For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Associate (SAA-C03)AWS SAA-C03 Practice Exam 5
    AWS Solutions Architect Associate (SAA-C03)

    AWS SAA-C03 Practice Exam 5

    65 free questions · No sign-up required to browse

    Comprehensive practice exam for AWS Certified Solutions Architect - Associate (SAA-C03). Covers Design Secure Architectures, Resilient Architectures, High-Performing Architectures, and Cost-Optimized Architectures.

    65
    Questions
    Mixed
    Difficulty
    72%
    Pass mark

    Difficulty breakdown

    Easy(13)
    Medium(39)
    Hard(13)

    Topics covered

    Browse all topics →
    Domain 1.1: Secure AccessDomain 1.2: Secure WorkloadsDomain 1.3: Data SecurityDomain 2.1: Scalable ArchitecturesDomain 2.2: Highly Available ArchitecturesDomain 2.3: Decoupling MechanismsDomain 2.4: Resilient StorageDomain 3.1: Storage PerformanceDomain 3.2: Compute PerformanceDomain 3.3: Database PerformanceDomain 3.4: Network PerformanceDomain 3.5: Data IngestionDomain 4.1: Storage Cost OptimizationDomain 4.2: Compute Cost OptimizationDomain 4.3: Database Cost OptimizationDomain 4.4: Network Cost Optimization

    Sample questions

    Q01Easy1 mark

    A company needs to grant an external auditor read-only access to specific AWS resources. The auditor has their own AWS account. What is the MOST secure way to grant this access?

    View question with guidance →
    Q02Medium1 mark

    An application running on EC2 instances needs to access objects in an S3 bucket. The security team mandates that no hardcoded credentials are used. How should a solutions architect meet this requirement?

    View question with guidance →
    Q03Medium1 mark

    A company is designing a VPC for a multi-tier web application. They need to block specific malicious IP addresses from accessing the web servers, while allowing legitimate HTTPS traffic. Which TWO actions should the solutions architect take? (Select TWO.)

    View question with guidance →
    Q04Hard1 mark

    A large enterprise uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no user or role in any member account can disable AWS CloudTrail. What is the MOST efficient way to enforce this?

    View question with guidance →
    Q05Medium1 mark

    A company hosts a web application on an Application Load Balancer (ALB). They are experiencing SQL injection attacks and cross-site scripting (XSS) attempts. Which AWS service should be deployed to protect the application?

    View question with guidance →

    Ready to Practice the full exam?

    All 65 questions with worked answers, mark schemes, and AI tutoring.

    Sign up freeTake the exam

    All questions (65)

