Every AWS exam guide opens with a table of domains and percentages, and most candidates skim right past it. That's a mistake. Those weights are the closest thing AWS gives you to a scoring map: they tell you which third of the exam can sink you and which sections are worth a light review. This article has AWS certification exam domains explained cert by cert, using the official AWS Certification Exam guides as the source of record, so you can see the whole portfolio's blueprints in one place instead of downloading five PDFs.

A quick word on how I picked the six exams below. These are the certifications most candidates actually register for: the entry-level Cloud Practitioner, the two most popular associate exams, and the specialty and professional credentials that carry the most weight in hiring conversations. Each entry follows the same pattern — the published domain weights, what tasks sit inside each domain, who the exam fits, and the drawback that catches people off guard. That way you can compare blueprints across certs without switching tabs.

One timing note before the list. AWS confirmed in September 2026 that three exams are being updated: Machine Learning Engineer – Associate (MLA-C02), Solutions Architect – Professional (SAP-C03, registration opens October 27, 2026), and Developer – Associate (DVA-C03). The weightings below reflect the current published guides, and I've flagged where a refresh is coming. If you're booking an exam for early 2027, double-check the exam code on your registration page against this article before you build your study plan.

1. Cloud Practitioner (CLF-C02): the four-domain foundation

Cloud Practitioner is the entry point, and its blueprint is the simplest in the portfolio: four domains that favor breadth over depth. Per the CLF-C02 exam guide, the split is:

  • Cloud Concepts — 24%. The value proposition of the cloud: elasticity, agility, high availability, and the global infrastructure model (Regions, Availability Zones, edge locations). You'll also see questions on the benefits of moving to cloud versus on-premises, and on the AWS Well-Architected Framework at a conceptual level.
  • Security and Compliance — 30%. The heaviest domain relative to its difficulty. Expect the shared responsibility model in detail (who patches what, who encrypts what), IAM basics like users, groups, roles, and policies, and how AWS handles compliance programs such as artifact reports.
  • Cloud Technology and Services — 34%. The largest slice. Core compute (EC2, Lambda), storage (S3, EBS), databases (RDS, DynamoDB), and networking (VPC, CloudFront), plus deployment and migration concepts like the AWS Cloud Adoption Framework.
  • Billing, Pricing, and Support — 12%. Pricing models (On-Demand, Reserved, Spot, Savings Plans), the Free Tier, cost tools like AWS Budgets and Cost Explorer, and the differences between support plan tiers.

The exam itself is 65 questions in 90 minutes, and the scoring runs on a 100–1000 scale with 700 needed to pass. Who it fits: career changers, new grads, and non-technical colleagues who need cloud literacy. It's also a common first step for sales, project management, and finance staff who work alongside cloud teams.

The limitation is that nearly a third of your score comes from technology questions about services you may never have touched, so pure conceptual reading won't carry you. Candidates who've never opened the console often fail not on Cloud Concepts but on Technology and Services, because "knowing what S3 is" and "knowing which storage class fits an archiving workload" are different questions. Budget real study time for the 34% domain, even though the exam is labeled foundational. And don't skip billing: at 12% it's the smallest domain, but those questions are concrete and rule-based, which makes them some of the easiest points on the test if you actually study the pricing models.

2. Solutions Architect – Associate (SAA-C03): security leads the scoring

This is the most popular AWS cert, and its blueprint rewards one thing above all: knowing how to build securely. The SAA-C03 exam guide lays out four domains:

  • Design Secure Architectures — 30%. IAM design (roles versus users, least privilege, cross-account access), encryption at rest and in transit with KMS and CloudHSM, network security with security groups, NACLs, and WAF, and securing workloads across application tiers.
  • Design Resilient Architectures — 26%. Multi-AZ and multi-Region design, decoupling with SQS, SNS, and load balancers, disaster recovery patterns from backup-and-restore through pilot light to multi-site active-active, and Route 53 routing policies.
  • Design High-Performing Architectures — 24%. Picking the right compute (EC2 families, containers, Lambda), storage, database (relational versus NoSQL versus caching with ElastiCache), and data transfer options for a given workload.
  • Design Cost-Optimized Architectures — 20%. S3 storage classes and lifecycle policies, EC2 purchasing options, right-sizing, and designing cost-aware data transfer.

