SAA-C03 sample questions with answers

10 free practice questions for the AWS Certified Solutions Architect – Associate exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Design Secure Architectures

A compliance standard requires that the people who administer encryption keys must not be able to decrypt data with them, and that the application which decrypts data must not be able to change key configuration. Which two policy arrangements implement this separation? (Choose TWO.)

Choose 2.

  1. A.

    Place the key in a separate AWS account and give both groups the account's root credentials for emergencies.

  2. B.

    Grant both groups full access to the key and review CloudTrail monthly for inappropriate use.

  3. C.

    Grant the key administrators management actions such as key policy and rotation changes, without cryptographic actions.

  4. D.

    Grant the key administrators cryptographic actions as well, so they can test the key after every change.

  5. E.

    Grant the application role only cryptographic actions such as Decrypt and GenerateDataKey on the key.

Show answer

Answer: C, E

A KMS key policy separates management actions from cryptographic actions, so administrators can configure the key without using it and the application can use it without configuring it.

  • A. Sharing root credentials concentrates privilege and destroys individual accountability.
  • B. Monthly review is detective and leaves the prohibited capability in place the whole time.
  • C. Management actions let administrators configure the key without any ability to decrypt data.
  • D. Giving administrators cryptographic actions removes the separation the standard requires.
  • E. Cryptographic actions let the application use the key without changing its configuration.
Question 2Design Secure Architectures

A company federates its identity provider with IAM using SAML 2.0. Users authenticate successfully at the identity provider, but the sign-in to AWS fails before any role selection screen appears. The IAM SAML identity provider object and the roles both exist, and the roles trust the provider. What should an engineer check first?

  1. A.

    That the roles carry a permissions boundary permitting the sts:AssumeRoleWithSAML action.

  2. B.

    That AWS CloudTrail is enabled in the account so that the federation request can be authorized.

  3. C.

    That each federated user has a matching IAM user created in the account before first sign-in.

  4. D.

    That the SAML assertion includes the Role and RoleSessionName attributes that AWS requires.

Show answer

Answer: D

AWS builds the role session from claims in the SAML assertion, so a missing Role or RoleSessionName attribute fails the sign-in before any role can be chosen.

  • A. A permissions boundary restricts a principal rather than enabling federation; the trust policy authorizes the call.
  • B. CloudTrail records activity and has no role in authorizing a federation request.
  • C. Federated users map to roles and receive temporary credentials; no matching IAM user is needed.
  • D. AWS derives the role and session name from assertion attributes, so missing claims break the flow immediately.
Question 3Design Secure Architectures

An audit found a production Amazon RDS for MySQL Multi-AZ instance that was created without encryption. The database must be encrypted at rest with a customer managed key, and the team has a short maintenance window. What should a solutions architect do?

  1. A.

    Take a snapshot, copy the snapshot with encryption enabled using the key, restore it, and cut over to the new instance.

  2. B.

    Modify the instance and select the customer managed key, then apply the change during the maintenance window.

  3. C.

    Create a read replica with encryption enabled and promote it, since replicas may differ in encryption state.

  4. D.

    Enable encryption on the existing storage volumes from the Amazon EBS console without touching the database.

Show answer

Answer: A

Encryption cannot be turned on for an existing RDS instance, so the supported path is snapshot, encrypted snapshot copy, restore and cut over.

  • A. The encrypted snapshot copy and restore is the only supported way to encrypt an existing instance.
  • B. RDS does not allow encryption to be enabled on an existing instance through modification.
  • C. A read replica of an unencrypted instance cannot be created with encryption enabled.
  • D. RDS manages its own storage, which is not exposed as customer EBS volumes to modify.
Question 4Design Secure Architectures

During a design review of a new cross-account integration, an engineer asks which document determines who is allowed to assume a particular IAM role, where that document lives, and what type of policy it is. Which statement correctly describes it?

  1. A.

    A service control policy on the account lists which principals are permitted to assume each role in that account, overriding the role's own configuration.

  2. B.

    The instance profile attached to the role determines which principals are allowed to assume the role.

