AWS / Professional / SAP-C02
Solutions Architect Professional
Combine organisational constraints, migration sequencing and cross-service trade-offs. Start with the professional decision chapters, then revisit foundations as needed.
THE REVISION PATH
Your topics, in order.
Read. Recall. Explain the alternative.
Getting Started with AWS
Choose the geography first, separate failure domains next, and bring eligible content closer to users at the edge.
IAM & AWS CLI
Identify who is calling, how they authenticated, and which policies authorize the exact request.
EC2 Fundamentals
Match the machine to the bottleneck, the purchase model to the commitment, and access to a temporary role.
EC2 SAA Level
Preserve the right identity, separate the right failure domains, and distinguish resuming a machine from recovering an application.
EC2 Instance Storage
Choose block, file or local scratch first, then check its failure boundary, performance and recovery behavior.
ELB & Auto Scaling
A load balancer chooses a destination; an Auto Scaling group maintains capacity; application state must survive either decision.
RDS, Aurora & ElastiCache
Replicas add read capacity, failover preserves service, backups recover history, proxies manage connections, and caches avoid repeated work.
Route 53
DNS chooses an answer that clients may cache; it does not inspect or balance every application request.
Classic Solutions Architectures
Make compute replaceable by putting necessary state in services with deliberately chosen durability, access and failure behavior.
S3 Introduction
A key names an object, versioning preserves history, and replication places eligible copies elsewhere.
Advanced S3
Measure access, choose an economical storage class, automate aging, and make event consumers tolerate retries.
S3 security
Encryption protects stored bytes, policies authorize callers, and browser rules do neither job for you.
CloudFront and Global Accelerator
CloudFront caches HTTP content, Global Accelerator routes network connections, and replication creates durable regional copies.
Storage extras
Choose the application's storage protocol first, then decide whether you need persistent access, hybrid access or data movement.
SQS, SNS, Kinesis and Amazon MQ
Queue work for competing workers, fan out events to independent consumers, and retain streams when replay matters.
Containers on AWS
Separate the container image, application task, compute capacity and permissions before choosing an orchestrator.
Serverless services
Separate execution limits, data access patterns, API authorization and workflow state instead of treating serverless as unlimited capacity.
Serverless solution architectures
Authenticate the caller, authorize the operation, keep durable state outside functions, and cache only responses safe to share.
Choosing an AWS database
Start with the required queries and consistency, then choose the data model, resilience and operating model.
Data and analytics
Separate ingestion, storage, metadata, permissions, computation and visualization so each requirement has a clear owner.
Machine Learning
Identify the input and the required output before choosing an AI service.
Monitoring & Audit
Metrics show symptoms, logs explain events, traces follow requests, and audit records identify changes.
IAM Advanced
First identify the caller, then find its grants, its permission ceilings and every applicable explicit deny.
Security & Encryption
Protect the connection, the stored data, the permission to use it and the evidence of misuse separately.
Networking: VPC
A working connection needs the right address, a forward route, permission and a return path.
Disaster Recovery & Migrations
RPO limits how much data may be lost; RTO limits how long useful service may be unavailable.
More Solution Architectures
Choose the delivery, state and failure behavior first, then select services that preserve those decisions.
Other Services
Separate deployment, administration, cost evidence and application delivery before choosing a tool.
Whitepapers & Architectures
Start with the workload's requirements, then explain what the design protects, what it costs and how you know it works.
Organisational Architecture and Guardrails
Design the account, identity, network and evidence boundaries before centralising services.
Professional Architecture Decisions and Migration Sequencing
Reject any option that breaks a hard constraint before comparing convenience or price.
Hybrid Networks, Shared Inspection and DNS Boundaries
Trace both directions through every routing and trust boundary.
Cross-Account Authorization and Evidence Architecture
Follow the principal, the policy ceiling, the resource and the key.
Regional Recovery, Write Ownership and Failback
Traffic can switch faster than data can become safe.
Migration Waves, Database Cutover and Strangler Patterns
Discover together, move deliberately, reconcile before retirement.
Performance Evidence, Cost Allocation and Commitment Risk
Measure the bottleneck; price the whole path; commit only to the baseline.
How this guide is organised
Original revision notes arranged around practical decisions. The linked official objectives define the mapped scope; primary documentation supports the explanations. Read each topic, answer without looking, then explain why another option would fail.
- Official exam guide ↗ Scope authority
- Stephane Maarek: Professional public course outline ↗ Sequence and topic reference; original notes
Revision material supports preparation; it does not guarantee every possible exam question. Check the exam version and official objectives before booking.