Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Starts this lesson and continues through 34 more to the end of certification prep.
"AWS global infrastructure (for example, Availability Zones, AWS Regions)" is a "Knowledge of" line in Tasks 1.1, 2.2, 3.3 and 4.2 (domain pages, fetched 2026-09-25). Task 2.2 adds "Amazon Route 53" to the same parenthetical, and Task 3.2 asks for "Distributed computing concepts supported by AWS global infrastructure and edge services". No other fundamentals topic is named that often.
And the reason is that almost every resilience, performance and cost question on this exam is secretly a question about which physical boundary something sits inside. This lesson names the boundaries. Lesson 3 says which services live inside which.
PARTITION (aws / aws-us-gov / aws-cn)
└── REGION ── "a separate geographic area" e.g. us-east-2
├── AVAILABILITY ZONE ── "isolated locations" us-east-2a (AZ ID use2-az1)
│ └── one or more discrete data centers
├── LOCAL ZONE ── "an extension of an AWS Region" us-west-2-lax-1
├── WAVELENGTH ZONE ── carrier 5G edge us-east-1-wl1-bos-wlz-1
└── OUTPOST ── AWS capacity at your site
EDGE LOCATIONS / POPs ── CloudFront, Route 53 data plane (not inside a Region)
From AWS Regions and Availability Zones, fetched 2026-09-25:
"Each Region is a separate geographic area."
"Each Region is designed to be isolated from the other Regions. This achieves the greatest possible fault tolerance and stability."
"Most AWS services support regional resources. A regional resource is specific to the Region in which you create it. … You can replicate some types of resources across Regions, but we don't automatically replicate them for you."
⚠️ That last sentence is the exam's favourite Region fact. Nothing crosses a Region boundary unless you configure it to — S3 Replication, DynamoDB global tables, cross-Region snapshots, and so on. A design that "survives a Regional outage" without naming a replication mechanism doesn't.
⚠️ Counts change. Both of these were fetched 2026-09-25 and they do not agree:
| Page | What it says |
|---|---|
| AWS Regions (docs) | "There are currently 34 Regions. The following table lists the Regions provided by an AWS account." |
| AWS Global Infrastructure (marketing) | "The AWS Cloud spans 124 Availability Zones within 39 Geographic Regions", with "7 more Availability Zones and 2 more AWS Regions in the Kingdom of Saudi Arabia, and Chile" announced |
The docs page scopes its count to Regions "provided by an AWS account" and describes GovCloud (US) and China Regions separately (GovCloud US-West and US-East; Beijing and Ningxia). I have not found a page that reconciles 34 with 39, so I won't do the arithmetic for you. Don't memorise either number for the exam — the guide does not test counts, and they will be stale by the time you sit it.
From the same Regions page, verbatim:
This is what lesson 3 calls a partition.
"To use a Region introduced after March 20, 2019, you must enable the Region before you can access it. The earlier Regions are enabled by default, which means that you can begin creating resources immediately."
The page lists 17 enabled by default and 17 disabled by default (fetched 2026-09-25). Examples of each: US East (N. Virginia) and Europe (Ireland) are enabled by default; Africa (Cape Town) and Europe (Milan) are not. You can check any Region from the CLI:
aws account get-region-opt-status --region-name af-south-1
⚠️ Exam relevance: a DR plan that fails over to a Region you have never enabled has an extra, untested
step. That is the same "invisible single point of failure" as the service-quota trap in SAA2 lesson 5.
What the pages I fetched actually say:
So, from AWS's own pages: services available · latency to users · legal/regulatory requirements.
⚠️ Price differs by Region is a commonly-taught fourth factor, and it's real, but none of the Region pages I fetched states it. The only per-location pricing statement I retrieved is the Local Zones page: "AWS resources in Local Zones have different prices than they do in parent AWS Regions." For Region pricing, read the pricing page of the specific service.
⚠️ The exam ordering. When a stem has a data-residency or legal requirement, that is a hard constraint — it eliminates Regions before latency or cost get a vote. Treat it as a filter, not a trade-off.
From AWS Regions and Availability Zones, verbatim:
"Each Region has multiple, independent locations known as Availability Zones. The Availability Zones in a Region are connected through low-latency, high-bandwidth, highly-redundant networking, over dedicated metro fiber."
"Each Availability Zone consists of one or more discrete data centers, each with redundant power, networking, and connectivity, and housed in separate facilities. Because they are physically separate, only a single Availability Zone would be affected in the unlikely event of a fire, tornado, or flooding."
⚠️ An AZ is not "a data center". It is one or more data centers. A distractor that says "each AZ is a single data center" is wrong on the page's own words.
How far apart? The global-infrastructure marketing page I fetched does not state a distance. The figure that does exist is on the S3 Data protection page, fetched 2026-09-25:
"Availability Zones are physically separated by a meaningful distance, many kilometers, from any other Availability Zone, although all are within 100 km (60 miles) of each other."
How many per Region? The AWS Availability Zones
page opens: "Each Region has at least three Availability Zones." ⚠️ But the same documentation set
also says, as a footnote on US West (N. California): "Newer accounts can access two Availability Zones
in US West (N. California)." And under Constrained Availability Zones: "your account might have a
different number of available Availability Zones in a Region than another account does."
So: a Region has at least three AZs; your account may not be able to use all of them. Check with
describe-availability-zones rather than assuming.
