Eight weeks at 8 to 10 hours per week is enough to take someone with basic cloud familiarity to a confident SAA-C03 pass. The trick is spending those hours in proportion to the exam, not your comfort. SAA-C03 weights security at 30% and resilience at 26%, so more than half the exam lives in two domains, and a study plan that treats all services equally wastes time on the small ones.
This schedule follows the domain weights, builds hands-on reps into every week, and runs practice exams as a feedback loop rather than a final-week cram. For the exam mechanics, start with the complete SAA-C03 guide; for the topic-level map, keep the domains breakdown open.
Find out where you stand first
Take the free SAA-C03 sample questions cold (no signup, real exam style), then read on with your gaps in mind. When you are ready for full rehearsal, Preporato's SAA-C03 practice tests include 6 full-length exams (401 questions in total, domain-proportional, every answer explained) for a one-time $19.99 with lifetime access.
Exam Quick Facts
Learn by exploring first
If you learn better by wandering a world than reading a syllabus, our SAA-C03 RPG study map turns the service landscape into a game board. Many learners use it to build intuition before the structured weeks below.
The Schedule
Foundations
Week 1- •AWS global infrastructure: Regions, AZs, edge locations
- •The Well-Architected Framework and its pillars
- •Set up a Free Tier account; learn the console and IAM basics
- •Take a full diagnostic practice exam and map your domain gaps
Compute & Networking
Week 2- •EC2 instance families, purchasing options, Auto Scaling
- •VPC core: subnets, route tables, IGW, NAT, security groups vs NACLs
- •Elastic Load Balancing types (ALB, NLB, GWLB)
- •Hands-on: build a VPC with public and private subnets
Storage
Week 3- •S3 storage classes, lifecycle policies, versioning
- •EBS volume types vs instance store; EFS vs FSx
- •S3 durability, consistency, and access controls
- •Hands-on: lifecycle a bucket from Standard to Glacier
Databases
Week 4- •RDS, Multi-AZ vs read replicas, Aurora
- •DynamoDB: partition keys, capacity modes, DAX, global tables
- •ElastiCache, Redshift, and when each fits
- •Hands-on: RDS Multi-AZ failover, a DynamoDB table
Security (30%)
Week 5- •IAM deep: policies, roles, cross-account, identity federation
- •Encryption: KMS, envelope encryption, in-transit vs at-rest
- •Network security: security groups, NACLs, VPC endpoints, WAF, Shield
- •Hands-on: least-privilege role, S3 bucket policy, KMS key
Resilience (26%)
Week 6- •Multi-AZ and multi-Region designs; Route 53 routing policies
- •Decoupling with SQS, SNS, EventBridge
- •Disaster-recovery strategies (backup/restore to multi-site)
- •Hands-on: SQS + Lambda fan-out; a Route 53 failover record
Performance & Cost
Week 7- •Caching: CloudFront, ElastiCache, DAX; performance patterns
- •Cost: Reserved Instances, Savings Plans, Spot, S3 class economics
- •CloudWatch, Trusted Advisor, Cost Explorer
- •Hands-on: front an S3 site with CloudFront
Rehearsal
Week 8- •One timed full-length practice exam per day, error-log review between
- •Re-drill your two weakest domains from the log
- •Reach 800/1000-equivalent on three consecutive timed exams
- •Skim the exam guide, rest the final day, sit the exam
Day-one benchmark: answer these three SAA-C03 questions cold, then note which domain tripped you up. That domain gets extra time in the plan below.
Three quick SAA-C03 questions
A developer needs to implement an AWS Lambda function in AWS account A that accesses an Amazon Simple Storage Service (Amazon S3) bucket in AWS account B. As a Solutions Architect, which of the following will you recommend to meet this requirement?
Create an IAM role for the AWS Lambda function that grants access to the Amazon S3 bucket. Set the IAM role as the AWS Lambda function's execution role. Make sure that the bucket policy also grants access to the AWS Lambda function's execution role If the IAM role that you create for the Lambda function is in the same AWS account as the bucket, then you don't need to grant Amazon S3 permissions on both the IAM role and the bucket policy. Instead, you can grant the permissions on the IAM role and then verify that the bucket policy doesn't explicitly deny access to the Lambda function role. If the IAM role and the bucket are in different accounts, then you need to grant Amazon S3 permissions on both the IAM role and the bucket policy. Therefore, this is the right way of giving access to AWS Lambda for the given use-case. Complete list of steps to be followed:  via - https://aws.amazon.com/premiumsupport/knowledge-center/lambda-execution-role-s3-bucket/
A retail company maintains an AWS Direct Connect connection to AWS and has recently migrated its data warehouse to AWS. The data analysts at the company query the data warehouse using a visualization tool. The average size of a query returned by the data warehouse is 60 megabytes and the query responses returned by the data warehouse are not cached in the visualization tool. Each webpage returned by the visualization tool is approximately 600 kilobytes. Which of the following options offers the LOWEST data transfer egress cost for the company?
