Synthesis: The 08-13 Prediction That "Secure Workloads and Applications" Was the Weak Domain Was Right — the Actual Exam Confirms It, With Specifics the Practice-Test Guess Didn't Have
The connection
Synthesis/egress-costs-and-oauth-oidc-name-this-windows-two-weakest-certexam-domains (2026-08-13) used a now-deleted practice-test file (TestResult/Summary.md, scored task 1.2 "Secure workloads and applications" at 17%) to predict that OAuth2/OIDC and mTLS were the vendor-neutral gap underneath that weak score. The real exam, taken 2026-08-16, confirms the domain-level call directly: Domain 1, "Design Secure Architectures" (30% weight), is the flagged weak domain on a 763/1000 passing score — the highest-weighted domain in the exam and the one the candidate scored worst on relatively.
The new Domain1/README.md and D1_Report.md (added this window, replacing the deleted TestResult/ folder) name the actual tested surface with much more precision than the earlier practice-test guess: IAM policy evaluation (explicit-deny precedence, identity vs. resource-based policies via the Principal element), Security Groups (stateful/instance) vs. NACLs (stateless/subnet), VPC endpoint cost split (Gateway free for S3/DynamoDB vs. Interface/PrivateLink paid), Secrets Manager vs. Parameter Store (rotation is the defining differentiator), KMS vs. CloudHSM, and the RPO/RTO DR ladder (backup-restore → pilot light → warm standby → multi-site).
Two of these six named sub-topics — secrets rotation and DR patterns — map onto Fundamentals notes that didn't exist when the original 08-13 prediction was made: secrets management and rotation and (at the framework level) STRIDE threat modeling (Secrets Manager/KMS map to STRIDE's Information Disclosure category, WAF/Shield to Denial-of-Service — a link the 08-13 note flagged as "plausible but undeveloped" and can now be confirmed against real exam content).
Why this wasn't visible before
The 08-13 note was working from a practice-test artifact three weeks stale relative to the fundamentals batch it was cross-linking, and had no way to confirm its domain-level guess against the actual exam — the exam hadn't been taken yet. TestResult/Summary.md has since been deleted in favor of the four Domain{1-4}/D{n}_Report.md files, which is itself a structural upgrade (per-domain retrospective reports replace a single practice-run summary) that makes this kind of before/after comparison possible for the first time.
What this suggests
- Per project_saa_c03_certified (unresolved) (memory), the SAA-C03 track is now closed — this note is a capstone, not a live remediation plan. Its value is validating that the vault's cross-linking method (Fundamentals ↔ CertExams) produces predictions that hold up against a real outcome, which is the strongest evidence yet that the crosslink-audit skill draft (unresolved) is worth keeping around for the next cert track, not just this one.
- The Tools/ folder's 18-file AWS Security/IAM/Governance cluster (AWS_KMS, AWS_CloudHSM, AWS_Secrets_Manager, IAM, AWS_WAF, AWS_Shield, Amazon_GuardDuty, Amazon_Macie, etc. — all added this window) is now a ready-made reference set for exactly the six sub-topics
D1_Report.mdnames, but none of the Tools notes cross-link back to the Domain1 report yet — the next skill-draft revision should add "check Tools/ for a matching stub" as an explicit step alongside the existing Fundamentals check.
Related
- Synthesis/egress-costs-and-oauth-oidc-name-this-windows-two-weakest-certexam-domains
- Synthesis/new-fundamentals-batch-grounds-into-certexams-weak-domains
- Architecture/Fundamentals/secrets-management-and-rotation
- Architecture/Fundamentals/threat-modeling-stride
- CertExams/SAA-C03/Domain1/README
- AgentStack/Skills/.drafts/certexam-fundamentals-crosslink-audit (unresolved)