  3. C.

    The role's permissions policy names the principals that may assume it and what they may do afterwards.

  4. D.

    The role's trust policy is a resource-based policy attached to the role and names the principals that may assume it.

Show answer

Answer: D

Every IAM role carries a trust policy, which is a resource-based policy naming the principals allowed to assume it.

  • A. SCPs cap permissions across an account; they do not enumerate per-role trust relationships.
  • B. An instance profile is the container that delivers a role to an EC2 instance and grants nothing itself.
  • C. The permissions policy defines what the role may do, not who may assume it.
  • D. The trust policy is the role's resource-based policy and defines the principals permitted to assume it.
Question 5Design Secure Architectures

A company wants to ensure that workloads running in its VPCs cannot copy data to Amazon S3 buckets belonging to anyone outside the organization, even if a compromised role has broad S3 permissions. Access to the organization's own buckets must continue to work normally. Which two controls implement this? (Choose TWO.)

Choose 2.

  1. A.

    Enable S3 Block Public Access in every account, which prevents workloads writing to external buckets.

  2. B.

    Enable Amazon Macie on the organization's buckets so that data copied elsewhere is detected and reported.

  3. C.

    Attach an endpoint policy to the S3 endpoints that allows access only when aws:ResourceOrgID matches the organization.

  4. D.

    Attach an SCP denying s3:PutObject for all principals, with an exception for the data engineering team.

  5. E.

    Remove routes to the internet from the workload subnets so that S3 is reachable only through the VPC endpoints.

Show answer

Answer: C, E

A data perimeter for egress needs the endpoint policy to permit only organization-owned buckets, and the only path to S3 to be that endpoint.

  • A. Block Public Access governs public grants on your buckets, not where workloads may write.
  • B. Macie classifies data and reports; it cannot stop a copy from happening.
  • C. Conditioning the endpoint policy on the resource's organization blocks writes to buckets outside it.
  • D. This blocks legitimate writes to your own buckets while leaving the excepted team unrestricted.
  • E. With no internet route the endpoint is the only path to S3, which is what makes the endpoint policy binding.
Question 6Design Secure Architectures

A security operations team reviews findings from GuardDuty, Inspector and Macie across 25 accounts and several Regions. Analysts currently open each service in each account separately, and there is no single measure of how the organization scores against a recognized security standard. What should a solutions architect recommend?

  1. A.

    Build an Amazon EventBridge rule in each account that forwards findings to a central Amazon SQS queue for analysts to poll.

  2. B.

    Enable AWS Security Hub with a delegated administrator and a cross-Region aggregation Region, and turn on the required standards.

  3. C.

    Export each service's findings to Amazon S3 daily and query them with Amazon Athena from a central account.

  4. D.

    Enable Amazon Detective in every account so that findings from the three services are correlated into one view.

Show answer

Answer: B

Security Hub is the aggregation layer: it normalizes findings from AWS security services across accounts and Regions and scores the estate against security standards.

  • A. A custom event pipeline duplicates the service and provides no standards assessment.
  • B. It aggregates and normalizes findings across accounts and Regions and provides standards-based scoring.
  • C. Daily exports and ad hoc queries lose timeliness and still produce no security score.
  • D. Detective investigates the context of a finding; it is not a multi-account aggregation layer.
Question 7Design Secure Architectures

A security team must ensure that every internet-facing Application Load Balancer created in any of 40 accounts is automatically associated with a standard AWS WAF web ACL, and that new accounts are covered without manual work. Which two statements describe how AWS Firewall Manager delivers this? (Choose TWO.)

Choose 2.

  1. A.

    Firewall Manager requires AWS Organizations and a designated administrator account to manage policies centrally.

  2. B.

    Firewall Manager can manage web ACLs but has no ability to manage security groups or Shield Advanced protections.

  3. C.

    A Firewall Manager policy applies the web ACL to in-scope resources across the organization automatically.

  4. D.

    Firewall Manager policies apply only to resources that already exist when the policy is created.

  5. E.

    Firewall Manager replaces AWS WAF, so individual accounts no longer need a web ACL at all.

