AWS Security Specialty: evidence-based security
SCS-C03 preparation covering detection, incidents, infrastructure, identity, data protection, and governance. Original lessons and cases.
Objectives and progression
Eight lessons, 50 questions, and eight fictional cases connect AWS controls to security and production decisions. Questions follow the six SCS-C03 domains: 8/7/9/10/9/7. The internal assessment contains 32 decisions in 60 minutes. The full mock is planned and not yet available. This initial pass does not claim exhaustive coverage of official tasks. The official guide includes single choice, multiple response, ordering, and matching. This pass uses single and multiple choice; it does not yet reproduce native ordering and matching interfaces. This path prepares SCS-C03. AWS announces retirement of Brazilian Portuguese, Simplified Chinese, and Latin American Spanish delivery after 2026-12-31; the certification remains active. Confirm language and version before scheduling.
Audience: Security and cloud engineers, APS teams, and technical managers coordinating controls and response.
Prerequisites: Experience with AWS, IAM, networking, logs, and data protection. The SCS-C03 guide recommends equivalent experience of three to five years securing cloud solutions; the general FAQ describes five years in security and two in AWS. These are recommendations with no mandatory prior certification.
360 estimated study minutes
- Define detection coverage and preserve useful evidence.
- Contain incidents and confirm recovery against criteria.
- Evaluate network, application, and identity controls.
- Manage cryptographic material, retention, and organizational boundaries.
Modules
- Detection and security evidence
- Response, containment, and preservation
- Networking and administrative access
- WAF and GenAI application protection
- Federation and delegation across entities
- Policies, tags, and access analysis
- Keys, masking, and retention
- Governance and central controls
Continue learning
- AWS Certified DevOps Engineer Professional
- AWS Certified Solutions Architect Professional
- CompTIA Security+
References and version
SCS-C03
- AWS Certified Security - Specialty · 2026-09-29
- SCS-C03 exam guide · 2026-09-29
- SCS-C03 domain 1 · 2026-09-29
- SCS-C03 domain 2 · 2026-09-29
- SCS-C03 domain 3 · 2026-09-29
- SCS-C03 domain 4 · 2026-09-29
- SCS-C03 domain 5 · 2026-09-29
- SCS-C03 domain 6 · 2026-09-29
- SCS-C03 revisions · 2026-09-29
- SCS-C02 to C03 comparison · 2026-09-29
- CloudTrail file integrity validation · 2026-09-29
- VPC Flow Logs · 2026-09-29
- GuardDuty foundational data sources · 2026-09-29
- Amazon Security Lake · 2026-09-29
- EC2 security groups · 2026-09-29
- Network ACLs · 2026-09-29
- Session Manager · 2026-09-29
- WAF testing and tuning · 2026-09-29
- Bedrock Guardrails · 2026-09-29
- Revoke role sessions · 2026-09-29
- Third-party role access · 2026-09-29
- Permissions boundaries · 2026-09-29
- S3 presigned URLs · 2026-09-29
- ABAC tag controls · 2026-09-29
- Access Analyzer findings · 2026-09-29
- S3 Object Lock · 2026-09-29
- KMS rotation · 2026-09-29
- Cross-account KMS · 2026-09-29
- Imported KMS key material · 2026-09-29
- CloudWatch Logs data protection · 2026-09-29
- Resource control policies · 2026-09-29
- Service control policies · 2026-09-29
- Centralized member root access · 2026-09-29
- AWS Audit Manager · 2026-09-29
- Incident containment · 2026-09-29
- EC2 triage and containment · 2026-09-29
What you will explore
0 / 8Detection and security evidence
Connect findings, sources, and actually observed coverage.
Response, containment, and preservation
Limit harm while retaining context needed for recovery.
Networking and administrative access
Evaluate rules, return paths, and audit limits.
WAF and GenAI application protection
Introduce filters with validation and retain data authorization.
Federation and delegation across entities
Bound context, duration, and principal type.
Policies, tags, and access analysis
Protect authorization attributes and interpret findings precisely.
Keys, masking, and retention
Distinguish cryptographic protection, visibility, and retention.
Governance and central controls
Introduce organizational boundaries and report scoped evidence.