The exam is 65 questions in 130 minutes, and recent blueprint revisions have started folding AI/ML service selection into the design domains — questions on when to reach for Amazon Bedrock or SageMaker now appear alongside classic architecture scenarios.

Who it fits: anyone pursuing an architecture, cloud engineering, or DevOps career, and it's the associate cert hiring managers recognize most. It also works as a second cert for people who passed Cloud Practitioner and want a credential with real signal.

The drawback: scenario questions are long, often a full paragraph describing a company's requirements, and several answers look plausible. A typical question gives you four architectures that all technically work and asks which is most secure, most cost-efficient, or most resilient. You need to understand why the winning option wins, not just recognize service names. Candidates who drill weighted practice questions aligned to these four domains consistently report that Domain 1 questions punish shallow IAM knowledge hardest. If your security fundamentals are weak, a 30% domain means roughly 20 of your 65 questions sit exactly there.

3. Developer – Associate (DVA-C02): build, deploy, debug

The Developer exam is more hands-on than people expect. According to the Developer Associate guide, the current DVA-C02 blueprint breaks into four domains:

  • Development with AWS Services — 32%. Writing code against AWS APIs and SDKs, working with Lambda (invocation models, concurrency, cold starts), and using services like DynamoDB (partition keys, indexes, capacity modes) and S3 from application code. This is the single heaviest domain on the exam.
  • Security — 26%. Authentication and authorization in apps (IAM roles for compute services, Cognito user pools versus identity pools), encryption with KMS, and secrets management with Secrets Manager and Parameter Store.
  • Deployment — 24%. CI/CD with CodeCommit, CodeBuild, CodeDeploy, and CodePipeline, plus Elastic Beanstalk, CloudFormation, SAM, and container deployment on ECS and ECR.
  • Troubleshooting and Optimization — 18%. Reading CloudWatch logs and metrics, tracing with X-Ray, and tuning performance, including DynamoDB throttling and Lambda memory allocation.

Recent versions of the exam also expect you to understand how to invoke Amazon Bedrock models from application code and manage prompt workflows, which is a sign of where DVA-C03 will push further.

Note that AWS has already announced DVA-C03 as part of the September 2026 refresh, so if you're early in your study plan, check the updated guide before committing to a date. The domain structure is expected to stay recognizable, but the task statements will reflect how the developer role has shifted toward AI-assisted and AI-integrated application work.

Who it fits: working developers and engineers who write code against AWS daily. The limitation is that it assumes real coding context; pure sysadmins often find the SDK-heavy questions harder than the services themselves. If you can't read a snippet of Lambda code and spot why it's failing to assume a role, the 32% domain will be a long afternoon. Hands-on lab time matters more for this blueprint than for any other associate exam.

4. Security – Specialty (SCS-C03): restructured in late 2025

AWS replaced SCS-C02 with SCS-C03 on December 2, 2025, and the domain structure changed meaningfully. The SCS-C03 exam guide shows six domains with reshuffled weights, including a new Governance domain at 14% and Identity and Access Management rising to 20%. Independent comparisons of the two versions put the core knowledge overlap at roughly 85%, with Infrastructure Security dropping from 26% to 18% and new AI/ML security coverage added. The C03 version also introduces ordering and matching question types alongside standard multiple choice and multiple response, which changes how you practice: you can't rely on elimination alone when a question asks you to sequence incident response steps.

Before-and-after comparison of SCS-C02 and SCS-C03 domain weights, part of AWS certification exam domains explained cert by cert, showing IAM rising to 20% and a new 14% Governance domain.

