AWS Certified Security – SpecialtyStudy guide
The specialty certification for designing security on AWS (SCS-C03, successor to SCS-C02, including generative AI guardrails).
About AWS Certified Security – Specialty (SCS-C03)
AWS Certified Security – Specialty (SCS-C03) is a Specialty-level certification from AWS. This page organizes the exam scope into a 6-chapter, 25-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Detection and Incident Response~16%
- Security Logging and Monitoring~14%
- Infrastructure Security (including generative AI guardrails)~18%
- Identity and Access Management~20%
- Data Protection~18%
- Security Foundations and Governance~14%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://docs.aws.amazon.com/aws-certification/latest/examguides/security-specialty-03.html
1Threat Detection and Incident Response
- 1.1Threat Detection
Understand threat detection—GuardDuty, Inspector, Macie, Detective, and IAM Access Analyzer. Find threats, vulnerabilities, and sensitive-data exposure from logs and activity.
- 1.2Aggregating Findings and Automated Response
Understand detection-to-response—Security Hub, EventBridge, auto-remediation (Lambda/SSM Automation), and isolation. Centralize findings and respond fast and mechanically.
- 1.3Incident Response Preparation and Forensics
Understand IR readiness—playbooks/runbooks, forensics (snapshots/isolation), CloudTrail trails, compromised-credential response, and least-privilege IR roles. Prepare in advance to respond fast and reliably.
- 1.4In-scope services for threat detection and incident response
A roundup of in-scope SCS-C03 services for threat detection and incident response.
2Security Logging and Monitoring
- 2.1Collecting and Protecting Logs
Understand log design—CloudTrail (API auditing), VPC Flow Logs, S3/service logs, organization trails, and tamper protection. Build comprehensive, tamper-resistant logging.
- 2.2Monitoring and Alerting
Understand real-time monitoring—CloudWatch (metrics/logs/alarms), metric filters, EventBridge, Config (config monitoring), and notifications. Detect and notify on anomalies immediately.
- 2.3Log Analysis and Centralization
Understand using logs—CloudWatch Logs Insights, Athena (S3 logs), OpenSearch, centralized logging (cross-account), and retention/lifecycle. Gain insight from large log volumes.
- 2.4In-scope services for security logging and monitoring
A roundup of in-scope SCS-C03 services for security logging and monitoring.
3Infrastructure Security
- 3.1Protecting the Network Perimeter
Understand VPC security—security groups/NACLs, subnet isolation, NAT/IGW, VPC endpoints (Gateway/Interface), and PrivateLink. Defend networks in depth.
- 3.2Edge Protection and DDoS Mitigation
Understand application-edge defense—WAF, Shield (Standard/Advanced), CloudFront, Route 53, Firewall Manager, and Network Firewall. Protect apps from L7 attacks and DDoS.
- 3.3Protecting Compute and Endpoints
Understand compute defense—Systems Manager (patch/Session Manager), hardening/golden AMIs, Inspector, bastion-less (SSM), and EC2 metadata (IMDSv2). Keep instances secure.
- 3.4Securing generative AI applications
Learn generative AI security, newly added in SCS-C03: mitigations for the OWASP Top 10 for LLM Applications (prompt injection, sensitive information disclosure, insecure output handling, etc.), Amazon Bedrock Guardrails (content filters, denied topics, PII masking, grounding), access control to Bedrock (IAM), data protection for prompts/outputs, and auditing/logging of model invocations.
- 3.5In-scope services for infrastructure security
A roundup of in-scope SCS-C03 services for infrastructure security.
4Identity and Access Management
- 4.1IAM Policies and Evaluation Logic
Understand the core of access control—identity/resource-based policies, explicit deny wins, SCPs, permissions boundaries, and condition keys. Precisely design who can access what.
- 4.2Federation and Cross-Account Access
Understand temporary credentials and federation—IAM roles (AssumeRole), SAML/OIDC federation, IAM Identity Center, ExternalId, and STS. Delegate securely without long-lived keys.
- 4.3Achieving Least Privilege and Auditing
Understand minimizing permissions—IAM Access Analyzer, Access Advisor (last-accessed), policy validation, temporary roles, and root user protection. Continually trim excess permissions.
- 4.4In-scope services for identity and access management
A roundup of in-scope SCS-C03 services for identity and access management.
5Data Protection
- 5.1KMS and Encryption
Understand at-rest encryption core—KMS, CMK (customer-managed keys), envelope encryption, key policies, key rotation, and CloudHSM. Manage keys securely and encrypt data.
- 5.2Secrets Management and Encryption in Transit
Understand protecting credentials and traffic—Secrets Manager (auto-rotation), Parameter Store (SecureString), TLS/ACM, and certificate management. Handle secrets and traffic securely.
- 5.3Protecting Storage and Database Data
Understand protecting stores—S3 encryption (SSE-S3/SSE-KMS/DSSE), S3 public-access block/bucket policies, EBS/RDS encryption, backup protection, and data lifecycle. Store data securely.
- 5.4In-scope services for data protection
A roundup of in-scope SCS-C03 services for data protection.
6Management and Security Governance
- 6.1Multi-Account Security Governance
Understand org-scale governance—AWS Organizations/SCP, Control Tower, delegated administrators, central log/security accounts, and Firewall Manager. Enforce consistent guardrails across accounts.
- 6.2Configuration Compliance and Auto-Remediation
Understand continuous compliance—AWS Config (rules/conformance packs), auto-remediation, Security Hub standards, Audit Manager, and Systems Manager. Continuously assess compliance and auto-fix drift.
- 6.3Operational Governance and Cost/Secret Control
Understand operational governance—tagging strategy, Trusted Advisor, cost anomaly detection, patch/config compliance, org-wide secret management, and backup policies. Balance security and operations.
- 6.4In-scope services for management and security governance
A roundup of in-scope SCS-C03 services for management and security governance.