    Free to browse · no sign-up required
    Q01A company needs to grant an external auditor read-only access to specific AWS resources. The auditor has their own AW...EasyQ02An application running on EC2 instances needs to access objects in an S3 bucket. The security team mandates that no h...MediumQ03A company is designing a VPC for a multi-tier web application. They need to block specific malicious IP addresses fro...MediumQ04A large enterprise uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no user...HardQ05A company hosts a web application on an Application Load Balancer (ALB). They are experiencing SQL injection attacks ...MediumQ06A financial company requires that all data stored in Amazon S3 is encrypted at rest using keys managed by the company...HardQ07Which AWS service provides intelligent threat detection by continuously monitoring for malicious activity and unautho...EasyQ08An application needs to connect to an Amazon RDS database. The database credentials must be encrypted, stored securel...MediumQ09A company requires that all AWS API calls are logged. They also need to mathematically prove that the log files have ...MediumQ10A mobile application needs to authenticate users using their social media accounts (Google, Facebook). Once authentic...MediumQ11A government agency is setting up a hybrid cloud architecture. They require a dedicated network connection from their...HardQ12A financial institution must store regulatory documents in Amazon S3 for 7 years. During this time, the documents can...MediumQ13A company wants to automatically discover and classify sensitive data, such as Personally Identifiable Information (P...EasyQ14A company is hosting a secure web application. They need to terminate SSL/TLS connections and protect the application...MediumQ15A company has 50 AWS accounts managed by AWS Organizations. They want to provide their employees with single sign-on ...MediumQ16An application in a private subnet needs to access an Amazon DynamoDB table. Traffic must not traverse the public int...MediumQ17A company has an unencrypted Amazon RDS MySQL database. A new compliance mandate requires that the database must be e...MediumQ18A security team wants a centralized view of security alerts and compliance status across all their AWS accounts. They...EasyQ19A company needs to inspect all outbound traffic from their VPC to the internet. They want to block traffic to known m...EasyQ20A company uses AWS Certificate Manager (ACM) to provision SSL/TLS certificates for their Application Load Balancers. ...MediumQ21A company runs a critical database on Amazon RDS for MySQL. They need to ensure the database remains available even i...EasyQ22An e-commerce application processes orders asynchronously. It is critical that orders are processed exactly once and ...MediumQ23A web application runs on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). Sometimes...MediumQ24A global application is deployed in the us-east-1 and eu-west-1 regions. Users should be routed to the region that pr...HardQ25A company wants to build an event-driven architecture. When a new object is uploaded to an S3 bucket, multiple indepe...MediumQ26A company is designing a disaster recovery (DR) strategy for their critical application. They require a Recovery Time...HardQ27A company stores critical documents in Amazon S3. They need to protect against accidental deletion or overwriting of ...EasyQ28A fleet of EC2 instances running Linux needs to access a shared file system concurrently. The file system must scale ...MediumQ29An application requires a complex workflow involving multiple AWS Lambda functions. The workflow includes branching l...MediumQ30A company needs to ingest real-time clickstream data from their website. The data needs to be buffered and then loade...MediumQ31A global financial application requires a relational database. The database must span multiple AWS Regions to provide...HardQ32A gaming company needs a NoSQL database to store player profiles. The game is played globally, and players must exper...MediumQ33A company wants to back up their on-premises file servers to AWS. They want to keep frequently accessed files locally...EasyQ34An application processes messages from an Amazon SQS queue. Occasionally, a malformed message causes the processing a...MediumQ35A company exposes a REST API using Amazon API Gateway. During peak hours, backend services are overwhelmed by sudden ...MediumQ36A company is deploying a containerized application using Amazon ECS. The application must be highly available and res...HardQ37An application is hosted on an on-premises server and an EC2 instance. A solutions architect needs to configure DNS f...MediumQ38A media company serves large video files to users globally. Users in regions far from the origin server are experienc...EasyQ39A gaming leaderboard application requires an in-memory data store to handle millions of requests per second with sub-...MediumQ40A database running on an EC2 instance requires block storage. The workload is highly transactional and requires susta...MediumQ41An application uses Amazon DynamoDB as its backend database. The application is experiencing high read traffic for a ...HardQ42A company needs to upload 100 GB files to an Amazon S3 bucket from locations around the world. The uploads are curren...MediumQ43A high-performance computing (HPC) application requires tightly coupled EC2 instances with the lowest possible networ...HardQ44A company has an application hosted in the us-west-2 region. Global users are experiencing high latency due to intern...EasyQ45A reporting application runs heavy analytical queries against an Amazon RDS for PostgreSQL database. These queries ar...MediumQ46A company has petabytes of structured data stored in Amazon S3. They want to run complex SQL queries across this data...MediumQ47A machine learning application processes thousands of small files concurrently from an Amazon EFS file system. The ap...MediumQ48A company has 50 VPCs across multiple AWS Regions. They need to establish network connectivity between all VPCs and t...HardQ49A company is streaming IoT sensor data into Amazon Kinesis Data Streams. They need to calculate rolling averages of t...MediumQ50A research facility needs to transfer 50 Terabytes of data to AWS. Their internet connection is 100 Mbps and is heavi...EasyQ51A serverless application uses AWS Lambda. During sudden traffic spikes, users experience high latency because Lambda ...MediumQ52A company needs to extract data from various databases, transform it, and load it into a data warehouse. They want a ...MediumQ53An application downloads large video files from Amazon S3. Users often skip to the middle of a video. To improve perf...MediumQ54A company stores millions of images in Amazon S3. The access patterns are unpredictable; some images are accessed dai...EasyQ55A company runs a batch processing job every night. The job takes 3 hours to complete. The workload is fault-tolerant ...MediumQ56A company has a steady-state workload running on EC2 instances. They want to commit to a 1-year term to reduce costs....MediumQ57A company has hundreds of EC2 instances in private subnets that frequently access Amazon S3 to download large dataset...HardQ58A startup is building a new application with an unpredictable workload. The database will experience periods of high ...MediumQ59A company generates daily log files that are stored in Amazon S3. The logs are frequently accessed for the first 30 d...HardQ60A company has hundreds of EC2 instances. The finance team noticed that EC2 costs are very high. They suspect many ins...EasyQ61A new mobile game uses Amazon DynamoDB. The game is expected to go viral, but the exact traffic patterns and peak loa...MediumQ62A company hosts a website on EC2 instances. They are paying high AWS Data Transfer Out charges because users are down...MediumQ63A company takes daily EBS snapshots of their EC2 instances. Over time, the storage costs for these snapshots have gro...MediumQ64A company has a multi-tier application. The web servers are in a public subnet in Availability Zone A, and the databa...HardQ65A company uses Amazon Macie to scan S3 buckets for sensitive data. They have a bucket containing 50 TB of historical ...Medium