What's changed: Deepened SCS-C02 Chapter 6 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)
6.4In-scope services for management and security governance
A roundup of in-scope SCS-C03 services for management and security governance.
6.4.1In-scope services for management and security governance
For management and security governance, beyond Organizations/SCP/Control Tower/Audit Manager/Artifact, know: AWS CloudFormation (IaC), AWS Service Catalog (distribute approved resources as a catalog), AWS Well-Architected Tool (assess designs against the six pillars: operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability), Amazon CodeGuru Security (detect code vulnerabilities), Amazon Q Business / Amazon Q Developer (assist business questions and coding), and Amazon SageMaker AI (build/operate ML—model security in scope).
6.4.2Section summary
- IaC/catalog/assess: CloudFormation / Service Catalog / Well-Architected Tool
- Code/gen AI/ML: CodeGuru Security / Amazon Q Business, Q Developer / SageMaker AI
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which AWS service automatically detects known vulnerabilities and security-policy violations in code?
Q2. Which catalogs approved resources (e.g., CloudFormation templates) for standardized self-service provisioning?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

