SAA-C03 Design Cost-Optimized Architectures Practice Question
An organization wants to identify and eliminate waste in their AWS account. They are specifically looking for idle resources that are still incurring charges. Which THREE AWS tools or features can help identify these cost-optimization opportunities?
⚠ Common exam trap
SAA-C03 often tests the distinction between cost-optimization tools and security/audit tools — candidates must recognize that CloudTrail (audit) and Inspector (vulnerability scanning) are security services that do not identify idle or over-provisioned resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Trusted Advisor.
AWS Trusted Advisor (A) is correct because its Cost Optimization checks specifically flag idle or underutilized resources that still incur charges, such as unassociated Elastic IP addresses, idle load balancers, and underutilized Amazon EC2 instances. AWS Compute Optimizer (B) is correct because it analyzes CloudWatch metrics to generate recommendations for over-provisioned resources, including idle or underutilized EC2 instances, Auto Scaling groups, EBS volumes, and Lambda functions, directly surfacing cost-optimization opportunities. AWS Cost Explorer Rightsizing Recommendations (C) is correct because it uses historical utilization data to recommend resizing or terminating idle/underutilized EC2 instances, helping eliminate waste from over-provisioned compute. AWS CloudTrail (D) is not correct because it records API activity for auditing, security, and compliance, not for identifying idle resources or cost waste. Amazon Inspector (E) is not correct because it is a vulnerability management service that scans workloads for security exposures, not a cost-optimization or idle-resource detection tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Trusted Advisor.
Why this is correct
Trusted Advisor includes a 'Cost Optimization' pillar that specifically flags idle resources, such as unassociated Elastic IP addresses, underutilized Amazon EBS volumes, and idle Amazon RDS instances. It provides a quick dashboard view of immediate savings that can be achieved by terminating or resizing these resources.
- ✓
AWS Compute Optimizer.
Why this is correct
Compute Optimizer analyzes the configuration and utilization metrics of your AWS resources. It uses machine learning to identify if resources are over-provisioned and provides recommendations to downsize or change instance types to save money while maintaining performance, covering EC2, EBS, and Lambda functions.
- ✓
AWS Cost Explorer Rightsizing Recommendations.
Why this is correct
Cost Explorer provides a dedicated rightsizing tool that looks at your EC2 instance usage. It identifies instances that could be downsized within the same family or moved to a different family to reduce costs, providing estimated monthly savings for each recommendation based on your actual usage patterns.
- ✗
AWS CloudTrail.
Why it's wrong here
CloudTrail is a service that records API calls and account activity for security, auditing, and compliance. While it tells you who created a resource, it does not provide analysis of resource utilization or cost-saving recommendations, making it the wrong tool for identifying idle resource waste.
- ✗
Amazon Inspector.
Why it's wrong here
Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. It focuses on finding vulnerabilities and deviations from best practices in security, not on cost optimization or identifying idle infrastructure resources.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
About these practice questions
One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.