Study AWS Solutions Architect Professional section notes, then jump straight into the guided course or related practice questions without losing your place.
Looking for your active Pro access before showing Course Notes. This usually takes just a moment.
Course Notes preview
Unlock Pro for the full per-exam reference guide.
Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.
Includes full Course Mode and Course Notes.
Section 1Foundations: ComplexityPreview
More in this section
2 more summary sections in Pro version
8 more key points in Pro version
4 more common mistakes in Pro version
4 more exam tips in Pro version
32 more related questions in Pro version
Summary
Multi-account architecture is about separating workloads, teams, and risk while still applying consistent governance. Architects must balance isolation, delegated administration, shared services, auditability, and billing visibility across an organization.
Key Points
**AWS Organizations:** A service for centrally managing multiple AWS accounts in an organization. Accounts can be grouped into OUs for governance and billing, and policies attached at the root, OU, or account level affect member accounts through inheritance.
Common Mistakes
**AWS Organizations vs. IAM:** IAM grants and controls access within account and resource boundaries; AWS Organizations manages account relationships, billing, and organization-level policies across accounts.
Exam Tips
Identify the governance scope first: single account, OU, entire organization, or selected services. The correct control usually follows that boundary.
Section 2Resilience & DRPreview
More in this section
2 more summary sections in Pro version
8 more key points in Pro version
5 more common mistakes in Pro version
5 more exam tips in Pro version
31 more related questions in Pro version
Summary
Resilience design separates steady-state high availability from disaster recovery. Architects map failure domains to RTO and RPO targets, then choose replication, failover, queueing, backup, and immutability patterns that fit the workload.
Key Points
**Reliability Architecture:** Designs workloads around failure isolation, automated recovery, validated backups, dependency limits, and tested procedures that satisfy stated RTO and RPO requirements.
Common Mistakes
**Aurora Global Database vs. DynamoDB Global Tables:** Aurora uses one writer Region with secondary read Regions and planned or unplanned promotion paths; DynamoDB global tables support multi-Region active-active access with asynchronous replication.
Exam Tips
Tie every resilience answer to the stated RTO, RPO, failure domain, and tolerance for data loss or manual action.
Section 3Security PrinciplesPreview
More in this section
2 more summary sections in Pro version
10 more key points in Pro version
4 more common mistakes in Pro version
4 more exam tips in Pro version
18 more related questions in Pro version
Summary
Security architecture combines identity, network, data-protection, logging, and workload controls so one missed control does not expose the whole environment. The design must match the threat, trust boundary, and operational model.
Key Points
**Defense in Depth:** Layers preventive, detective, and responsive controls across identity, network, application, and data planes so failure of one control does not create unrestricted access.
Common Mistakes
**Security Groups vs. Network ACLs:** Security groups are stateful resource-level controls with allow rules only. NACLs are stateless subnet-level controls with ordered allow and deny rules.
Exam Tips
Start with the threat model: web exploit, credential exposure, data access, network path, or cross-account trust. Then choose controls at the matching layer.
Section 4Network IntegrationPreview
More in this section
2 more summary sections in Pro version
9 more key points in Pro version
5 more common mistakes in Pro version
5 more exam tips in Pro version
17 more related questions in Pro version
Summary
Network integration connects VPCs, accounts, Regions, and on-premises environments while preserving routing control, availability, security boundaries, and operational visibility.
Key Points
**Transit Gateway:** A managed regional hub for connecting VPCs, VPNs, and Direct Connect gateway attachments. It reduces point-to-point complexity, but route-table associations and propagations control which attachments can communicate.
Common Mistakes
**Transit Gateway vs. VPC Peering:** Transit Gateway supports hub-and-spoke and transitive routing at scale. VPC peering is point-to-point, non-transitive, and can be simpler or cheaper for a small number of connections.
Exam Tips
Choose Transit Gateway when central routing, segmentation, or many connections are explicit requirements; do not choose it solely because more VPCs are mentioned.
Section 5Modernization StrategiesPreview
More in this section
2 more summary sections in Pro version
9 more key points in Pro version
5 more common mistakes in Pro version
4 more exam tips in Pro version
17 more related questions in Pro version
Summary
Migration and modernization design begins with business drivers, dependencies, downtime tolerance, data gravity, security constraints, and target-state operations. The migration strategy should fit the workload, not the other way around.
Key Points
**Migration Planning:** Maps dependencies, groups migration waves, defines cutover and rollback, and validates target-state operations. AWS Migration Hub provides visibility and coordination across migration tools.
Common Mistakes
**DMS vs. DataSync:** DMS migrates and replicates database data. DataSync transfers file and object data between storage locations.
Exam Tips
Start with the migration strategy: rehost, replatform, refactor, relocate, repurchase, retain, or retire. The service choice should support that strategy.
Section 6Cost ManagementPreview
More in this section
2 more summary sections in Pro version
9 more key points in Pro version
4 more common mistakes in Pro version
4 more exam tips in Pro version
17 more related questions in Pro version
Summary
Cost architecture optimizes spend while preserving required performance, reliability, security, and operations. The design starts with workload patterns and then applies purchasing, storage, scaling, scheduling, and visibility controls.
Key Points
**Cost Optimization Principles:** Analyze demand, utilization, access patterns, availability needs, and operational constraints before changing architecture. Right-size resources, use elasticity, choose suitable storage tiers, and apply commitments only to stable usage.
Common Mistakes
**Savings Plans vs. Reserved Instances:** Savings Plans discount eligible compute usage based on hourly spend commitments. Reserved Instances are more service and configuration specific, with flexibility depending on RI type and scope.
Exam Tips
Classify the spend driver before choosing a tool: compute commitment, storage retention, idle resources, unknown access, or lack of visibility.
Search catalog
Find a practice exam
Flexible search understands AI-901, ai901, ai 901, 901, ai, network plus, and saa c03.