SAA-C03 Sample Questions & Answers
Designing secure access to resources and workloads carries the heaviest weight, ahead of building scalable, resilient architectures, choosing high-performing storage and compute options, and optimizing database and storage costs.
Launch the full SAA-C03 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Design High-Performing Architectures · Determining high-performing data ingestion and transformation solutions.
A solutions architect is designing a system to process a continuous stream of IoT data. The data must be processed in the order it is received for each IoT device. The system must also be able to handle sudden spikes in data volume and store the raw data durably for later batch analysis. The solution should be serverless and cost-effective. Which architecture best meets these requirements?
Show answer & explanation
Correct answer: B
This architecture meets all requirements. Kinesis Data Streams is designed for high-volume streaming data. Using the device ID as the partition key ensures that data from each device is processed in order. AWS Lambda provides scalable, serverless processing. Kinesis Data Firehose is the simplest, most cost-effective way to durably store the raw streaming data in Amazon S3 for later analysis.
- Question 2Beginner
Design Secure Architectures · Design secure access to AWS resources.
True or False: When using an Amazon S3 gateway endpoint in a VPC, you can use an endpoint policy to restrict access to specific S3 buckets, but you cannot restrict access based on specific S3 object-level API actions like
s3:GetObject.Show answer & explanation
Correct answer: B
This statement is false. A VPC endpoint policy is an IAM resource policy that you attach to an endpoint. You can use this policy to control access to the service. The policy can restrict access to specific resources (like S3 buckets) and also to specific API actions (like
s3:GetObjectors3:PutObject). This allows for granular control over what actions can be performed on which resources through the endpoint. - Question 3Intermediate
Design Resilient Architectures · Designing scalable and loosely coupled architectures.
A company has a legacy monolithic application running on a large, memory-optimized Amazon EC2 instance. The application writes temporary data to a local disk during processing. The company wants to make the application highly available by running a standby instance in a different Availability Zone. The standby instance must be able to take over quickly and have access to the same temporary data if a failure occurs. The application cannot be refactored to use object storage. Which storage solution should be used for the temporary data to ensure high availability?
Show answer & explanation
Correct answer: C
Amazon EFS provides a shared file system that can be mounted concurrently by multiple EC2 instances, even across different Availability Zones. This makes it the perfect solution for this scenario. Both the primary and standby instances can read and write to the same EFS file system, ensuring that the temporary data is always available to the active instance. EBS volumes are tied to a single AZ, and instance stores are ephemeral and cannot be shared.
- Question 4Intermediate
Design Secure Architectures · Design secure access to AWS resources.
A development team is using AWS Organizations to manage multiple AWS accounts. The central security team wants to enforce a preventative control that denies any IAM user or role in member accounts from disabling AWS CloudTrail or modifying its configuration. This rule must be enforced even by the root user of the member accounts. How can this be achieved?
Show answer & explanation
Correct answer: B
Service Control Policies (SCPs) are the correct tool for this requirement. SCPs are a type of organization policy that you can use to manage permissions in your organization. They offer central control over the maximum available permissions for all accounts in your organization. An explicit
Denyin an SCP overrides anyAllowfrom IAM policies and applies to all principals in the account, including the root user. This makes them ideal for enforcing security guardrails. - Question 5Intermediate
Design High-Performing Architectures · Determine high-performing database solutions.
A gaming company is launching a new mobile game. The backend API is built using AWS Lambda and Amazon API Gateway. The company anticipates massive, unpredictable traffic spikes globally. The data for player leaderboards is stored in Amazon DynamoDB. To ensure a low-latency user experience, the company wants to cache database responses at the edge. Which service should be used to provide this caching capability with the least amount of architectural change?
Show answer & explanation
Correct answer: A
Enabling caching directly on the API Gateway stage is the simplest and most integrated solution. It allows you to cache the responses from your backend Lambda function, reducing the number of calls made to the function and the downstream DynamoDB table. This provides a low-latency experience for frequently requested data without requiring significant changes to the Lambda function or adding another service like ElastiCache to manage.
