HomeRoadmaps › AWS SCS-C03
Specialty certification roadmap

AWS Certified Security - Specialty (SCS-C03)

A five-phase path for the active AWS Security Specialty exam: multi-account detection, tested incident response, edge and network controls, temporary identity and least privilege, cryptographic and data controls, plus secure governance at organization scale.

Exam code: SCS-C03 Six official domains Suggested plan: 10–14 weeks Published: August 19, 2026
Use the current AWS exam guide as the source of truth. AWS describes the target candidate as having the equivalent of 3–5 years securing cloud solutions. The exam includes multiple-choice, multiple-response, ordering, and matching questions; 50 questions affect the score and 15 are unscored. The reported score range is 100–1,000 and the minimum passing score is 750. Recheck exam logistics, scope, services, and pricing before scheduling or building a lab.
This is SCS-C03, not the existing SCS-C02 course. AWS states that SCS-C02 was used until December 1, 2025 and SCS-C03 began December 2, 2025. The new blueprint restructures Detection and Incident Response, weights IAM at 20% and Infrastructure Security at 18%, renames Domain 6, and adds finding validation, edge/OCSF integrations, generative AI guardrails, inter-resource encryption, imported-key distinctions, sensitive-data masking, and multi-Region key/certificate management. Keep older SCS-C02 materials separate.

Official SCS-C03 domains

The official guide validates the ability to secure AWS products and services, choose among cost, security, and deployment-complexity trade-offs, implement data protection and secure protocols, and understand security operations and risks.

Official content domainWeight
Content Domain 1: Detection16%
Content Domain 2: Incident Response14%
Content Domain 3: Infrastructure Security18%
Content Domain 4: Identity and Access Management20%
Content Domain 5: Data Protection18%
Content Domain 6: Security Foundations and Governance14%
1

Detection, logging, and finding validation

Weeks 1–2

Build evidence before automation. Learn which source answers which question, how coverage scales across accounts and Regions, and how to distinguish a finding from a proven incident.

  • Design organization CloudTrail and dedicated log-archive patterns
  • Distinguish management, data, Insights, and network log sources
  • Configure S3/KMS delivery policies, validation, retention, and mutation alerts
  • Use VPC Flow Logs, transit gateway flow logs, and Route 53 Resolver query logs deliberately
  • Centralize GuardDuty administration and understand protection-plan coverage
  • Use Security Hub central configuration, standards, automation rules, and finding aggregation
  • Compare Security Hub findings, Security Lake OCSF data, and Detective investigations
  • Use Macie for scoped S3 classification and sensitive-data findings
  • Troubleshoot missing logs from selectors, permissions, resources, Regions, agents, and delivery paths
  • Validate actor, API, resource, network, time, severity, scope, and impact before remediation
2

Incident readiness, containment, forensics, and recovery

Weeks 3–4

Practice a complete response lifecycle with synthetic findings and disposable resources. Access, evidence destinations, isolation, recovery, and communications must exist before the alarm.

  • Design runbooks, escalation, severity, ownership, communications, and legal/evidence decisions
  • Pre-provision cross-account response roles, evidence KMS access, and break-glass paths
  • Test plans through game days, sample findings, and authorized fault exercises
  • Route findings with EventBridge and add approval-aware Systems Manager, Lambda, or Step Functions automation
  • Make response actions least-privilege, idempotent, bounded, reversible, and fully logged
  • Contain disposable EC2 resources without immediately destroying volatile evidence
  • Capture approved logs, snapshots, memory, metadata, and timelines with chain-of-custody
  • Use Detective and log correlation to find related identities, resources, connections, and root cause
  • Revoke synthetic credentials and remove persistence before recovery
  • Restore from a trusted source, monitor the recovered workload, and conduct lessons learned
3

Infrastructure and application security

Weeks 5–7

Protect distinct layers with the right controls: web requests at the edge, routed flows in the network, and workload identity, patching, vulnerability, and administrative paths on compute.

  • Protect CloudFront, ALB, API endpoints, and other supported resources with AWS WAF
  • Stage managed/custom WAF rules in Count, use labels and rate rules, inspect logs, then enforce
  • Understand Shield Standard versus Shield Advanced capabilities and response requirements
  • Evaluate third-party WAF rules and OCSF-compatible edge/security integrations
  • Design security groups, stateless network ACLs, private subnets, and VPC endpoints
  • Route traffic symmetrically through Network Firewall endpoints and test every Availability Zone
  • Design segmentation, Transit Gateway inspection, centralized egress, VPN, Direct Connect, and MACsec requirements
  • Use Verified Access for identity-aware application access where appropriate
  • Build hardened AMIs/images, patch with Systems Manager, scan with Inspector, and use GuardDuty runtime coverage where applicable
  • Administer EC2 through Session Manager without public SSH or persistent keys
  • Apply least-privilege service and execution roles to EC2, Lambda, ECS, EKS, and pipelines
  • Threat-model generative AI prompt injection, tool misuse, data boundaries, output trust, and excessive agency
4

Identity, authorization, and data protection

Weeks 8–10

This phase joins the two 18–20% domains. Follow a request from human or workload authentication through every policy layer to encrypted data, secrets, keys, certificates, backups, and retention.

