AWS Training
Modules Listen All tracks

← Exam Strategy and Question Mechanics

SAA9 Drills — the one word that changes the answer

How to use this file. Each drill is a pair of near-identical answer options and a one-line requirement. Cover the right-hand explanation. Say out loud which word differs, what that word commits you to, and which option survives. Then check.

This trains lesson 2's skill in isolation: read only the difference.

⚠️ The option pairs are original, written for this course. They're not from the AWS Official Practice Question Set. Every fact used to decide a pair is quoted from the page in sources:, fetched 2026-09-25.


Databases

D1. Requirement: offload read-heavy reporting from the primary.

Answer

Changed words: Multi-AZ / read replica. Y survives. "a Multi-AZ standby cannot serve read requests. Multi-AZ deployments are designed to provide enhanced database availability and durability, rather than read scaling benefits" (RDS FAQ). X is impossible, not just weaker.

D2. Requirement: no committed transaction may be lost if the primary's AZ fails.

Answer

Changed word: synchronously / asynchronously. X survives. Multi-AZ "uses synchronous replication between primary and standby". Read replicas use "native, asynchronous replication" (RDS FAQ). Asynchronous means a replica can lag the primary.

D3. Requirement: cross-Region DR where the secondary must take writes in under a minute.

Answer

Changed words: RDS read replica / Aurora global database. Y survives. Aurora global database can "promote one of the secondary regions to take read/write responsibilities in less than one minute". For DB instances other than Aurora, "the process takes a few minutes to complete and rebooting is part of the process" (DR options).

Messaging and workflow

M1. Requirement: three consumers must each receive every message, and one is offline for hours.

Answer

Changed words: endpoint / SQS queue per consumer. Y survives. Fanout to SQS queues is AWS's named pattern ("replicated and pushed to multiple endpoints, such as … Amazon SQS queues", SNS), and the queue holds messages for a retention period configurable "from 1 minute to 14 days" (SQS FAQ). X has no buffer.

M2. Requirement: a payment must never be processed twice, and the consumer cannot be changed.

Answer

Changed word: standard / FIFO. Y survives. "Standard queues provide at-least-once delivery… FIFO queues provide exactly-once processing." With standard queues "you must design your applications to be idempotent" (SQS FAQ), and the stem forbids changing the consumer.

M3. Requirement: a workflow waits for a human approval that may take two days.

Answer

Changed word: Express / Standard. Y survives. "Express Workflows only support Request Response integrations" and "can run for up to five minutes". Standard workflows "can run for up to one year" (Step Functions). X fails twice.

M4. Requirement: orchestrate a very high event rate of short IoT processing steps, cost-sensitive.

Answer

Changed word: Standard / Express. Y survives. "Express workflows are ideal for high-event-rate workloads, such as streaming data processing and IoT data ingestion" (Step Functions). It's the mirror image of M3. The same pair flips depending on the requirement.

Compute and containers

C1. Requirement: a job that runs about 40 minutes, no servers to manage.

Answer

Changed words: Lambda / ECS on Fargate. Y survives. Lambda: "Up to 15 minutes per invocation" (Lambda). Fargate "removes the need to choose server types" (Fargate).

C2. Requirement: register a Fargate-backed ECS service with a load balancer target group.

Answer

Changed word: instance / ip. Y survives. "you must choose ip as the target type, not instance. This is because tasks that use the awsvpc network mode are associated with an elastic network interface, not an Amazon EC2 instance" (Fargate).

Networking and routing

N1. Requirement: active-passive DNS failover to a standby site.

Answer

Changed word: weighted / failover. Y survives. "You configure active-active failover using any routing policy (or combination of routing policies) other than failover, and you configure active-passive failover using the failover routing policy" (Route 53).

N2. Requirement: a partner must allowlist fixed IP addresses for your load balancer.

Answer

Changed words: fixed Elastic IP / resolved DNS name. X survives. NLB: "you can optionally associate one Elastic IP address per subnet" and "Support for static IP addresses for the load balancer" (NLB). A DNS name doesn't give the partner a fixed address to allowlist.

Storage and data protection

S1. Requirement: no user, including the root user, may delete records during the retention period.

Answer

Changed word: governance / compliance. Y survives. Compliance: "can't be overwritten or deleted by any user, including the root user in your AWS account." Governance: "users can't overwrite or delete an object version or alter its lock settings unless they have special permissions" (Object Lock).

S2. Requirement: protect against an engineer accidentally deleting data.

Answer

Changed words: replication alone / plus point-in-time backups. Y survives. "Continuous replication of data has the advantage of being the shortest time (near zero) to back up your data, but may not protect against disaster events such as data corruption or malicious attack (such as unauthorized data deletion) as well as point-in-time backups" (DR options).

Disaster recovery

R1. Requirement: the DR Region must serve requests immediately at reduced capacity.

Answer

Changed words: switched off / running. Y survives. "pilot light cannot process requests without additional action taken first, whereas warm standby can handle traffic (at reduced capacity levels) immediately" (DR options).

R2. Requirement: the recovery Region must survive a failover even if the control plane is degraded.

Answer

Changed words: rely on Auto Scaling / full capacity in advance. Y survives. "Because Auto Scaling is a control plane activity, taking a dependency on it will lower the resiliency of your overall recovery strategy. It is a trade-off. You can choose to provision sufficient capacity such that the recovery Region can handle the full production load" (DR options). ⚠️ If the stem instead says "most cost-effective" with no control-plane requirement, X can be the answer. The requirement decides.

Reading the question itself

Q1. You see "Amazon EMR" in an option and don't recognise the expansion.

Answer

Y. "Not every abbreviation is fully spelled out on the exam or available in the Help feature. The official full name for some AWS services includes an abbreviation that is never expanded (for example, Amazon API Gateway, Amazon EMR)" (service mentions).


Build your own — Method

The fastest way to lock in a pair is to write it. For every fact you learn in SAA1–SAA4:

  1. Write the correct option in one sentence.
  2. Change one word to its nearest sibling: feature ↔ feature, mode ↔ mode, sync ↔ async, policy ↔ policy, or a number up or down.
  3. Write a one-line requirement that the change breaks.
  4. Quote the documentation sentence that decides it.

If you can't find the quote in step 4, you don't know the fact well enough yet. That's worth knowing before the exam, not during it.