- Question 6Beginner
Design Secure Architectures · Design secure access to AWS resources.
The command to request temporary security credentials from AWS STS for an IAM role is
aws sts assume-role --role-arn "arn:aws:iam::123456789012:role/MyRole" --role-session-name "MySession". Which of the following is required for this command to succeed?Show answer & explanation
Correct answer: C
The
assume-roleaction is governed by the role's trust policy (also known as the assume role policy). This policy defines which principals (users, roles, or AWS services) are trusted to assume the role. The principal making theassume-rolecall must be listed and allowed thests:AssumeRoleaction within this trust policy. - Question 7Advanced
Design High-Performing Architectures · Determine high-performing and/or scalable storage solutions.
A solutions architect needs to design a shared storage solution for a high-performance computing (HPC) cluster running on Linux EC2 instances. The workload involves large-scale parallel processing of seismic data. The storage must provide millions of IOPS, sub-millisecond latencies, and be accessible via a POSIX-compliant file system interface. The data is linked to an Amazon S3 data lake. What is the most suitable storage service for this workload?
Show answer & explanation
Correct answer: C
Amazon FSx for Lustre is specifically designed for high-performance computing workloads. It provides a fully managed, high-performance file system optimized for fast processing of workloads like HPC, machine learning, and media processing. It offers sub-millisecond latencies, up to hundreds of gigabytes per second of throughput, and millions of IOPS. Its native integration with Amazon S3 makes it ideal for processing data from a data lake.
- Question 8Beginner
Design Secure Architectures · Design secure access to AWS resources.
A company is serving a static website from an Amazon S3 bucket configured for website hosting. To improve performance and add a layer of security, the company puts an Amazon CloudFront distribution in front of the S3 bucket. The security team requires that users must NOT be able to access the S3 content directly using the S3 URL. How can this be enforced?
Show answer & explanation
Correct answer: A
An Origin Access Identity (OAI) is a special CloudFront user that can be associated with a distribution. By creating an OAI and modifying the S3 bucket policy to grant
s3:GetObjectpermission only to this OAI, you can effectively block all direct access to the S3 bucket. Users will be forced to access the content through CloudFront, which will use the OAI to fetch content from the S3 origin securely. - Question 9Intermediate
Design High-Performing Architectures · Determine high-performing and/or scalable network architectures.
A company wants to establish a private, dedicated connection from its on-premises data center to its AWS VPCs. The company has multiple VPCs in the
us-east-1region and needs a scalable way to connect them to the on-premises network without creating complex peering meshes or multiple connections. Which architecture provides the most scalable and manageable solution?Show answer & explanation
Correct answer: C
AWS Transit Gateway acts as a cloud router and simplifies network architecture. By establishing a single Direct Connect connection with a transit virtual interface (VIF) to a Transit Gateway, the company can connect its on-premises network to hundreds or thousands of VPCs in a hub-and-spoke model. This is highly scalable and much easier to manage than creating multiple VIFs or a complex VPC peering mesh.
- Question 10Intermediate
Design Resilient Architectures · Designing scalable and loosely coupled architectures.
An e-commerce platform uses an Amazon SQS standard queue to process new orders. The processing is handled by a fleet of Amazon EC2 instances in an Auto Scaling group. During peak holiday sales, the number of messages in the SQS queue grows significantly, but the Auto Scaling group is slow to add new instances, causing delays in order processing. CloudWatch metrics show that the CPU utilization of the existing EC2 instances remains below 30%. What is the MOST effective way to ensure the Auto Scaling group scales in response to the order volume?
Show answer & explanation
Correct answer: B
The root cause of the issue is that the scaling trigger (CPU utilization) does not accurately reflect the workload (number of orders to process). Since the CPU is low, the scaling policy isn't triggered. The most direct and effective metric for this decoupled architecture is the number of messages waiting in the SQS queue. A target tracking policy based on
ApproximateNumberOfMessagesVisiblewill automatically scale the number of consumer instances up or down to keep the queue backlog at a desired level.
Ready for the real thing?
The full SAA-C03 simulator has every exam-style question, timed mode, and instant scoring.