
AWS Certified Security - Specialty
The AWS Certified Security - Specialty certification validates your expertise in creating and implementing security solutions in the AWS Cloud. It covers specialized data classifications, data protection mechanisms, encryption methods, and secure internet protocols. This certification is for experienced security professionals who design and secure AWS workloads and architectures, positioning you as a trusted advisor to stakeholders and customers.
462 practice questions · Updated 2026-07-30
6Domains
16Objectives
172Concepts
462Questions
SCS-C03 Curriculum
Every domain, objective, and concept the SCS-C03 exam measures.
- Workload Monitoring Requirements Analysis
- Workload Monitoring Strategy Design
- Security Event Aggregation
- Metrics, Alerts, and Dashboards
- Automated Assessments and Investigations
- Identify log sources for ingestion
- Evaluate log storage requirements
- Configure CloudTrail for organization
- Set up dedicated CloudWatch logging account
- Configure CloudWatch Logs agent
- Implement log data lakes with Security Lake
- Integrate logs with third-party security tools
- Analyze logs with CloudWatch Logs Insights
- Analyze logs with Amazon Athena
- Use Security Hub findings for log analysis
- Normalize and parse logs with OpenSearch Service
- Use Lambda for log processing
- Visualize logs with Managed Grafana
- Correlate logs across sources
- Select log sources based on network design
- Configure VPC Flow Logs
- Configure transit gateway flow logs
- Configure Route 53 Resolver logs
- Lambda function logging analysis
- API Gateway logging analysis
- Health checks analysis
- CloudFront logging analysis
- CloudWatch Agent configuration troubleshooting
- Missing logs remediation
- Incident response plan design
- Runbook creation
- Systems Manager OpsCenter for incident response
- SageMaker AI notebooks for incident response
- Provisioning access for incident response
- Deploying security tools
- Minimizing blast radius
- Configuring AWS Shield Advanced protections
- Testing incident response plans
- AWS Fault Injection Service for incident response testing
- AWS Resilience Hub for incident response validation
- Automated remediation with Systems Manager
- Automated Forensics Orchestrator for Amazon EC2
- AWS Step Functions for incident response orchestration
- Amazon Application Recovery Controller for incident response
- Lambda functions for automated remediation
- Forensic log capture
- Log storage and retention
- Log search and correlation
- Validating security findings
- Containment controls
- Eradication and recovery
- Root cause analysis methods
- Edge Security Strategy Selection
- CloudFront Headers and Security
- AWS WAF Implementation
- AWS IoT Policies for Edge Security
- S3 CORS Configuration
- AWS Shield Advanced Deployment
- Geographic and Geolocation Controls
- Rate Limiting at the Edge
- Client Fingerprinting
- Edge Service Integration with Third-Party WAF
- Open Cybersecurity Schema Framework (OCSF) Integration
- Hardened AMI Design
- Container Image Hardening
- EC2 Image Builder Pipelines
- Instance Profiles for EC2
- Service Roles for AWS Services
- Execution Roles for Compute
- Amazon Inspector Vulnerability Scanning
- GuardDuty Runtime Monitoring
- Patch Management with Systems Manager
- Continuous Compliance Validation
- Systems Manager Session Manager
- EC2 Instance Connect
- Pipeline Security Scanning
- Amazon Q Developer Security
- Amazon CodeGuru Security
- GenAI OWASP Top 10 Protections
- Guardrails for Generative AI
- Security Groups vs Network ACLs
- AWS Network Firewall
- Site-to-Site VPN and Direct Connect
- MACsec on Direct Connect
- AWS Verified Access
- Network Segmentation and Traffic Flow
- Network Access Analyzer
- Amazon Inspector Network Reachability
- IAM Identity Center for human authentication
- Amazon Cognito for application authentication
- MFA enforcement and configuration
- Identity provider integration
- System and application authentication mechanisms
- AWS STS and temporary credentials
- Amazon S3 presigned URLs
- Troubleshooting authentication with CloudTrail
- Troubleshooting Cognito authentication issues
- Troubleshooting IAM Identity Center permission sets
- Troubleshooting AWS Directory Service authentication
- Authorization Controls for Human, Application, and System Access
- ABAC and RBAC Strategies
- IAM Policies and Least Privilege
- Analyzing Authorization Failures
- Investigating and Correcting Unintended Permissions
- ELB security policies
- TLS enforcement configurations
- AWS PrivateLink
- VPC endpoints
- AWS Client VPN
- AWS Verified Access
- Inter-node encryption for Amazon EMR
- Inter-node encryption for Amazon EKS
- Inter-node encryption for SageMaker AI
- Nitro encryption
- AWS KMS vs AWS CloudHSM
- Server-Side Encryption (SSE)
- Client-Side Encryption
- S3 Object Lock
- S3 Glacier Vault Lock
- S3 Versioning
- Digital Code Signing and File Validation
- S3 Lifecycle Policies
- Amazon EFS Lifecycle Policies
- Amazon FSx for Lustre Backup Policies
- Amazon Data Lifecycle Manager (DLM)
- AWS Backup
- Ransomware Protection
- AWS DataSync
- AWS Secrets Manager basics
- Secret rotation strategies
- Secret retrieval and access control
- Importing key material into KMS
- Managing imported key material
- Rotating imported key material
- External key stores (XKS)
- Comparing imported vs AWS-generated key material
- CloudWatch Logs data protection
- SNS message data protection
- Creating and managing KMS keys
- Multi-Region KMS keys
- AWS Private Certificate Authority (PCA)
- Certificate lifecycle management
- AWS Organizations fundamentals
- Creating and managing an organization
- AWS Control Tower setup
- Control Tower controls
- Service control policies (SCPs)
- Resource control policies (RCPs)
- AI service opt-out policies
- Declarative policies
- Delegated administrator accounts
- Centralized security service management
- Root user credential management
- Root user MFA enforcement
- Break-glass procedures
- Infrastructure as Code (IaC) Fundamentals
- AWS CloudFormation Stack Sets
- Third-Party IaC Tools
- CloudFormation Guard
- cfn-lint
- Tagging Strategies for Resource Organization
- Centralized Policy and Configuration Deployment
- AWS Firewall Manager
- AWS Service Catalog for Secure Resource Sharing
- AWS Resource Access Manager (RAM)
- AWS Config rules
- AWS Config remediation actions
- AWS Config notifications
- AWS Security Hub
- AWS Audit Manager
- AWS Artifact
- Architecture evaluation for compliance
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for SCS-C03, so none is invented.