AWS CERTIFIED · ASSOCIATE SAA-C03

AWS Certified Solutions Architect - Associate

The most in-demand cloud certification of 2026. Scenario-based questions covering secure, resilient, high-performing and cost-optimized architectures.

Unlock SAA-C03 - 90-day access

10 full-length premium mock exams with full explanations on every question, review mode, practice mode and unlimited retakes for 90 days. New exams added to this track during your window are included.

Pass guarantee: average 85%+ across this track's mocks, sit the real exam, and if you fail we refund you in full. 14-day money-back on top. Terms.

Start the free diagnostic - no account needed Create account

Free Diagnostic Exam Free

15 questions · 25 min · pass mark 72% · Find out if you'd pass SAA-C03 today

Practice Exam 1 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Practice Exam 2 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Practice Exam 3 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Practice Exam 4 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Practice Exam 5 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Practice Exam 6 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Practice Exam 7 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Practice Exam 8 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Practice Exam 9 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Practice Exam 10 Premium

65 questions · 130 min · pass mark 72% · Full-length 65-question timed mock

Sample questions from this bank

Straight from the premium SAA-C03 exams, explanation included. Judge the quality before you spend a cent.

Design Secure Architectures

A logistics company runs a fleet-tracking API on EC2 instances behind an Application Load Balancer. The security team requires that database credentials used by the application be rotated automatically every 30 days without any code redeployment. Which solution meets this requirement with the least operational overhead?

  • A Store the credentials in AWS Secrets Manager and enable managed rotation with the built-in Lambda rotation function
  • B Store the credentials in AWS Systems Manager Parameter Store SecureString parameters and write a Lambda cron job to rotate them
  • C Embed the credentials in an encrypted environment file on each instance and update them with a maintenance window
  • D Store the credentials in an S3 bucket encrypted with SSE-KMS and reference them at boot time
Show answer and explanation

Correct: A

AWS Secrets Manager natively supports scheduled automatic rotation using a managed Lambda rotation function for supported databases, requiring no application redeployment. Parameter Store has no built-in rotation and would require custom code. Encrypted files and S3 objects still require manual rotation processes.

Reference: https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotating-secrets.html

Design Secure Architectures

A media startup must let a partner company read objects from a specific S3 bucket in the startup's account. The partner uses their own AWS account and must not receive any long-term credentials. Which approach follows the principle of least privilege?

  • A Make the S3 bucket public and share the object URLs with the partner
  • B Add the partner account root user to the bucket ACL with full control
  • C Create an IAM role in the startup account that trusts the partner account and grant read-only access to the bucket prefix
  • D Create an IAM user in the startup account and share the access keys with the partner
Show answer and explanation

Correct: C

A cross-account IAM role with a trust policy for the partner account lets the partner assume the role using temporary credentials scoped to read-only bucket access. Sharing access keys distributes long-term credentials, public buckets expose data broadly, and granting full control via ACL violates least privilege.

Reference: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_common-scenarios_aws-accounts.html

Design Secure Architectures Choose all that apply

A healthcare analytics firm must encrypt patient records at rest across multiple services. Which combinations correctly provide encryption at rest with customer-managed keys? (Choose TWO)

  • A Enable encryption on an Amazon EBS volume using a customer managed KMS key
  • B Attach a security group that only allows HTTPS traffic
  • C Enable AWS Shield Advanced on the account
  • D Enable SSE-KMS on an S3 bucket using a customer managed KMS key
  • E Enable TLS 1.2 on the Application Load Balancer listener
Show answer and explanation

Correct: A, D

SSE-KMS on S3 and EBS volume encryption both use customer managed KMS keys to encrypt data at rest. TLS on a load balancer and HTTPS-only security groups address data in transit, and Shield Advanced provides DDoS protection, none of which encrypt data at rest.

Reference: https://docs.aws.amazon.com/kms/latest/developerguide/services-ebs.html

Every question in the bank ships with an explanation at this depth. See how our questions are made.

About the SAA-C03 exam

What the real exam looks like and how PassForge gets you ready for it.

Format 65 questions (about 50 scored, 15 unscored), 130 minutes. Multiple choice (one correct) and multiple response (two or more correct).
Passing score 720 out of 1000 on a scaled score. PassForge sets its pass mark at 72% so clearing our mocks maps to clearing the real bar.
Real exam cost 150 USD to sit the real exam at Pearson VUE or PSI.

Domains and official weights

Every PassForge mock in this track mirrors these proportions, so your practice score maps to the real one.

Design Secure Architectures 30%
Design Resilient Architectures 26%
Design High-Performing Architectures 24%
Design Cost-Optimized Architectures 20%

How scoring works

AWS scores on a scaled range of 100 to 1000; you need 720 to pass. It is compensatory, meaning you do not have to pass each domain individually, only the overall score. About 15 of the 65 questions are unscored trial items that do not affect your result, which is why our full-length mocks also run 65 questions.

How to pass with PassForge

  1. Take the free diagnostic to see your starting level and per-domain breakdown.
  2. Read the explanation on every question you miss. The reference link goes to the official AWS docs.
  3. Use practice mode to drill your two weakest domains without the timer.
  4. Sit full-length timed mocks back to back until you are consistently above 72% with time to spare.
  5. Book the real exam once two mocks in a row clear the pass mark comfortably.