Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
AWS

AWS Certified Security - Specialty

SCS-C03AWS Certified Security - Specialty (SCS-C03)

The AWS Certified Security - Specialty certification validates your expertise in creating and implementing security solutions in the AWS Cloud. It covers specialized data classifications, data protection mechanisms, encryption methods, and secure internet protocols. This certification is for experienced security professionals who design and secure AWS workloads and architectures, positioning you as a trusted advisor to stakeholders and customers.

462 practice questions · Updated 2026-07-30

6Domains
16Objectives
172Concepts
462Questions

SCS-C03 Curriculum

Every domain, objective, and concept the SCS-C03 exam measures.

  1. Workload Monitoring Requirements Analysis
  2. Workload Monitoring Strategy Design
  3. Security Event Aggregation
  4. Metrics, Alerts, and Dashboards
  5. Automated Assessments and Investigations
  1. Identify log sources for ingestion
  2. Evaluate log storage requirements
  3. Configure CloudTrail for organization
  4. Set up dedicated CloudWatch logging account
  5. Configure CloudWatch Logs agent
  6. Implement log data lakes with Security Lake
  7. Integrate logs with third-party security tools
  8. Analyze logs with CloudWatch Logs Insights
  9. Analyze logs with Amazon Athena
  10. Use Security Hub findings for log analysis
  11. Normalize and parse logs with OpenSearch Service
  12. Use Lambda for log processing
  13. Visualize logs with Managed Grafana
  14. Correlate logs across sources
  15. Select log sources based on network design
  16. Configure VPC Flow Logs
  17. Configure transit gateway flow logs
  18. Configure Route 53 Resolver logs
  1. Lambda function logging analysis
  2. API Gateway logging analysis
  3. Health checks analysis
  4. CloudFront logging analysis
  5. CloudWatch Agent configuration troubleshooting
  6. Missing logs remediation

  1. Incident response plan design
  2. Runbook creation
  3. Systems Manager OpsCenter for incident response
  4. SageMaker AI notebooks for incident response
  5. Provisioning access for incident response
  6. Deploying security tools
  7. Minimizing blast radius
  8. Configuring AWS Shield Advanced protections
  9. Testing incident response plans
  10. AWS Fault Injection Service for incident response testing
  11. AWS Resilience Hub for incident response validation
  12. Automated remediation with Systems Manager
  13. Automated Forensics Orchestrator for Amazon EC2
  14. AWS Step Functions for incident response orchestration
  15. Amazon Application Recovery Controller for incident response
  16. Lambda functions for automated remediation

Task 2.2: Respond to security events

7 concepts · 25 questions
  1. Forensic log capture
  2. Log storage and retention
  3. Log search and correlation
  4. Validating security findings
  5. Containment controls
  6. Eradication and recovery
  7. Root cause analysis methods

  1. Edge Security Strategy Selection
  2. CloudFront Headers and Security
  3. AWS WAF Implementation
  4. AWS IoT Policies for Edge Security
  5. S3 CORS Configuration
  6. AWS Shield Advanced Deployment
  7. Geographic and Geolocation Controls
  8. Rate Limiting at the Edge
  9. Client Fingerprinting
  10. Edge Service Integration with Third-Party WAF
  11. Open Cybersecurity Schema Framework (OCSF) Integration
  1. Hardened AMI Design
  2. Container Image Hardening
  3. EC2 Image Builder Pipelines
  4. Instance Profiles for EC2
  5. Service Roles for AWS Services
  6. Execution Roles for Compute
  7. Amazon Inspector Vulnerability Scanning
  8. GuardDuty Runtime Monitoring
  9. Patch Management with Systems Manager
  10. Continuous Compliance Validation
  11. Systems Manager Session Manager
  12. EC2 Instance Connect
  13. Pipeline Security Scanning
  14. Amazon Q Developer Security
  15. Amazon CodeGuru Security
  16. GenAI OWASP Top 10 Protections
  17. Guardrails for Generative AI
  1. Security Groups vs Network ACLs
  2. AWS Network Firewall
  3. Site-to-Site VPN and Direct Connect
  4. MACsec on Direct Connect
  5. AWS Verified Access
  6. Network Segmentation and Traffic Flow
  7. Network Access Analyzer
  8. Amazon Inspector Network Reachability

  1. IAM Identity Center for human authentication
  2. Amazon Cognito for application authentication
  3. MFA enforcement and configuration
  4. Identity provider integration
  5. System and application authentication mechanisms
  6. AWS STS and temporary credentials
  7. Amazon S3 presigned URLs
  8. Troubleshooting authentication with CloudTrail
  9. Troubleshooting Cognito authentication issues
  10. Troubleshooting IAM Identity Center permission sets
  11. Troubleshooting AWS Directory Service authentication
  1. Authorization Controls for Human, Application, and System Access
  2. ABAC and RBAC Strategies
  3. IAM Policies and Least Privilege
  4. Analyzing Authorization Failures
  5. Investigating and Correcting Unintended Permissions

  1. ELB security policies
  2. TLS enforcement configurations
  3. AWS PrivateLink
  4. VPC endpoints
  5. AWS Client VPN
  6. AWS Verified Access
  7. Inter-node encryption for Amazon EMR
  8. Inter-node encryption for Amazon EKS
  9. Inter-node encryption for SageMaker AI
  10. Nitro encryption
  1. AWS KMS vs AWS CloudHSM
  2. Server-Side Encryption (SSE)
  3. Client-Side Encryption
  4. S3 Object Lock
  5. S3 Glacier Vault Lock
  6. S3 Versioning
  7. Digital Code Signing and File Validation
  8. S3 Lifecycle Policies
  9. Amazon EFS Lifecycle Policies
  10. Amazon FSx for Lustre Backup Policies
  11. Amazon Data Lifecycle Manager (DLM)
  12. AWS Backup
  13. Ransomware Protection
  14. AWS DataSync
  1. AWS Secrets Manager basics
  2. Secret rotation strategies
  3. Secret retrieval and access control
  4. Importing key material into KMS
  5. Managing imported key material
  6. Rotating imported key material
  7. External key stores (XKS)
  8. Comparing imported vs AWS-generated key material
  9. CloudWatch Logs data protection
  10. SNS message data protection
  11. Creating and managing KMS keys
  12. Multi-Region KMS keys
  13. AWS Private Certificate Authority (PCA)
  14. Certificate lifecycle management

  1. AWS Organizations fundamentals
  2. Creating and managing an organization
  3. AWS Control Tower setup
  4. Control Tower controls
  5. Service control policies (SCPs)
  6. Resource control policies (RCPs)
  7. AI service opt-out policies
  8. Declarative policies
  9. Delegated administrator accounts
  10. Centralized security service management
  11. Root user credential management
  12. Root user MFA enforcement
  13. Break-glass procedures
  1. Infrastructure as Code (IaC) Fundamentals
  2. AWS CloudFormation Stack Sets
  3. Third-Party IaC Tools
  4. CloudFormation Guard
  5. cfn-lint
  6. Tagging Strategies for Resource Organization
  7. Centralized Policy and Configuration Deployment
  8. AWS Firewall Manager
  9. AWS Service Catalog for Secure Resource Sharing
  10. AWS Resource Access Manager (RAM)
  1. AWS Config rules
  2. AWS Config remediation actions
  3. AWS Config notifications
  4. AWS Security Hub
  5. AWS Audit Manager
  6. AWS Artifact
  7. Architecture evaluation for compliance
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for SCS-C03, so none is invented.