Courseiva

SAA-C03 Design Cost-Optimized Architectures Practice Question

An organization wants to identify and eliminate waste in their AWS account. They are specifically looking for idle resources that are still incurring charges. Which THREE AWS tools or features can help identify these cost-optimization opportunities?

⚠ Common exam trap

SAA-C03 often tests the distinction between cost-optimization tools and security/audit tools — candidates must recognize that CloudTrail (audit) and Inspector (vulnerability scanning) are security services that do not identify idle or over-provisioned resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Trusted Advisor.

AWS Trusted Advisor (A) is correct because its Cost Optimization checks specifically flag idle or underutilized resources that still incur charges, such as unassociated Elastic IP addresses, idle load balancers, and underutilized Amazon EC2 instances. AWS Compute Optimizer (B) is correct because it analyzes CloudWatch metrics to generate recommendations for over-provisioned resources, including idle or underutilized EC2 instances, Auto Scaling groups, EBS volumes, and Lambda functions, directly surfacing cost-optimization opportunities. AWS Cost Explorer Rightsizing Recommendations (C) is correct because it uses historical utilization data to recommend resizing or terminating idle/underutilized EC2 instances, helping eliminate waste from over-provisioned compute. AWS CloudTrail (D) is not correct because it records API activity for auditing, security, and compliance, not for identifying idle resources or cost waste. Amazon Inspector (E) is not correct because it is a vulnerability management service that scans workloads for security exposures, not a cost-optimization or idle-resource detection tool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Trusted Advisor.

    Why this is correct

    Trusted Advisor includes a 'Cost Optimization' pillar that specifically flags idle resources, such as unassociated Elastic IP addresses, underutilized Amazon EBS volumes, and idle Amazon RDS instances. It provides a quick dashboard view of immediate savings that can be achieved by terminating or resizing these resources.

  • ✓

    AWS Compute Optimizer.

    Why this is correct

    Compute Optimizer analyzes the configuration and utilization metrics of your AWS resources. It uses machine learning to identify if resources are over-provisioned and provides recommendations to downsize or change instance types to save money while maintaining performance, covering EC2, EBS, and Lambda functions.

  • ✓

    AWS Cost Explorer Rightsizing Recommendations.

    Why this is correct

    Cost Explorer provides a dedicated rightsizing tool that looks at your EC2 instance usage. It identifies instances that could be downsized within the same family or moved to a different family to reduce costs, providing estimated monthly savings for each recommendation based on your actual usage patterns.

  • ✗

    AWS CloudTrail.

    Why it's wrong here

    CloudTrail is a service that records API calls and account activity for security, auditing, and compliance. While it tells you who created a resource, it does not provide analysis of resource utilization or cost-saving recommendations, making it the wrong tool for identifying idle resource waste.

  • ✗

    Amazon Inspector.

    Why it's wrong here

    Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. It focuses on finding vulnerabilities and deviations from best practices in security, not on cost optimization or identifying idle infrastructure resources.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.