The docs' own warning about the single-AZ failure mode:
"if you host all of your EC2 instances in a single Availability Zones and that Availability Zone is affected by a failure, none of your EC2 instances would be available."
From the AZ page, verbatim:
"The code for an Availability Zone is its Region code followed by a letter identifier. For example,
us-east-2a…""For accounts created before November 2025, in our oldest Regions, we independently map Availability Zones to codes for each AWS account. For example, the
us-east-1aAvailability Zone for your account might not be the same physical location as it is in another account. Accounts created starting November 2025, get the same Availability Zones mapped to codes.""Each Availability Zone has an AZ ID, which is the same physical location in every AWS account. … For example,
euw1-az1,euw1-az2, andeuw1-az3are the AZ IDs for the Availability Zones in theeu-west-1Region."
⚠️ Use AZ IDs whenever two accounts must line up — shared subnets, cross-account latency-sensitive
placement, or any "put these in the same AZ as the other team's" requirement. us-east-1a in your
account and us-east-1a in theirs may be different buildings.
aws ec2 describe-availability-zones --filters Name=zone-type,Values=availability-zone \
--query "AvailabilityZones[].{ZoneName:ZoneName,ZoneId:ZoneId}"
From What is AWS Local Zones? and How AWS Local Zones work, fetched 2026-09-25:
"AWS Local Zones places compute, storage, database, and other select AWS resources close to large population and industry centers."
"A Local Zone is an extension of an AWS Region in geographic proximity to your users. Local Zones have their own connections to the internet and support Direct Connect…"
"To use a Local Zone, you must first enable it. Next, you create a subnet in the Local Zone. Finally, you launch resources in the Local Zone subnet."
The three reasons AWS gives, verbatim headings: "Run low-latency applications at the edge" (gaming, live streaming, AR/VR, virtual workstations), "Simplify hybrid cloud migrations", and "Meet stringent data residency requirements" ("state and local data residency requirements in sectors such as healthcare, financial services, iGaming, and government").
Naming, from the EC2 page: "The code for a Local Zone is its Region code followed by an identifier that
indicates its physical location. For example, us-west-2-lax-1 in Los Angeles."
Constraints worth knowing, verbatim from How AWS Local Zones work:
⚠️ Local Zones do not appear by name on the SAA-C03 In-Scope Services page I fetched 2026-09-25, which does list AWS Outposts and AWS Wavelength under Compute. That list says it is "non-exhaustive", so this is not proof Local Zones are out of scope — but weight your study toward the two that are named.
From What is AWS Wavelength?, fetched 2026-09-25:
"Wavelength deploys standard AWS compute and storage services to the edge of communications service providers' (CSP) networks. You can extend a virtual private cloud (VPC) to one or more Wavelength Zones."
"Wavelength Zone — A zone in the carrier location where the Wavelength infrastructure is deployed. Wavelength Zones are associated with an AWS Region. A Wavelength Zone is a logical extension of the Region, and is managed by the control plane in the Region."
"Carrier gateway — A carrier gateway serves two purposes. It allows inbound traffic from a carrier network in a specific location, and allows outbound traffic to the carrier network and internet."
The Regions-and-AZs page frames the use case: "ultra-low latencies to 5G devices and end users." You opt in first (EC2 page: "To use a Wavelength Zone, you must first opt in to the Zone.").
The discriminator: Local Zone = near a city's users. Wavelength = inside a mobile carrier's 5G network. If the stem says "5G" or "mobile devices on a carrier network", it's Wavelength.
From the EC2 Regions and Zones page, fetched 2026-09-25:
"AWS Outposts is a fully managed service that extends AWS infrastructure, services, APIs, and tools to customer premises."
"An Outpost is a pool of AWS compute and storage capacity deployed at a customer site. AWS operates, monitors, and manages this capacity as part of an AWS Region."
Outposts is the example the exam guide gives for "Hybrid compute options" (Task 4.2).
From What is Amazon CloudFront?, fetched 2026-09-25:
"CloudFront delivers your content through a worldwide network of data centers called edge locations. When a user requests content that you're serving with CloudFront, the request is routed to the edge location that provides the lowest latency (time delay)…"
"CloudFront sends your distribution's configuration (but not your content) to all of its edge locations or points of presence (POPs)— collections of servers in geographically-dispersed data centers where CloudFront caches copies of your files."
Count, from the global infrastructure page fetched 2026-09-25: *"CloudFront POPs and 15 Regional edge caches: 750+"*. Same caveat as Region counts — don't memorise it.
⚠️ Edge locations are not Regions and not AZs. You cannot launch an EC2 instance in one. They host the data planes of edge services — CloudFront, and (lesson 3) Route 53's public DNS — which is why those services behave "globally".
From How Amazon VPC works, fetched 2026-09-25:
"AWS Regions are connected to multiple Internet Service Providers (ISPs) as well as to a private global network backbone, which provides improved network performance for cross-Region traffic…"
"Packets that originate from the AWS network with a destination on the AWS network stay on the AWS global network, except traffic to or from AWS China Regions and the AWS European Sovereign Cloud Region. This is true whether the destination is a private IP address or a public IP address."
That second sentence surprises people: two EC2 instances talking over public IPs still stay on the AWS backbone.
us-east-1a in your account and us-east-1a in a partner's account. Same building?use1-az1), which are "the same
physical location in every AWS account".describe-availability-zones in two accounts and show that the
letter-to-ID mapping differs (it will only differ for older accounts in older Regions — say so before
you run it, in case it doesn't).