Solution Architect Associate Checklist
(this document is a work-in-progress, it is not complete, so you should visit this document from time to time to see if anything has changed)
The AWS Solution Architect Associate exam content contains these sections:
Domain 1: Design Secure Architectures (30%)
1.1: Design secure access to AWS resources.
- Cross account resource access in IAM
- Identity providers and federation
- What is IAM Identity Center
- AWS Global Infrastructure
- AWS security best practices
- Shared Responsibility Model
- Skills:
- Applying AWS security best practices to IAM users and root users (for example, multi-factor authentication [MFA]):
- Designing a flexible authorization model that includes IAM users, groups, roles, and policies
- Designing a role-based access control strategy (for example, AWS Security Token Service [AWS STS], role switching, cross-account access)
- In identities: IAM roles
- Designing a security strategy for multiple AWS accounts (for example, AWS Control Tower, service control policies [SCPs])
- Determining the appropriate use of resource policies for AWS services
- Determining when to federate a directory service with IAM roles
1.2: Design secure workloads and applications
1.3: Determine appropriate data security controls
Domain 2: Design Resilient Architectures (26%)
- 2.1: Design scalable and loosely coupled architectures
- 2.2: Design highly available and/or fault-tolerant architectures
Domain 3: Design High-Performing Architectures (24%)
- 3.1: Determine high-performing and/or scalable storage solutions
- 3.2: Design high-performing and elastic compute solutions
- 3.3: Determine high-performing database solutions.
- 3.4: Determine high-performing and/or scalable network
- 3.5: Determine high-performing data ingestion and transformation solutions
Domain 4: Design Cost-Optimized Architectures (20%)
- 4.1: Design cost-optimized storage solutions.
- 4.2: Design cost-optimized compute solutions.
- 4.3: Design cost-optimized database solutions.
- 4.4: Design cost-optimized network architectures.