AWS SAA-C03
EXAM MASTERY
120 HIGH-YIELD MCQs
SCENARIO-BASED QUESTIONS WITH FULL EXPLANATIONS & AWS DOCUMENTATION
REFERENCES
Solutions Architect Associate (SAA-C03) Certification Preparation
WHAT'S INSIDE THIS BOOK
✔ 120 Real Exam-Style Scenario Questions Across 14 Domains
✔ Clear, Jargon-Free Explanations for Every Option
✔ Matches the Actual SAA-C03 Exam Style & Difficulty
✔ Backed by Official AWS Documentation References
✔ Covers Every Major SAA-C03 Exam Domain
Topics: IAM & Security • VPC & Networking • S3 & Storage • EC2 & Compute • Databases •
Load Balancing & Auto Scaling • Serverless & Integration • HA & Disaster Recovery •
Monitoring • Cost Optimization • Migration • Containers • CDN & DNS • Data & ML
Designed for AWS SAA-C03 Exam Candidates — 2026
, TABLE OF CONTENTS
14 Domains — 120 Questions
1. IAM & Security Fundamentals............................................................................... Q1–12
2. VPC & Networking...................................................................................................Q13–24
3. S3 & Storage Solutions...........................................................................................Q25–34
4. EC2 & Compute.........................................................................................................Q35–44
5. Databases (RDS, DynamoDB, Aurora)..............................................................Q45–54
6. Load Balancing & Auto Scaling...........................................................................Q55–62
7. Serverless & Application Integration...............................................................Q63–74
8. High Availability & Disaster Recovery.............................................................Q75–84
9. Monitoring, Logging & CloudWatch..................................................................Q85–90
10. Cost Optimization..................................................................................................Q91–98
11. Migration & Hybrid Cloud................................................................................ Q99–104
12. Containers (ECS, EKS, Fargate)......................................................................Q105–110
13. Content Delivery & DNS...................................................................................Q111–116
14. Data Analytics & Machine Learning............................................................Q117–120
, WELCOME
Let's get you AWS certified!
Hi there! This book is built for one purpose: helping you pass the AWS Certified Solutions Architect
– Associate (SAA-C03) exam with confidence.
Every question here is written in the same scenario-based style as the real exam — a company, a
requirement, and a decision to make. We've kept the explanations clear and jargon-free, without cutting
corners on technical accuracy.
HOW TO USE THIS BOOK
1. Read the scenario carefully — the requirement (cost, performance, security, availability)
determines the right answer.
2. Pick your answer — before looking at the solution.
3. Read ALL FOUR explanations — the exam tests your ability to eliminate close-but-wrong
distractors.
4. Note the AWS service and reference — know exactly which service solves which problem.
MARKING PATTERN
+4 for Correct • −1 for Incorrect (matches typical certification-exam-style scoring)
Good luck — let's get you exam-ready!
, Section 1: IAM & Security Fundamentals
Q1.
A company has multiple AWS accounts for different departments. The security team wants to
allow developers in the “Dev” account to access specific S3 buckets in the “Prod” account
without creating individual IAM users in the Prod account.
What is the MOST secure and scalable way to achieve this?
A. Create an IAM user in the Prod account for each developer and share the credentials B.
Create an IAM role in the Prod account with the necessary permissions, and configure a trust
policy allowing the Dev account to assume it C. Make the S3 buckets public and restrict access
using bucket policies based on IP address D. Copy the developers’ access keys from the Dev
account into the Prod account’s IAM users
Select the SINGLE best answer.
Correct Answer: B
Explanation (in simple terms): Cross-account IAM roles are the standard, secure way to let
identities from one AWS account access resources in another. You create a role in the Prod
account with a trust policy that names the Dev account as a trusted entity, and developers
assume that role temporarily (via STS) to get short-lived credentials — no permanent keys are
shared, and access can be revoked centrally at any time.
Why the others are wrong: - A. Creating individual IAM users in every account they need
access to doesn’t scale, multiplies credential management overhead, and increases the attack
surface — cross-account roles solve exactly this problem. - C. Making buckets public is a
serious security anti-pattern; IP-based restriction alone doesn’t provide identity-based access
control and violates the principle of least privilege. - D. Sharing or copying access keys across
accounts is a critical security violation — keys should never be duplicated across identities or
accounts.
AWS Reference: AWS IAM documentation — Cross-Account Access Using IAM Roles; AWS
Well-Architected Framework, Security Pillar.
Q2.
A Solutions Architect needs to grant a Lambda function permission to read objects from a
specific S3 bucket. The company’s security policy prohibits storing long-term credentials in
code or environment variables.