificate Manager [ACM] using TLS)
    • Implementing access policies for encryption keys
    • Implementing data backups and replications
    • Implementing policies for data access, lifecycle, and protection
    • Rotating encryption keys and renewing certificates

Outline reproduced from the vendor's public exam guide for study reference.Official guide

SAA-C03 practice — frequently asked questions

Are these real SAA-C03 exam questions?

No. Every question on CertifyCloudx is original, written by us against Amazon Web Services's publicly available SAA-C03 exam guide to rehearse the skills it lists. None are actual exam questions, and CertifyCloudx is not affiliated with or endorsed by Amazon Web Services.

How many SAA-C03 practice questions are there?

824 practice questions, including 3 full-length timed mock exams and 77 domain papers of up to 25 questions (mixed and by topic). Every question has a detailed explanation of why the right answer wins and why each distractor loses.

Is the content up to date with the current SAA-C03 exam guide?

The questions are written against the SAA-C03 exam guide dated 2026-09-29, and we revise them when Amazon Web Services updates the guide.

What question formats are covered?

The same formats the real SAA-C03 uses: Multiple choice, Multiple response. Each is rendered and graded the way the exam does it.

How long is the SAA-C03 exam and how many questions does it have?

According to Amazon Web Services's published exam details: 65 questions, 130 minutes, passing score 720 / 1000. Our mock exams use the same time limit and question count. Always confirm current details with Amazon Web Services before booking.

Can I practise SAA-C03 for free?

Yes. 3 papers are free, with up to 10 questions a day on the free plan and no card needed. Pro unlocks every paper and mock exam with no daily limit.

Does CertifyCloudx guarantee that I will pass?

No practice material can guarantee a result. CertifyCloudx helps you find and close your weak areas — accuracy by exam-guide domain and topic shows what to study next.