AWS Training
Modules Listen All tracks

← All modules

SAA1 — Design Secure Architectures

Why this module exists

Domain 1 is the largest domain on the SAA-C03 exam — 30% of scored content, more than any other — and it is the domain people revise worst. The usual approach is to memorise a list of services: KMS encrypts, WAF filters, Cognito signs people in, Shield stops DDoS. Then the exam asks which of four plausible architectures meets a compliance requirement at the lowest operational overhead, and the service list doesn't help, because all four options contain real services used correctly.

What the exam is actually testing is narrower and more mechanical than the syllabus makes it look. Almost every Domain 1 question resolves to one of three decisions:

  1. Who is allowed? — and therefore how policies combine to produce an allow or a deny.
  2. What path does the traffic take? — and therefore which control sits on that path.
  3. Who holds the key, and can they be stopped? — and therefore whether the control survives a determined insider or an auditor.

This module is built around those three, in that order, because that is also the order in which they appear in the exam guide's task statements.

The one idea to hold onto

Permissions are an intersection of ceilings and a union of grants, and an explicit deny beats everything.

   Is there an explicit Deny anywhere?  ──yes──▶  DENIED. Stop. Nothing overrides this.
                 │ no
                 ▼
   ┌─────────────────────────── CEILINGS (all must allow) ───────────────────────────┐
   │   SCP / RCP        ∩      Permissions boundary      ∩      Session policy       │
   └──────────────────────────────────┬─────────────────────────────────────────────-┘
                                      │  ∩
                 ┌────────────────────▼────────────────────┐
                 │   GRANTS (any one is enough)            │
                 │   identity-based policy  ∪  resource-based policy
                 └────────────────────┬────────────────────┘
                                      ▼
                                  ALLOWED

Ceilings never grant anything. Grants never raise a ceiling. AWS says it directly about SCPs: "SCPs do not grant permissions to the IAM users and IAM roles in your organization. No permissions are granted by an SCP." (SCPs, verified 2026-09-21)

Get that diagram onto paper from memory and a large fraction of Domain 1 becomes arithmetic. Most wrong answers in the exam are wrong because they put a grant where a ceiling is needed, or expect a ceiling to grant.

What you'll be able to do

  1. Work out, for any combination of identity policy, resource policy, SCP, permissions boundary and session policy, whether a request is allowed — and say which policy decided it.
  2. Choose between a resource policy and an identity policy for cross-account access, and explain why cross-account needs both sides to agree.
  3. Design a multi-account guardrail with SCPs, and name the four things an SCP cannot restrict.
  4. Place security groups, network ACLs, NAT gateways and VPC endpoints correctly, and say which of them is stateful and which evaluates rules in order.
  5. Pick between Cognito user pools and identity pools without hesitating, and say what each returns.
  6. Choose a KMS key type on cost and control grounds, and explain why a key policy is not optional.
  7. Choose between S3 Object Lock governance mode, compliance mode and a legal hold for a stated retention requirement — including the one that not even the root user can undo.

Lessons

# Lesson Task statement Read Listen
1 Policy evaluation — the only thing you must actually know 1.1 26 min 10 min
2 Multi-account guardrails 1.1 28 min 10 min
3 Network security controls and where they sit 1.2 30 min 12 min
4 Application protection, identity and secrets 1.2 28 min 12 min
5 Encryption and key management 1.3 32 min 13 min
6 Data protection, retention and recovery 1.3 31 min 15 min

Then: Cheat sheet · Lab · Quiz · Interview

Where this sits in the exam

From the SAA-C03 exam guide, Version 1.1 (verified 2026-09-21):

Domain Weight
1 — Design Secure Architectures 30%
2 — Design Resilient Architectures 26%
3 — Design High-Performing Architectures 24%
4 — Design Cost-Optimized Architectures 20%

Domain 1 has three task statements, and this module maps to all three:

Exam mechanics, same source: 65 questions, of which 50 are scored and 15 are unscored and unmarked; 130 minutes; scaled score 100–1,000 with a minimum passing score of 720; and a compensatory scoring model — "you do not need to achieve a passing score in each section. You need to pass only the overall exam."

What this module is not

This is not a reproduction of AWS Skill Builder's exam prep content, and the quiz in it is not the AWS Official Practice Question Set. The questions here are written from the task statements and the service documentation; they are exam-styled, not calibrated against real exam items. Treat a good score here as evidence that you understand Domain 1, not as a predicted exam score. Buy the official practice question set separately if you want calibration.

Facts verified 2026-09-21 against the pages cited in each lesson. Quotas and pricing move — re-verify anything you are about to rely on.

Keeps playing into the following modules — 279 min from here to the end of certification prep.