AWS Certified Solutions Architect – ProfessionalStudy guide
The professional certification for designing, optimizing, and migrating complex, large-scale AWS solutions (SAP-C02).
About AWS Certified Solutions Architect – Professional (SAP-C02)
AWS Certified Solutions Architect – Professional (SAP-C02) is a Professional / Expert-level certification from AWS. This page organizes the exam scope into a 4-chapter, 16-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Design Solutions for Organizational Complexity~26%
- Design for New Solutions~29%
- Continuous Improvement for Existing Solutions~25%
- Accelerate Workload Migration and Modernization~20%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://aws.amazon.com/certification/certified-solutions-architect-professional/
1Design Solutions for Organizational Complexity
- 1.1Multi-Account Strategy and Governance
Understand the foundation for large organizations: AWS Organizations, Organizational Units (OUs), Service Control Policies (SCPs), consolidated billing, and Control Tower. Operate many accounts securely and with governance.
- 1.2Cross-Account Access and Identity Federation
Understand secure access across accounts—cross-account IAM roles, IAM Identity Center (SSO), SAML/OIDC federation, and Resource Access Manager (RAM). Design org-wide access with least privilege.
- 1.3Multi-Account and Hybrid Networking
Understand large-scale connectivity—Transit Gateway, VPC peering, PrivateLink, Direct Connect, Site-to-Site VPN, and Route 53 Resolver. Interconnect many VPCs and on-premises efficiently.
- 1.4Governance, Security, and End-User Services
A catalog of supporting services for organizational complexity—certificates/keys (ACM, CloudHSM), identity and directories (Cognito, Directory Service), network defense (Firewall Manager, Network Firewall), audit/compliance (Artifact, Audit Manager), cost/governance tooling (Cost and Usage Report, License Manager, Service Catalog, Well-Architected Tool, Health Dashboard, Management Console, CLI), and virtual desktops (WorkSpaces, AppStream 2.0)—organized by definition, role, and when to choose.
2Design for New Solutions
- 2.1High Availability and Disaster Recovery
Understand designs for availability and resilience—Multi-AZ/Multi-Region, RTO/RPO, the four DR strategies (backup & restore/pilot light/warm standby/multi-site), and Route 53 failover.
- 2.2Scalable, Loosely Coupled Architectures
Understand elasticity and decoupling—Auto Scaling/ELB, decoupling with SQS/SNS/EventBridge, serverless (Lambda/API Gateway/Step Functions), and caching. Handle demand swings and contain failures.
- 2.3Choosing Data Stores and Encryption
Understand the right data store and protection—choosing RDS/Aurora/DynamoDB/S3 storage classes, encryption with KMS, Secrets Manager, and encryption at rest/in transit. Select secure stores that fit requirements.
- 2.4Compute, Container, Database, Storage, and Network Services
Building blocks for new solutions—simple/PaaS compute (App Runner, Elastic Beanstalk, Lightsail), hybrid/edge (Outposts, Wavelength, ECS Anywhere, EKS Anywhere, EKS Distro), purpose-built databases (Aurora Serverless, DocumentDB, Keyspaces, Neptune, Timestream), DR/archive/hybrid storage (Elastic Disaster Recovery, S3 Glacier, Storage Gateway), and global delivery (Global Accelerator)—by definition, role, and when to choose.
- 2.5Analytics, ML, IoT, Media, and Integration Services
Building blocks for data-driven and intelligent features—analytics (Athena, EMR, OpenSearch Service, Kinesis Data Streams, Data Firehose, MSK, Managed Service for Apache Flink, Lake Formation, QuickSight, Data Exchange, AppFlow), machine learning (SageMaker AI, Rekognition, Comprehend, Textract, Transcribe, Translate, Polly, Kendra, Personalize, Fraud Detector), IoT (IoT Core, Greengrass, SiteWise, etc.), media (Kinesis Video Streams, Elastic Transcoder), application integration (AppSync, MQ), and blockchain/email (Managed Blockchain, SES).
3Continuous Improvement for Existing Solutions
- 3.1Operational Observability and Automation
Understand observability and operations for improving existing systems—CloudWatch (metrics/logs/alarms), X-Ray (distributed tracing), CloudTrail (API auditing), Systems Manager, and automation. Detect issues early and automate operations.
- 3.2Performance and Cost Optimization
Understand optimizing existing workloads—right-sizing, purchase options (On-Demand/RI/Savings Plans/Spot), Compute Optimizer/Cost Explorer/Budgets/Trusted Advisor, and CloudFront/caching. Keep performance while cutting waste.
- 3.3Improving Reliability and Security Posture
Understand hardening existing systems—Well-Architected, fault isolation, GuardDuty/Security Hub/Config, WAF/Shield, and automated remediation. Continuously raise threat detection and compliance.
- 3.4Developer Tools and Operations Management Services
Supporting services for improvement and automated delivery—CI/CD pipelines (CodePipeline, CodeBuild, CodeDeploy, CodeArtifact, CodeGuru), open-source-compatible observability (Managed Grafana, Managed Service for Prometheus), standardized templates (Proton), and frontend/testing (Amplify, Device Farm)—by definition, role, and when to choose.
4Accelerate Workload Migration and Modernization
- 4.1Choosing a Migration Strategy (The 7 Rs)
Understand migration approaches—the 7 Rs (rehost/replatform/refactor/repurchase/retire/retain/relocate) and assessment via Migration Hub/Application Discovery Service. Pick the best path per workload.
- 4.2Tools to Execute Migrations
Understand migration tools—Application Migration Service (MGN), DMS/SCT (DB migration), DataSync (online bulk transfer), the Snow Family (offline bulk), and Transfer Family. Choose by data type and connectivity.
- 4.3Modernizing on the Cloud
Understand post-migration modernization—containers (ECS/EKS/Fargate), serverless, decomposing into microservices, and incremental migration via the strangler fig pattern. Improve agility, scale, and cost-efficiency.

