2026 Licensing & Certification Curricula (Securities, Cloud, IT, Real Estate, Bar & CPA) are now live
Tactical Certification Roadmap

AWS Certified Solutions Architect – Associate 6-Week Study Plan

The AWS Certified Solutions Architect – Associate (SAA-C03) examination tests 65 questions across 130 minutes, requiring a scaled passing score of 720 / 1000. Candidates must master complex architectural tradeoffs between security, resilience, performance, and cost optimization. Follow this structured 6-week schedule to allocate your 80–120 study hours, complete full timed mocks, and memorize the essential Pearson VUE first-5-minute dry-erase dump sheet.

6 WeeksStructured Timeline
80–120 HrsTotal Study Effort
720 / 1000Passing Benchmark
65 QsMock Simulator

6-Week Structured SAA-C03 Study Schedule

Week 1: Domain 1 — Design Secure Architectures (Part 1: IAM & Organizations)

Master IAM roles, instance profiles, permission boundaries, and AWS Organizations Service Control Policies (SCPs). Deep dive into cross-account S3 bucket access with KMS Customer Managed Keys (CMKs) and IAM Identity Center federation with SAML 2.0.

Week 2: Domain 1 — Design Secure Architectures (Part 2: Network & Data Security)

Master VPC Security Groups (stateful) vs Network ACLs (stateless ephemeral return ports), AWS WAF rate-based rules, AWS Shield Advanced, KMS envelope encryption mechanics (kms:GenerateDataKey), S3 bucket TLS enforcement (aws:SecureTransport), and S3 Object Lock Compliance mode.

Week 3: Domain 2 — Design Resilient Architectures

Master asynchronous decoupling with Amazon SQS (Visibility Timeout, DLQs, FIFO MessageGroupId), SNS fanout, EventBridge content filtering, Step Functions Saga rollback pattern, EC2 Auto Scaling Target Tracking with ELB health checks, RDS Multi-AZ vs Read Replicas, and Aurora Global Database.

Week 4: Domain 3 — Design High-Performing Architectures

Master global edge acceleration: CloudFront Origin Shield vs AWS Global Accelerator (Anycast UDP/TCP), S3 Transfer Acceleration & Multipart Upload, EBS gp3 vs io2 Block Express, EC2 Cluster Placement Groups, FSx for Lustre linked to S3, DynamoDB DAX microsecond caching, and Direct Connect.

Week 5: Domain 4 — Design Cost-Optimized Architectures

Master S3 Intelligent-Tiering vs Standard-IA, S3 Lifecycle rules down to Glacier Deep Archive ($0.00099/GB), Compute Savings Plans vs Spot Fleets, AWS Graviton ARM64 price-performance, VPC Gateway Endpoints for S3/DynamoDB (eliminating NAT charges), and Aurora Serverless v2.

Week 6: Full Timed Mocks, Weak Area Drills & Exam Day Strategy

Complete multiple timed 65-question mock exams on the simulator, review distractor autopsies for missed questions, memorize the Pearson VUE dry-erase dump sheet, and practice rapid elimination of common exam traps.

Exam Day Strategy

Pearson VUE First-5-Minute Dry-Erase Dump Sheet

During the initial 15-minute tutorial at the Pearson VUE test center, write down these critical architectural rules on your provided dry-erase scratch booklet:

Storage Class Tiers & Rules

  • Intelligent-Tiering: Unknown/unpredictable; NO retrieval fee!
  • Standard-IA: Min 30 days, min 128KB, per-GB retrieval fee.
  • One Zone-IA: 20% cheaper than Standard-IA; recreatable data.
  • Glacier Deep Archive: 180 days min, 12-48h retrieval, cheapest!
  • Prefix Limits: 3,500 PUT / 5,500 GET per partitioned prefix.

Database & Caching Rules

  • RDS Multi-AZ: Synchronous, failover only (RPO=0, DNS CNAME switch).
  • Read Replica: Asynchronous read scaling (RPO > 0).
  • Aurora Global DB: Dedicated storage replication < 1s lag across regions.
  • DynamoDB DAX: Microsecond in-memory cache; zero query rewrite.
  • Redis vs Memcached: Redis = Sorted sets, multi-AZ, persistence.

Networking & Security Rules

  • Gateway Endpoints: FREE for S3 & DynamoDB (bypasses NAT!).
  • Interface Endpoints: ENI with private IP for all other services ($).
  • Security Groups: Stateful (instance ENI). Only ALLOW rules.
  • Network ACLs: Stateless (subnet). Outbound ephemeral 1024-65535!
  • Global Accelerator: Anycast IPs, UDP/TCP non-HTTP over AWS fiber.
  • Direct Connect: Dedicated physical fiber (consistent low latency).

Compute & DR Rules

  • Placement Groups: Cluster = Low latency single AZ; Spread = Rack isolated.
  • Spot Fleet: Capacity-optimized allocation minimizes interruptions.
  • Graviton: ARM64 up to 40% better price-performance.
  • DR Spectrum: Backup & Restore ($) < Pilot Light ($$) < Warm Standby ($$$) < Active-Active ($$$$).
  • Pilot Light: Live DB replication running, compute dormant/minimal.
Launch SAA-C03 Exam Simulator →