Instiq

AWS Certified Security – SpecialtyStudy guide

The specialty certification for designing security on AWS (SCS-C03, successor to SCS-C02, including generative AI guardrails).

About AWS Certified Security – Specialty (SCS-C03)

AWS Certified Security – Specialty (SCS-C03) is a Specialty-level certification from AWS. This page organizes the exam scope into a 6-chapter, 25-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Detection and Incident Response~16%
  • Security Logging and Monitoring~14%
  • Infrastructure Security (including generative AI guardrails)~18%
  • Identity and Access Management~20%
  • Data Protection~18%
  • Security Foundations and Governance~14%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Official exam information: https://docs.aws.amazon.com/aws-certification/latest/examguides/security-specialty-03.html

1Threat Detection and Incident Response

2Security Logging and Monitoring

  • 2.1Collecting and Protecting Logs

    Understand log design—CloudTrail (API auditing), VPC Flow Logs, S3/service logs, organization trails, and tamper protection. Build comprehensive, tamper-resistant logging.

  • 2.2Monitoring and Alerting

    Understand real-time monitoring—CloudWatch (metrics/logs/alarms), metric filters, EventBridge, Config (config monitoring), and notifications. Detect and notify on anomalies immediately.

  • 2.3Log Analysis and Centralization

    Understand using logs—CloudWatch Logs Insights, Athena (S3 logs), OpenSearch, centralized logging (cross-account), and retention/lifecycle. Gain insight from large log volumes.

  • 2.4In-scope services for security logging and monitoring

    A roundup of in-scope SCS-C03 services for security logging and monitoring.

3Infrastructure Security

  • 3.1Protecting the Network Perimeter

    Understand VPC security—security groups/NACLs, subnet isolation, NAT/IGW, VPC endpoints (Gateway/Interface), and PrivateLink. Defend networks in depth.

  • 3.2Edge Protection and DDoS Mitigation

    Understand application-edge defense—WAF, Shield (Standard/Advanced), CloudFront, Route 53, Firewall Manager, and Network Firewall. Protect apps from L7 attacks and DDoS.

  • 3.3Protecting Compute and Endpoints

    Understand compute defense—Systems Manager (patch/Session Manager), hardening/golden AMIs, Inspector, bastion-less (SSM), and EC2 metadata (IMDSv2). Keep instances secure.

  • 3.4Securing generative AI applications

    Learn generative AI security, newly added in SCS-C03: mitigations for the OWASP Top 10 for LLM Applications (prompt injection, sensitive information disclosure, insecure output handling, etc.), Amazon Bedrock Guardrails (content filters, denied topics, PII masking, grounding), access control to Bedrock (IAM), data protection for prompts/outputs, and auditing/logging of model invocations.

  • 3.5In-scope services for infrastructure security

    A roundup of in-scope SCS-C03 services for infrastructure security.

4Identity and Access Management

5Data Protection

  • 5.1KMS and Encryption

    Understand at-rest encryption core—KMS, CMK (customer-managed keys), envelope encryption, key policies, key rotation, and CloudHSM. Manage keys securely and encrypt data.

  • 5.2Secrets Management and Encryption in Transit

    Understand protecting credentials and traffic—Secrets Manager (auto-rotation), Parameter Store (SecureString), TLS/ACM, and certificate management. Handle secrets and traffic securely.

  • 5.3Protecting Storage and Database Data

    Understand protecting stores—S3 encryption (SSE-S3/SSE-KMS/DSSE), S3 public-access block/bucket policies, EBS/RDS encryption, backup protection, and data lifecycle. Store data securely.

  • 5.4In-scope services for data protection

    A roundup of in-scope SCS-C03 services for data protection.

6Management and Security Governance