Instiq

AWS Certified Security – SpecialtyStudy guide

The specialty certification for designing threat detection, logging, infrastructure/identity security, data protection, and governance on AWS (SCS-C02).

About AWS Certified Security – Specialty (SCS-C02)

AWS Certified Security – Specialty (SCS-C02) is a Specialty-level certification from AWS. This page organizes the exam scope into a 6-chapter, 18-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Threat Detection and Incident Response~14%
  • Security Logging and Monitoring~18%
  • Infrastructure Security~20%
  • Identity and Access Management~16%
  • Data Protection~18%
  • Management and Security Governance~14%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Note: This exam has been retired (successor: SCS-C03).

Official exam information: https://aws.amazon.com/certification/certified-security-specialty/

1Threat Detection and Incident Response

  • 1.1Threat Detection

    Understand threat detection—GuardDuty, Inspector, Macie, Detective, and IAM Access Analyzer. Find threats, vulnerabilities, and sensitive-data exposure from logs and activity.

  • 1.2Aggregating Findings and Automated Response

    Understand detection-to-response—Security Hub, EventBridge, auto-remediation (Lambda/SSM Automation), and isolation. Centralize findings and respond fast and mechanically.

  • 1.3Incident Response Preparation and Forensics

    Understand IR readiness—playbooks/runbooks, forensics (snapshots/isolation), CloudTrail trails, compromised-credential response, and least-privilege IR roles. Prepare in advance to respond fast and reliably.

2Security Logging and Monitoring

  • 2.1Collecting and Protecting Logs

    Understand log design—CloudTrail (API auditing), VPC Flow Logs, S3/service logs, organization trails, and tamper protection. Build comprehensive, tamper-resistant logging.

  • 2.2Monitoring and Alerting

    Understand real-time monitoring—CloudWatch (metrics/logs/alarms), metric filters, EventBridge, Config (config monitoring), and notifications. Detect and notify on anomalies immediately.

  • 2.3Log Analysis and Centralization

    Understand using logs—CloudWatch Logs Insights, Athena (S3 logs), OpenSearch, centralized logging (cross-account), and retention/lifecycle. Gain insight from large log volumes.

3Infrastructure Security

  • 3.1Protecting the Network Perimeter

    Understand VPC security—security groups/NACLs, subnet isolation, NAT/IGW, VPC endpoints (Gateway/Interface), and PrivateLink. Defend networks in depth.

  • 3.2Edge Protection and DDoS Mitigation

    Understand application-edge defense—WAF, Shield (Standard/Advanced), CloudFront, Route 53, Firewall Manager, and Network Firewall. Protect apps from L7 attacks and DDoS.

  • 3.3Protecting Compute and Endpoints

    Understand compute defense—Systems Manager (patch/Session Manager), hardening/golden AMIs, Inspector, bastion-less (SSM), and EC2 metadata (IMDSv2). Keep instances secure.

4Identity and Access Management

  • 4.1IAM Policies and Evaluation Logic

    Understand the core of access control—identity/resource-based policies, explicit deny wins, SCPs, permissions boundaries, and condition keys. Precisely design who can access what.

  • 4.2Federation and Cross-Account Access

    Understand temporary credentials and federation—IAM roles (AssumeRole), SAML/OIDC federation, IAM Identity Center, ExternalId, and STS. Delegate securely without long-lived keys.

  • 4.3Achieving Least Privilege and Auditing

    Understand minimizing permissions—IAM Access Analyzer, Access Advisor (last-accessed), policy validation, temporary roles, and root user protection. Continually trim excess permissions.

5Data Protection

  • 5.1KMS and Encryption

    Understand at-rest encryption core—KMS, CMK (customer-managed keys), envelope encryption, key policies, key rotation, and CloudHSM. Manage keys securely and encrypt data.

  • 5.2Secrets Management and Encryption in Transit

    Understand protecting credentials and traffic—Secrets Manager (auto-rotation), Parameter Store (SecureString), TLS/ACM, and certificate management. Handle secrets and traffic securely.

  • 5.3Protecting Storage and Database Data

    Understand protecting stores—S3 encryption (SSE-S3/SSE-KMS/DSSE), S3 public-access block/bucket policies, EBS/RDS encryption, backup protection, and data lifecycle. Store data securely.

6Management and Security Governance

  • 6.1Multi-Account Security Governance

    Understand org-scale governance—AWS Organizations/SCP, Control Tower, delegated administrators, central log/security accounts, and Firewall Manager. Enforce consistent guardrails across accounts.

  • 6.2Configuration Compliance and Auto-Remediation

    Understand continuous compliance—AWS Config (rules/conformance packs), auto-remediation, Security Hub standards, Audit Manager, and Systems Manager. Continuously assess compliance and auto-fix drift.

  • 6.3Operational Governance and Cost/Secret Control

    Understand operational governance—tagging strategy, Trusted Advisor, cost anomaly detection, patch/config compliance, org-wide secret management, and backup policies. Balance security and operations.