The six domains cover threat detection and incident response (16%), security logging and monitoring (18%), infrastructure security (18%), IAM (20%), data protection (18%), and the new governance slice (14%). In practical terms, governance means multi-account strategy: AWS Organizations, service control policies, Control Tower, and centralized compliance. Data protection leans on KMS key policies, S3 bucket policies, and certificate management. Logging and monitoring is heavily CloudTrail, GuardDuty, Security Hub, and Config.

Who it fits: security engineers, cloud security analysts, and architects who want a credential that signals depth rather than breadth. It's one of the more respected AWS credentials in security job postings precisely because the blueprint is unforgiving.

The drawback is scope: six domains means six distinct study tracks, and the governance material trips up candidates who only prepared for hands-on security controls. Someone who's excellent at hardening a VPC can still lose points on questions about SCP inheritance across an organization. If you studied for C02, you're mostly ready, but the IAM and governance additions deserve targeted work — together they account for 34% of the current exam, more than a third of your score sitting in material that grew or arrived with the new version.

5. DevOps Engineer – Professional (DOP-C02): six domains, deepest exam here

Professional-level blueprints read differently. The DevOps Engineer – Professional guide splits the exam into six domains:

  • SDLC Automation — 22%. CI/CD pipeline design, build and deploy automation, source control strategy, and testing integration. This is the largest domain and the heart of the cert.
  • Configuration Management and IaC — 17%. CloudFormation at depth (nested stacks, StackSets, drift detection), CDK, Systems Manager, and configuration drift management across fleets.
  • Resilient Cloud Solutions — 15%. High availability, fault tolerance, disaster recovery automation, and chaos-testing concepts.
  • Monitoring and Logging — 15%. CloudWatch in depth (custom metrics, alarms, dashboards), X-Ray, centralized logging architectures, and alerting design.
  • Incident and Event Response — 14%. Event-driven remediation with EventBridge and Lambda, troubleshooting methodologies, and escalation workflows.
  • Security and Compliance — 17%. Automating security controls, identity at scale, and compliance as code with Config rules and conformance packs.

No single domain dominates, which is the trap: you can't coast on one strength. The spread between the biggest and smallest domains is only eight percentage points, so a candidate who's brilliant at pipelines but weak on incident response has a real problem. Compare that to Cloud Practitioner, where you could theoretically survive a weak billing section.

Who it fits: platform engineers and senior DevOps practitioners with multi-year AWS experience. AWS recommends professional-level candidates have substantial hands-on background, and the questions assume it — they describe production environments with multiple constraints and ask you to choose an operational strategy, not recall a definition.

The limitation is exam length and question density; 75 questions in 180 minutes of dense scenario text wears people down. Pacing practice under timed conditions matters more here than on any associate exam. If that's your target, a DOP-C02 practice test that mirrors the six-domain spread is a realistic way to gauge pacing before you spend the exam fee. Aim to finish full-length simulations with time to review flagged questions, because flag-and-return is how most passing candidates handle the longest scenarios.

6. Solutions Architect – Professional (SAP-C02, with SAP-C03 arriving)

The current SAP-C02 blueprint runs four domains: Design Solutions for Organizational Complexity (26%), Design for New Solutions (29%), Continuous Improvement for Existing Solutions (25%), and Accelerate Workload Migration and Modernization (20%). The naming alone tells you the difference from the associate exam: these are organizational problems, not single-workload problems. Questions involve multiple accounts, multiple teams, hybrid connectivity, migration waves, and trade-offs between cost, security, and operational overhead where every option sacrifices something.

That structure changes soon. AWS has confirmed SAP-C03 registration opens October 27, 2026, and the new version expands from four domains to five, adding coverage of generative and agentic AI, resilience engineering, and post-quantum cryptography, according to AWS's September 2026 certification update. The services you've studied for C02 still matter; the context you're tested in is what shifts.

Who it fits: senior architects designing multi-account, multi-team environments, and consultants who need the portfolio's most recognized architecture credential. The drawback is twofold: the questions are the longest in the portfolio (some scenarios run three paragraphs before the actual question), and the blueprint itself is a moving target right now.

