AWS Certified Security – SpecialtyStudy guide
The specialty certification for designing threat detection, logging, infrastructure/identity security, data protection, and governance on AWS (SCS-C02).
About AWS Certified Security – Specialty (SCS-C02)
AWS Certified Security – Specialty (SCS-C02) is a Specialty-level certification from AWS. This page organizes the exam scope into a 6-chapter, 18-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Threat Detection and Incident Response~14%
- Security Logging and Monitoring~18%
- Infrastructure Security~20%
- Identity and Access Management~16%
- Data Protection~18%
- Management and Security Governance~14%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Note: This exam has been retired (successor: SCS-C03).
Official exam information: https://aws.amazon.com/certification/certified-security-specialty/
1Threat Detection and Incident Response
- 1.1Threat Detection
Understand threat detection—GuardDuty, Inspector, Macie, Detective, and IAM Access Analyzer. Find threats, vulnerabilities, and sensitive-data exposure from logs and activity.
- 1.2Aggregating Findings and Automated Response
Understand detection-to-response—Security Hub, EventBridge, auto-remediation (Lambda/SSM Automation), and isolation. Centralize findings and respond fast and mechanically.
- 1.3Incident Response Preparation and Forensics
Understand IR readiness—playbooks/runbooks, forensics (snapshots/isolation), CloudTrail trails, compromised-credential response, and least-privilege IR roles. Prepare in advance to respond fast and reliably.
2Security Logging and Monitoring
- 2.1Collecting and Protecting Logs
Understand log design—CloudTrail (API auditing), VPC Flow Logs, S3/service logs, organization trails, and tamper protection. Build comprehensive, tamper-resistant logging.
- 2.2Monitoring and Alerting
Understand real-time monitoring—CloudWatch (metrics/logs/alarms), metric filters, EventBridge, Config (config monitoring), and notifications. Detect and notify on anomalies immediately.
- 2.3Log Analysis and Centralization
Understand using logs—CloudWatch Logs Insights, Athena (S3 logs), OpenSearch, centralized logging (cross-account), and retention/lifecycle. Gain insight from large log volumes.
3Infrastructure Security
- 3.1Protecting the Network Perimeter
Understand VPC security—security groups/NACLs, subnet isolation, NAT/IGW, VPC endpoints (Gateway/Interface), and PrivateLink. Defend networks in depth.
- 3.2Edge Protection and DDoS Mitigation
Understand application-edge defense—WAF, Shield (Standard/Advanced), CloudFront, Route 53, Firewall Manager, and Network Firewall. Protect apps from L7 attacks and DDoS.
- 3.3Protecting Compute and Endpoints
Understand compute defense—Systems Manager (patch/Session Manager), hardening/golden AMIs, Inspector, bastion-less (SSM), and EC2 metadata (IMDSv2). Keep instances secure.
4Identity and Access Management
- 4.1IAM Policies and Evaluation Logic
Understand the core of access control—identity/resource-based policies, explicit deny wins, SCPs, permissions boundaries, and condition keys. Precisely design who can access what.
- 4.2Federation and Cross-Account Access
Understand temporary credentials and federation—IAM roles (AssumeRole), SAML/OIDC federation, IAM Identity Center, ExternalId, and STS. Delegate securely without long-lived keys.
- 4.3Achieving Least Privilege and Auditing
Understand minimizing permissions—IAM Access Analyzer, Access Advisor (last-accessed), policy validation, temporary roles, and root user protection. Continually trim excess permissions.
5Data Protection
- 5.1KMS and Encryption
Understand at-rest encryption core—KMS, CMK (customer-managed keys), envelope encryption, key policies, key rotation, and CloudHSM. Manage keys securely and encrypt data.
- 5.2Secrets Management and Encryption in Transit
Understand protecting credentials and traffic—Secrets Manager (auto-rotation), Parameter Store (SecureString), TLS/ACM, and certificate management. Handle secrets and traffic securely.
- 5.3Protecting Storage and Database Data
Understand protecting stores—S3 encryption (SSE-S3/SSE-KMS/DSSE), S3 public-access block/bucket policies, EBS/RDS encryption, backup protection, and data lifecycle. Store data securely.
6Management and Security Governance
- 6.1Multi-Account Security Governance
Understand org-scale governance—AWS Organizations/SCP, Control Tower, delegated administrators, central log/security accounts, and Firewall Manager. Enforce consistent guardrails across accounts.
- 6.2Configuration Compliance and Auto-Remediation
Understand continuous compliance—AWS Config (rules/conformance packs), auto-remediation, Security Hub standards, Audit Manager, and Systems Manager. Continuously assess compliance and auto-fix drift.
- 6.3Operational Governance and Cost/Secret Control
Understand operational governance—tagging strategy, Trusted Advisor, cost anomaly detection, patch/config compliance, org-wide secret management, and backup policies. Balance security and operations.

