Study guide · SAA-C03

Design Secure Architectures

30% of the exam by AWS's own published weighting.

What it covers

The official exam guide breaks this domain into 3 objectives:

  • Design secure access to AWS resources
  • Design secure workloads and applications
  • Determine appropriate data security controls

Practice this domain

A drill pulls every published question in this domain and grades each one as you go. Flashcards skip the grading entirely — read the stem, flip when you're ready, move on.

A sample question

A compliance rule requires that log data stored in Amazon CloudWatch Logs be encrypted with a key the company manages. What should the team do?

  • AAssociate a customer managed KMS key with the CloudWatch log group.
  • BStore the logs in an unencrypted S3 bucket instead of CloudWatch.
  • CRely on TLS in transit as sufficient to meet the at-rest requirement.
  • DDisable log retention so that no data is stored long enough to matter.

CloudWatch Logs can encrypt a log group at rest with a customer managed KMS key, meeting the requirement. Moving to an unencrypted bucket removes encryption, TLS covers transit not rest, and disabling retention destroys the logs rather than protecting them.

A team needs to capture metadata about accepted and rejected IP traffic to and from network interfaces in a VPC for troubleshooting and forensics. What should they enable?

  • AAWS CloudTrail data events captured for the VPC's resources and APIs.
  • BAWS Config recording enabled for the VPC's subnets and interfaces.
  • CAmazon GuardDuty DNS logging turned on for the VPC's outbound queries.
  • DVPC Flow Logs delivered to CloudWatch Logs or Amazon S3 for analysis.

VPC Flow Logs capture metadata about accepted and rejected traffic on network interfaces and can be sent to CloudWatch Logs or S3. CloudTrail records API calls, Config records configuration, and GuardDuty DNS logging covers only DNS queries.

Unofficial study aid. Not affiliated with, endorsed by, or sponsored by Amazon Web Services.