Show answer

Answer: A, C

Firewall Manager sits on AWS Organizations with a designated administrator account and continuously applies its policies to in-scope resources, including ones created later.

  • A. The service is built on AWS Organizations and is administered from a designated account.
  • B. It also manages security group policies, Shield Advanced, Network Firewall and DNS Firewall associations.
  • C. Policies apply continuously to in-scope resources, including ones created after the policy exists.
  • D. Covering future resources automatically is the main reason to use the service.
  • E. Firewall Manager configures AWS WAF centrally; the web ACLs it manages are still WAF resources.
Question 8Design Secure Architectures

A VPC spans three Availability Zones and currently routes all private subnet egress through a single NAT gateway. A zone impairment last month cut off internet access for workloads in the other two zones as well. The company wants outbound access in one zone to survive the loss of another. Which two changes achieve this? (Choose TWO.)

Choose 2.

  1. A.

    Enable cross-zone load balancing on the Application Load Balancer that fronts the private instances.

  2. B.

    Give each Availability Zone's private subnets their own route table pointing at the NAT gateway in that zone.

  3. C.

    Assign a second elastic IP address to the existing NAT gateway so that it can fail over between zones.

  4. D.

    Create a NAT gateway in a public subnet in each of the three Availability Zones.

  5. E.

    Place the existing NAT gateway in an Auto Scaling group that spans all three Availability Zones.

Show answer

Answer: B, D

A NAT gateway is a zonal resource, so resilience comes from one gateway per zone plus per-zone route tables that keep traffic inside its own zone.

  • A. Cross-zone load balancing affects inbound distribution, not outbound internet access.
  • B. Per-zone route tables keep each zone's traffic on its own gateway, which is what makes the extra gateways effective.
  • C. An elastic IP address identifies the gateway and does not let it move between Availability Zones.
  • D. One gateway per zone removes the dependency on a single zone for egress.
  • E. A NAT gateway is a managed resource, not an instance that Auto Scaling can manage.
Question 9Design Secure Architectures

A company is replacing a server-based batch job with AWS Lambda functions invoked through Amazon API Gateway. A reviewer asks which security duty still belongs to the company under the AWS shared responsibility model. Which task remains the company's responsibility?

  1. A.

    Applying security patches to the managed language runtime.

  2. B.

    Scoping the function execution role to the actions and resources the code uses.

  3. C.

    Maintaining physical access controls and environmental protections at the data centers that host the compute fleet.

  4. D.

    Patching the host operating system under the execution environment.

Show answer

Answer: B

With Lambda, AWS operates everything below the function, leaving the customer responsible for the code and the permissions it is given.

  • A. AWS patches and updates the managed Lambda runtimes it publishes.
  • B. Least privilege on the execution role is configuration the customer owns; AWS enforces it but never authors it.
  • C. Physical data center security is the canonical example of security of the cloud.
  • D. The host and the execution environment beneath the function are operated entirely by AWS.
Question 10Design Secure Architectures

Twenty VPCs attach to a transit gateway. Production VPCs must reach shared services and each other, and development VPCs must reach shared services but must never reach production. The company wants this enforced by the network rather than by security group rules in each VPC. What should a solutions architect configure?

  1. A.

    One transit gateway per environment, connected to each other with a peering attachment for shared services access.

  2. B.

    Separate transit gateway route tables for production and development, each associated with its own attachments and propagations.

  3. C.

    A single transit gateway route table with network ACLs in the development VPCs that deny the production CIDR ranges.

  4. D.

    VPC peering between each development VPC and the shared services VPC, with the transit gateway used only by production.

Show answer

Answer: B

Transit gateway route tables are the isolation mechanism: associating attachments with different route tables and controlling propagation decides which networks can reach which.

  • A. A second gateway and a peering attachment add cost and complexity that route tables already avoid.
  • B. Association and propagation across separate route tables decides reachability centrally, with no route from development to production.
  • C. The route still exists and enforcement depends on every VPC maintaining its own ACLs.
  • D. Reverting to per-pair peering loses the hub model and central routing control.

Keep going with 814 more SAA-C03 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.