Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Domain 1 is the largest domain on the SAA-C03 exam — 30% of scored content, more than any other — and it is the domain people revise worst. The usual approach is to memorise a list of services: KMS encrypts, WAF filters, Cognito signs people in, Shield stops DDoS. Then the exam asks which of four plausible architectures meets a compliance requirement at the lowest operational overhead, and the service list doesn't help, because all four options contain real services used correctly.
What the exam is actually testing is narrower and more mechanical than the syllabus makes it look. Almost every Domain 1 question resolves to one of three decisions:
This module is built around those three, in that order, because that is also the order in which they appear in the exam guide's task statements.
Permissions are an intersection of ceilings and a union of grants, and an explicit deny beats everything.
Is there an explicit Deny anywhere? ──yes──▶ DENIED. Stop. Nothing overrides this.
│ no
▼
┌─────────────────────────── CEILINGS (all must allow) ───────────────────────────┐
│ SCP / RCP ∩ Permissions boundary ∩ Session policy │
└──────────────────────────────────┬─────────────────────────────────────────────-┘
│ ∩
┌────────────────────▼────────────────────┐
│ GRANTS (any one is enough) │
│ identity-based policy ∪ resource-based policy
└────────────────────┬────────────────────┘
▼
ALLOWED
Ceilings never grant anything. Grants never raise a ceiling. AWS says it directly about SCPs: "SCPs do not grant permissions to the IAM users and IAM roles in your organization. No permissions are granted by an SCP." (SCPs, verified 2026-09-21)
Get that diagram onto paper from memory and a large fraction of Domain 1 becomes arithmetic. Most wrong answers in the exam are wrong because they put a grant where a ceiling is needed, or expect a ceiling to grant.
| # | Lesson | Task statement | Read | Listen |
|---|---|---|---|---|
| 1 | Policy evaluation — the only thing you must actually know | 1.1 | 26 min | 10 min |
| 2 | Multi-account guardrails | 1.1 | 28 min | 10 min |
| 3 | Network security controls and where they sit | 1.2 | 30 min | 12 min |
| 4 | Application protection, identity and secrets | 1.2 | 28 min | 12 min |
| 5 | Encryption and key management | 1.3 | 32 min | 13 min |
| 6 | Data protection, retention and recovery | 1.3 | 31 min | 15 min |
Then: Cheat sheet · Lab · Quiz · Interview
From the SAA-C03 exam guide, Version 1.1 (verified 2026-09-21):
| Domain | Weight |
|---|---|
| 1 — Design Secure Architectures | 30% |
| 2 — Design Resilient Architectures | 26% |
| 3 — Design High-Performing Architectures | 24% |
| 4 — Design Cost-Optimized Architectures | 20% |
Domain 1 has three task statements, and this module maps to all three:
Exam mechanics, same source: 65 questions, of which 50 are scored and 15 are unscored and unmarked; 130 minutes; scaled score 100–1,000 with a minimum passing score of 720; and a compensatory scoring model — "you do not need to achieve a passing score in each section. You need to pass only the overall exam."
This is not a reproduction of AWS Skill Builder's exam prep content, and the quiz in it is not the AWS Official Practice Question Set. The questions here are written from the task statements and the service documentation; they are exam-styled, not calibrated against real exam items. Treat a good score here as evidence that you understand Domain 1, not as a predicted exam score. Buy the official practice question set separately if you want calibration.
Facts verified 2026-09-21 against the pages cited in each lesson. Quotas and pricing move — re-verify anything you are about to rely on.
Keeps playing into the following modules — 279 min from here to the end of certification prep.