If you're mid-prep on SAP-C02, finishing before the transition is cleaner than restarting on a five-domain blueprint. If you haven't started, waiting for C03 materials to mature may be smarter than studying toward a retiring exam. Either way, a timed SAP-C02 practice test helps you confirm you're ready before the window closes. Professional exams cost more than associate ones, and a failed attempt means paying the retake fee, so a realistic readiness check is money well spent.

Turning domain weights into a study plan

Across all six blueprints, one pattern repeats: the heaviest domain is usually the one candidates enjoy studying least. Cloud Practitioner leans on billing and support details people skip. SAA-C03 weights security highest. SCS-C03 raised IAM and added governance. DOP-C02 spreads weight so evenly that there's no safe corner at all. Treat the percentages as a study-hours allocator: if a domain is worth 30% of your score, it deserves roughly 30% of your prep time, weighted further by how weak you are in it. A simple formula works well — domain weight multiplied by your gap in that domain, ranked highest first.

There's also a floor effect worth knowing. Every blueprint's smallest domain still carries scored questions. On a 65-question exam, a 12% domain is seven or eight questions, and on a scaled score out of 1000 where you need 700, that's a meaningful chunk of the margin between passing and a retake fee. Skipping small domains is the most common self-inflicted wound in AWS prep.

The other pattern is drift. AWS revises blueprints regularly, and 2026 has been busy, with SCS-C03 live since December 2025 and SAP-C03, DVA-C03, and MLA-C02 in the pipeline. Always match your study materials to the exam code on your registration, not the code printed on a course you bought last year. A domain table for a retired version is worse than no table, because the weights you memorize will quietly mislead your time allocation.

The most efficient way to close the loop is to test yourself against the blueprint. On ExamJungle, practice exams are organized by certification, so you can run a timed session, then filter your review to the domains where you missed questions. The detailed explanations walk through why each option is right or wrong, which matters on scenario exams where two answers both look defensible. When an explanation doesn't click, Caesar AI can expand it or generate a harder variant of the same question, so you end up understanding the concept rather than memorizing the item. That combination, blueprint-driven study plus weighted practice, is also the lens behind our breakdown of AWS practice exams compared by real pass-rate data.

One practical idea if you're juggling multiple domains: a simple domain-weight planner where you enter your exam code and your confidence per domain, and it outputs weekly study hours per domain proportional to blueprint weight. Even a spreadsheet version of that beats studying what feels comfortable. Comfort is the enemy here; the domains that bore you are usually the ones quietly holding 25% of your score.

Questions readers ask about AWS exam domains

Do the domain percentages translate directly into question counts? Roughly, yes. On a 65-question associate exam, a 30% domain yields about 19 or 20 scored questions, though AWS includes unscored experimental items, so the visible mix can vary slightly from sitting to sitting.

How often does AWS change exam domains? Major versions (like SCS-C02 to SCS-C03) arrive every two to three years per exam, with smaller in-version tweaks in between. AWS announces changes on its Training and Certification blog months in advance, so the code on your registration page is the authority.

Should I skip low-weight domains? No. Even a 12% domain like Cloud Practitioner's billing section is worth seven or eight questions, and those are often the easiest points on the exam because the material is concrete and memorizable. Low-weight domains are where underprepared candidates quietly lose their margin.

Are the domains the same across all AWS associate exams? No. Each associate cert has its own blueprint: SAA-C03 is architecture-focused with four design domains, while DVA-C02 centers on development, deployment, and troubleshooting. SysOps Administrator – Associate uses yet another structure oriented around operations and monitoring. Always pull the guide for your specific exam code.

Where do I find the official domain list for my exam? The AWS Certification exam guides page links the current PDF or HTML guide for every active exam. That's the only source you should trust for weightings; third-party summaries age quickly during refresh cycles like the 2026 updates, and an outdated percentage can distort weeks of study planning.

Keep building your AWS exam plan