Study tracks
AWS Certified Security – Specialty (SCS-C03) Track
SCS-C03 is the current version of the AWS security specialty exam. Compared with SCS-C02, it splits "threat detection and incident response" into two separate domains (Detection, Incident Response) and makes identity the heaviest domain. This track walks the six domains in exam order and points each task at the section of this repo that teaches it. Domain weights come from the official AWS exam guide; re-check it before you book, because AWS revises these guides.
6 min read
6 sections
verified 2026-10
Last verified2026-10
| Domain | Weight |
|---|---|
| 1. Detection | 16% |
| 2. Incident Response | 14% |
| 3. Infrastructure Security | 18% |
| 4. Identity and Access Management | 20% |
| 5. Data Protection | 18% |
| 6. Security Foundations and Governance | 14% |
TipThe exam is scenario-heavy: "a company needs X with the least operational overhead — which service?" For every service, know what it does, what it does not do, and which service people confuse it with.
Domain 1 — Detection (16%)
Task 1.1 — Monitoring and alerting across an account or organisation
- How the security services link together — GuardDuty and Inspector findings flow into Security Hub, then EventBridge triggers the response
- GuardDuty — threat detection from CloudTrail, VPC Flow Logs and DNS logs; what it can and cannot see
- Security Hub and Macie — finding aggregation versus sensitive-data discovery in S3
- AWS Config — continuous configuration recording, rules and conformance packs
- Amazon Security Lake — an OCSF-normalised log lake across accounts; State Manager for scheduled assessments is in IR automation
Task 1.2 — Logging solutions
- CloudTrail — organisation trail, management versus data events
- VPC security — where VPC Flow Logs fit
- The SIEM pipeline — collect, parse, normalise, enrich, store; maps onto OpenSearch, Lambda and Athena
- Useful IR queries — hunting through CloudTrail
- Lab: CloudTrail detection — build CloudTrail → S3 + CloudWatch + Athena with alarms as code
- Logging architecture — log-archive account, CloudWatch agent, Route 53 Resolver query logs, transit gateway flow logs
- Querying logs — CloudWatch Logs Insights, Athena, OpenSearch, metric filters
Task 1.3 — Troubleshooting monitoring and logging
- Troubleshooting missing logs — agent permissions, Lambda and API Gateway logging, CloudTrail bucket and key policies
Domain 2 — Incident Response (14%)
Task 2.1 — Design and test an incident response plan
- IR framework for AWS — the NIST phases applied to cloud resources
- Multi-account security — limiting blast radius before anything happens
- GuardDuty finding → response mapping — which finding triggers which automated action
- Lab: IR scenario — SSRF to IMDS credential theft, then respond with IR roles
- IR preparation, automation and testing — SSM Automation and OpsCenter, Step Functions, Forensics Orchestrator, Fault Injection Service, Resilience Hub
Task 2.2 — Respond to security events
- Compromised IAM credentials — contain, investigate, eradicate
- A leaked access key, step by step
- EC2 instance compromise — isolation security group, snapshots, memory capture
- S3 data exfiltration and Lambda compromise
- Compromised EKS pod — plus the EKS lab
- Digital forensics — order of volatility and chain of custody for the artifacts you capture
- Amazon Detective — behaviour graphs for root-cause analysis
- Backups and ransomware resilience — restoring with AWS Backup
Domain 3 — Infrastructure Security (18%)
Task 3.1 — Network edge
- The security products overview — WAF, Shield and CloudFront in one place
- OWASP Top 10 for the web — what WAF managed rules are defending against
- HTTP security headers — including CORS
- AWS WAF building blocks — rate-based and geo rules, Bot Control, JA3/JA4 fingerprinting, labels
- AWS Shield and locking the origin — Shield Advanced, origin access control, S3 CORS
Task 3.2 — Compute workloads
- EC2 security — IMDSv2, instance profiles, IRSA
- How compute gets credentials — instance profiles, service roles, execution roles
- Lambda security and Inspector
- Linux hardening — what a hardened AMI should bake in
- SAST, DAST and SCA in the pipeline
- OWASP LLM Top 10 — the guardrails a generative-AI workload needs
- Compute security — Image Builder, Patch Manager, Session Manager vs Instance Connect, Inspector, pipeline scanning, GenAI guardrails
Task 3.3 — Network security controls
- VPC security — security groups versus NACLs, Network Firewall, segmentation
- VPC endpoint policies — private access without the internet
- Hybrid connectivity — Site-to-Site VPN, Direct Connect, MACsec, Client VPN
- Verified Access, segmentation and finding unintended access — Network Access Analyzer, Inspector reachability
Domain 4 — Identity and Access Management (20%)
Task 4.1 — Authentication
- Principals and the root user
- Roles and AssumeRole — STS temporary credentials,
AKIAversusASIA - Provisioning users the right way — IAM Identity Center and permission sets
- OIDC and SAML — the federation protocols behind the IdP integration
- MFA methods compared
- Cognito, presigned URLs and Directory Service
Task 4.2 — Authorisation
- The policy types and how a request is evaluated
- Policy types deep dive — resource-based policies, boundaries, session policies
- Permission boundaries — safe delegation
- PassRole, confused deputy and ExternalId
- IAM privilege escalation paths
- IAM Access Analyzer — finding unintended external and unused access
- ABAC, Roles Anywhere and Verified Permissions
- Debugging AccessDenied — Policy Simulator, Access Analyzer, decoding messages
Domain 5 — Data Protection (18%)
Task 5.1 — Data in transit
- How TLS works and mTLS
- TLS end to end — certificates, cipher suites, the 1.3 handshake
- VPC endpoint policies — PrivateLink keeps traffic off the internet
- Encryption in transit on AWS — ELB security policies, aws:SecureTransport, Nitro, EKS and EMR
Task 5.2 — Data at rest
- KMS — envelope encryption, key policies, grants
- S3 security — Block Public Access, versioning, Object Lock
- MACs and digital signatures — integrity and code signing
- Choosing where keys live — CloudHSM vs KMS, client- vs server-side
- Integrity, retention and immutability — Object Lock, Vault Lock, Lifecycle
- Backups and ransomware resilience — Backup Vault Lock, air-gapped vaults, Data Lifecycle Manager
Task 5.3 — Secrets, credentials and key material
- Secrets management — why secrets leave code and CI
- Certificates and PKI
- Imported material, external key stores, multi-Region keys
- Secrets, certificates and masking — Secrets Manager rotation, Private CA, log and SNS data protection
Domain 6 — Security Foundations and Governance (14%)
Task 6.1 — Centrally deploy and manage accounts
- AWS Organizations, SCPs and RCPs — landing zone, the two kinds of guardrail
- Worked example: an S3, EKS and EC2-only account
- Cost controls — SCPs as spend guardrails; a cost spike as a cryptomining signal
- Control Tower — preventive, detective and proactive controls
- Organization policy types — declarative and AI opt-out policies, delegated admins, centralised root access
Task 6.2 — Secure, consistent deployment
- IaC and tagging — StackSets, cfn-lint, CloudFormation Guard, tag policies
- Firewall Manager, Service Catalog, RAM
Task 6.3 — Compliance evaluation
- Compliance frameworks — what the evidence is ultimately for
- Evaluating compliance — Config remediation, Security Hub, Audit Manager, Artifact, Well-Architected