Security Notes
Study tracks

AWS Certified Security – Specialty (SCS-C03) Track

SCS-C03 is the current version of the AWS security specialty exam. Compared with SCS-C02, it splits "threat detection and incident response" into two separate domains (Detection, Incident Response) and makes identity the heaviest domain. This track walks the six domains in exam order and points each task at the section of this repo that teaches it. Domain weights come from the official AWS exam guide; re-check it before you book, because AWS revises these guides.

6 min read 6 sections verified 2026-10

Last verified2026-10

DomainWeight
1. Detection16%
2. Incident Response14%
3. Infrastructure Security18%
4. Identity and Access Management20%
5. Data Protection18%
6. Security Foundations and Governance14%
Tip

The exam is scenario-heavy: "a company needs X with the least operational overhead — which service?" For every service, know what it does, what it does not do, and which service people confuse it with.

Domain 1 — Detection (16%)

Task 1.1 — Monitoring and alerting across an account or organisation

Task 1.2 — Logging solutions

Task 1.3 — Troubleshooting monitoring and logging

Domain 2 — Incident Response (14%)

Task 2.1 — Design and test an incident response plan

Task 2.2 — Respond to security events

Domain 3 — Infrastructure Security (18%)

Task 3.1 — Network edge

Task 3.2 — Compute workloads

Task 3.3 — Network security controls

Domain 4 — Identity and Access Management (20%)

Task 4.1 — Authentication

Task 4.2 — Authorisation

Domain 5 — Data Protection (18%)

Task 5.1 — Data in transit

Task 5.2 — Data at rest

Task 5.3 — Secrets, credentials and key material

Domain 6 — Security Foundations and Governance (14%)

Task 6.1 — Centrally deploy and manage accounts

Task 6.2 — Secure, consistent deployment

Task 6.3 — Compliance evaluation