AWS Training
Modules Listen All tracks
0:00 0:00

← Whitepapers and FAQs

SAA0 Quiz — Whitepapers and FAQs

18 questions, four options each, one correct answer, no partial credit. Answers and explanations below.

⚠️ Exam-styled questions written from the reading list and the exam guide. Not the AWS Official Practice Question Set, and not calibrated against real exam items.


1. How many pillars does the AWS Well-Architected Framework have, and which is most often missing from older study material?

2. A question stem ends "…with the least operational overhead". What does that phrase tell you?

3. Which general design principle supports using an Auto Scaling group rather than a fixed fleet size?

4. A requirement says the disaster recovery plan must be validated. Which design principle applies, and what does it rule out?

5. In the Security Pillar's fifth design principle, what step comes before applying encryption?

6. Which security design principle most directly argues for AWS Systems Manager Session Manager over SSH keys and a bastion host?

7. Which of the Security Pillar's seven best practice areas has no direct SAA-C03 task statement?

8. An EC2 instance is stopped and started. Data written to its root volume is gone. What explains this?

9. What does the EC2 SLA guarantee?

10. Which S3 storage class is designed for 99.5% availability, and why?

11. A 200 GB object must be stored in Amazon S3. Which statement is correct?

12. How many usable IP addresses are in a /28 subnet in a VPC?

13. VPC A is peered with VPC B, and VPC B is peered with VPC C. How does traffic get from A to C?

14. A regulatory requirement states that users in Germany must be served from eu-central-1. Which routing policy, and which is the trap?

15. You need example.com (the naked domain) to resolve to an Application Load Balancer. What do you create, and what does it cost?

16. Read queries are overwhelming an RDS instance. An engineer enables Multi-AZ. What is the effect on read capacity?

17. A compliance requirement says database backups must be retained for 90 days. Can RDS automated backups meet it?

18. An SQS consumer takes 90 seconds to process a message. The queue's visibility timeout is 30 seconds. What happens?


Answers and explanations

1 — B. "The framework is based on six pillars: Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability." Sustainability was added after much existing material was written, so "five pillars" is a reliable sign your source is out of date.

2 — C. The phrase names Operational Excellence as the scoring criterion. It isn't the same as cheapest (A) or fastest to build (D), and fewer services (B) is not the same as less overhead — a managed service is usually more services and less overhead.

3 — C. "Stop guessing your capacity needs … You can use as much or as little capacity as you need, and scale in and out automatically."

4 — B. "Improve through game days: Test how your architecture and processes perform by regularly scheduling game days to simulate events in production." Writing the runbook is not testing it. A is a different principle about test environments; C and D misattribute.

5 — B. "Classify your data into sensitivity levels and use mechanisms, such as encryption, tokenization, and access control where appropriate." Classification comes first — which is why Macie exists, and why "encrypt everything uniformly" is a weaker answer than protecting according to sensitivity.

6 — C. "Keep people away from data: Use mechanisms and tools to reduce or eliminate the need for direct access or manual processing of data." A is about credentials and identity; both A and C argue against long-lived SSH keys, but C is the principle about eliminating the human access itself, which is what Session Manager does.

7 — C. The seven areas are security foundations, identity and access management, detection, infrastructure protection, data protection, incident response, and application security. Incident response has no directly weighted SAA-C03 task statement — which you only discover by reading the pillar and the exam guide together.

8 — B. "the local instance store only persists during the life of the instance." An EBS root volume persists "independently from the lifetime of the instance", so C is false. A and D are irrelevant.

9 — B. "Our SLA guarantees a Monthly Uptime Percentage of at least 99.99% for Amazon EC2 and Amazon EBS within a Region." Note both the scope (Region, not AZ or instance) and that it covers EBS as well.

10 — C. One Zone-IA is "designed for 99.5% availability", and the reason is the single AZ. That's why it's right for re-creatable data and wrong wherever losing an AZ must not lose the data. Glacier Deep Archive is designed for 99.99% with a 99.9% SLA; Standard-IA and Intelligent-Tiering are 99.9%.

11 — C. Maximum object size is 50 TB; largest single PUT is 5 GB. A confuses the two figures — and note that older material says 5 TB for the maximum, because it has increased over time.

12 — C. "Amazon reserves the first four (4) IP addresses and the last one (1) IP address of every subnet." 16 − 5 = 11. B (14) is the on-premises answer, where you'd lose only the network and broadcast addresses — and it will be in the options for exactly that reason.

13 — C. "No. Transitive peering relationships are not supported." A and B both assume routing through B, which is the thing that isn't supported. D is unrelated — peering has nothing to do with AZs. Ten fully-meshed VPCs would need 45 connections, which is the case for a Transit Gateway.

14 — B. Geolocation routes on where the request originates — "continent, country, or state level" — which is what a regulatory requirement needs. Latency-based is the trap: it would probably route German users to Frankfurt anyway, but "probably" is an optimisation, not a control.

15 — C. An alias record. A CNAME cannot exist at the zone apex (a DNS protocol restriction, not an AWS one), which kills A. B is fragile because an ALB's IPs change. And per the FAQ, "There is no additional charge for queries to Alias records that are mapped to AWS ELB load balancers."

16 — C. "A Multi-AZ standby cannot serve read requests. Multi-AZ deployments are designed to provide enhanced database availability and durability, rather than read scaling benefits." The fix for read load is read replicas — a separate feature solving a separate problem.

17 — C. "you can modify this to any number from 0 … up to 35." So 90 is out of range. Use manual snapshots, or AWS Backup with a longer retention lifecycle. D understates it — 7 days is the default, not the maximum.

18 — B. The visibility timeout "prevents other consuming components from receiving and processing a message" — for its duration only. After 30 seconds the message reappears while the first consumer is still working, so a second consumer picks it up. Raise the timeout above the processing time, and make the consumer idempotent because standard queues are at-least-once anyway.

Scoring

Score Read this as
16–18 Reading list absorbed. Go to SAA1 and the other domain modules.
12–15 Solid. Re-read the lessons behind each miss; the explanations name them.
8–11 You have the concepts but not the numbers. Redo the cheat sheet drills, then the lab.
< 8 Work the module in order and do the lab. The numbers are the point.

Miss patterns:

And then go and close the gaps

This module flagged facts it could not verify from the pages fetched: the Spot interruption notice period, S3 minimum storage durations, Glacier retrieval times, VPC rule quotas and CIDR expansion, the Route 53 availability figure, RDS point-in-time recovery detail, and the SQS visibility timeout maximum, among others.

None of those appear in this quiz, because it would be dishonest to test you on something the module didn't source. They are all examinable. Part 6 of the lab is where you go and get them — and noting which ones you'd have answered wrong from memory is worth more than the marks.