The 3 AWS exam domains most people underestimate (and how to fix it)
After helping dozens of engineers prep for their AWS certs, I see the same pattern over and over.
People spend 60% of their study time on compute and storage — EC2, S3, Lambda. Makes sense, those feel "core." But here's the thing: AWS consistently hammers three domains that most self-studiers barely touch.
1. Security & Compliance (~25-30% of questions)
IAM policies, KMS, Security Groups vs NACLs, CloudTrail vs Config. Most people think they know IAM until they see a question with three policies that all look correct. The trick is understanding policy evaluation logic — explicit deny > explicit allow > implicit deny. Practice reading JSON policies until it's second nature.
2. High Availability & Fault Tolerance (~20%)
Multi-AZ vs Multi-Region, Route 53 failover, Auto Scaling lifecycle hooks, RDS read replicas vs Multi-AZ. AWS loves scenario questions here: "Your application needs 99.99% uptime..." — and the answer hinges on whether you know the difference between AZ-level and Region-level redundancy.
3. Cost Optimization (~15%)
Reserved Instances vs Savings Plans vs Spot, S3 storage class transitions, right-sizing recommendations, Cost Explorer vs Budgets vs Cost Anomaly Detection. This one catches experienced engineers off guard because they've never had to think about billing in their day job.
What to do about it:
Map your study time to actual exam weight. AWS publishes the domain breakdown in every exam guide — use it. If Security is 30% of the exam, it should be 30% of your prep.
Then take practice exams early and often. Not to "test" yourself, but to calibrate where you're actually weak vs where you think you're weak.
I built CertStack around this exact approach. Every module is weighted by exam importance, not by what feels important. If you're prepping for SA Associate, Developer Associate, or SysOps Admin — the course, practice exams, and weekly live sessions are all here.