Deploy the visualization tool in the same AWS region as the data warehouse. Access the visualization tool over a Direct Connect connection at a location in the same region AWS Direct Connect is a networking service that provides an alternative to using the internet to connect to AWS. Using AWS Direct Connect, data that would have previously been transported over the internet is delivered through a private network connection between your on-premises data center and AWS. For the given use case, the main pricing parameter while using the AWS Direct Connect connection is the Data Transfer Out (DTO) from AWS to the on-premises data center. DTO refers to the cumulative network traffic that is sent through AWS Direct Connect to destinations outside of AWS. This is charged per gigabyte (GB), and unlike capacity measurements, DTO refers to the amount of data transferred, not the speed.  via - https://aws.amazon.com/directconnect/pricing/ Each query response is 60 megabytes in size and each webpage for the visualization tool is 600 kilobytes in size. If you deploy the visualization tool in the same AWS region as the data warehouse, then you only need to pay for the 600 kilobytes of DTO charges for the webpage. Therefore this option is correct. However, if you deploy the visualization tool on-premises, then you need to pay for the 60 MB of DTO charges for the query response from the data warehouse to the visualization tool.
An Internet of Things (IoT) company would like to have a streaming system that performs real-time analytics on the ingested IoT data. Once the analytics is done, the company would like to send notifications back to the mobile applications of the IoT device owners. As a solutions architect, which of the following AWS technologies would you recommend to send these notifications to the mobile applications?
Amazon Kinesis with Amazon Simple Notification Service (Amazon SNS) Amazon Kinesis makes it easy to collect, process, and analyze real-time, streaming data so you can get timely insights and react quickly to new information. Amazon Kinesis offers key capabilities to cost-effectively process streaming data at any scale, along with the flexibility to choose the tools that best suit the requirements of your application. With Amazon Kinesis, you can ingest real-time data such as video, audio, application logs, website clickstreams, and IoT telemetry data for machine learning, analytics, and other applications. Amazon Kinesis enables you to process and analyze data as it arrives and respond instantly instead of having to wait until all your data is collected before the processing can begin. Amazon Kinesis will be great for event streaming from the IoT devices, but not for sending notifications as it doesn't have such a feature. Amazon Simple Notification Service (Amazon SNS) is a highly available, durable, secure, fully managed pub/sub messaging service that enables you to decouple microservices, distributed systems, and serverless applications. Amazon SNS provides topics for high-throughput, push-based, many-to-many messaging. Amazon SNS is a notification service and will be perfect for this use case. Streaming data with Amazon Kinesis and using Amazon SNS to send the response notifications is the optimal solution for the current scenario.
Full SAA-C03 set: 6 timed exams, every answer explained, $19.99 one-time.
See the practice testsPreparing for SAA-C03? Practice with 390+ exam questions
Week-by-Week Notes
Week 1 is diagnosis, not mastery. Take a full practice exam before you feel ready. The score is irrelevant; the per-domain results are the point, because they tell you whether this default schedule fits or needs rebalancing. Preporato's SAA-C03 practice exams break scores out by domain automatically across 24 tests.
Weeks 2 to 4 build the service vocabulary. Compute, networking, storage, and databases are the raw materials every scenario question assembles. You cannot reason about a resilient, cost-optimized architecture until you know what an ALB, a NAT gateway, a gp3 volume, and a DynamoDB partition key each do. Read the topic deep-dives as you go: VPC networking, S3 storage classes, and databases.
Week 5 is the biggest single domain. Security is 30% of the exam, and it is where "which is more secure" scenario questions live. Give IAM policy evaluation, encryption models, and network security their full week. The IAM and security guide is the companion.
Week 6 carries the second-biggest domain. Resilience (26%) is about designing for failure: Multi-AZ, decoupling, and disaster recovery. The exam loves "make this architecture more resilient" prompts. See high availability and DR and SQS vs SNS vs EventBridge.
Week 7 rounds out performance and cost (24% and 20%). These reward knowing the cheaper or faster option among several that all "work," which is the exam's favorite framing. The cost optimization guide covers the pricing models.
Week 8 is rehearsal only. No new services in the final week; consolidation of the heavyweight domains outscores anything new. Timed exams train the two-minutes-per-question pace, and your error log directs the review between them.
Hands-On Is Not Optional
SAA-C03 is a scenario exam, and scenarios stick when you have built the thing. Every week above has a Free Tier lab because "I configured a NAT gateway once" beats "I read about NAT gateways" on exam day. If you would rather follow guided depth than improvise, the SAA-C03 study guide walks each service with diagrams and worked examples.
Master These Concepts with Practice
Our SAA-C03 practice bundle includes:
- 6 full practice exams (390+ questions)
- Detailed explanations for every answer
- Domain-by-domain performance tracking
30-day money-back guarantee
The Weekly Rhythm
- Two weeknight sessions (2 hours): reading and video, each closed with 15 practice questions on the day's topic
- One weekend block (3-4 hours): the week's hands-on lab plus a timed practice segment
- Daily 15 minutes: error-log review, the highest-leverage quarter hour in the plan
Track Your Progress
8-Week Plan Milestones
0/8 completedStart with the Diagnostic
Everything calibrates off the week 1 diagnostic. Preporato's SAA-C03 prep includes 24 practice exams with explanations for every answer and per-domain tracking, plus a free question set if you want to sample the format first.
Sources:
- AWS Certified Solutions Architect - Associate Official Page
- AWS SAA-C03 Exam Guide (PDF)
- AWS Well-Architected Framework
Last updated: July 10, 2026
Ready to Pass the SAA-C03 Exam?
Join thousands who passed with Preporato practice tests