  • Federate workforce users with IAM Identity Center, groups, MFA policy, permission sets, and temporary sessions
  • Use Cognito for application identities and STS, role sessions, Roles Anywhere, or presigned URLs for temporary credentials
  • Design cross-account trust and external IDs for third-party confused-deputy scenarios
  • Apply RBAC, trusted ABAC attributes, permission boundaries, session policies, and resource policies
  • Use IAM Access Analyzer, policy validation, simulation, CloudTrail, and denial context to troubleshoot
  • Understand union/intersection logic, explicit deny, SCPs, RCPs, key policies, grants, and service control boundaries
  • Require supported TLS policies, private connectivity, and service-specific inter-node encryption
  • Compare SSE-S3, SSE-KMS, client-side envelope encryption, KMS, CloudHSM, and external key stores
  • Distinguish AWS-generated and imported KMS key material, expiration, backup, reimport, and availability
  • Use key policies, aliases, grants, encryption context, rotation, deletion windows, and multi-Region keys safely
  • Protect secrets with Secrets Manager rotation and certificates with ACM or AWS Private CA where required
  • Use versioning, Object Lock, lifecycle, replication, AWS Backup, and tested restore for integrity and resilience
  • Discover sensitive S3 data with Macie and mask log or SNS data using supported protection policies
5

Governance, secure deployment, compliance, and readiness

Weeks 11–14

Finish at organization scale. A secure configuration must survive account creation, code deployment, drift, exceptions, audits, incidents, and cost review.

  • Design OUs, management/security/log-archive accounts, delegated administrators, and root-access procedures
  • Use SCPs, RCPs, tag policies, AI service opt-out policies, and declarative policies for their intended purposes
  • Apply AWS Control Tower controls to new or existing environments where appropriate
  • Deploy baselines with CloudFormation StackSets and validate IaC with CloudFormation Guard and linting
  • Use Firewall Manager to centrally manage supported WAF, Shield, security group, DNS, and Network Firewall policies
  • Share approved resources with Service Catalog and AWS RAM rather than unmanaged copies
  • Evaluate resources with Config organization rules, conformance packs, aggregators, and bounded remediation
  • Use Audit Manager to organize evidence and Artifact for AWS compliance reports and agreements
  • Use the Well-Architected Tool and security best practices without confusing review with automatic compliance
  • Run the two synthetic portfolio projects and complete cost and deletion rehearsals
  • Answer timed original questions across all response types and explain every distractor from AWS documentation
  • Recheck the official guide, in-scope services, updates, exam logistics, and current AWS service behavior

PrepKloud SCS-C03 study surfaces

Official AWS sources

SCS-C03 exam guide

Confirm target candidate, response types, scoring, exact domain weights, tasks, and services.

Open AWS exam guide
SCS-C02 to SCS-C03 comparison

Review dates, weight changes, additions, deletions, and recategorized objectives.

Open official comparison
Detection domain

Review monitoring, alerting, organization logging, analysis, normalization, and troubleshooting.

Open Domain 1
Incident Response domain

Review plans, testing, automated remediation, evidence, finding validation, containment, and root cause.

Open Domain 2
Identity and Access Management domain

Review human/workload authentication, temporary credentials, policy design, ABAC/RBAC, and authorization diagnosis.

Open Domain 4
Data Protection domain

Review transit/at-rest controls, integrity, backups, imported keys, masking, secrets, certificates, and multi-Region management.

Open Domain 5

Frequently asked questions

Is SCS-C03 the active AWS Security Specialty exam?

Yes. AWS says SCS-C03 began use on December 2, 2025. SCS-C02 was in use until December 1, 2025. Use current SCS-C03 domain names, weights, tasks, and additions.

What are the six official weights?

Detection 16%, Incident Response 14%, Infrastructure Security 18%, Identity and Access Management 20%, Data Protection 18%, and Security Foundations and Governance 14% of scored content.

What changed from SCS-C02?

Detection and Incident Response were restructured; IAM rose to 20%; Infrastructure Security became 18%; Domain 6 was renamed. New content includes finding validation, OCSF/edge integrations, generative AI guardrails, internal encryption, imported-key differences, masking, and multi-Region key/certificate management.

How much experience does AWS recommend?

The official target candidate has the equivalent of 3–5 years of experience securing cloud solutions, including identity at scale, multi-account governance, incident response, vulnerability management, firewall rules, audits, logging, encryption, and recovery controls.

Are these materials exam dumps?

No. PrepKloud creates original scenarios and projects from public objectives and AWS documentation. No live, recalled, leaked, proprietary, or marketplace questions are used, and no passing result is guaranteed.

Integrity and independence: Use authorized labs, synthetic findings and data, original practice, and official AWS documentation. Do not seek, share, or memorize recalled live-exam content. PrepKloud is independent and is not affiliated with or endorsed by Amazon Web Services. AWS product and certification names belong to their respective owner.

Turn SCS-C03 knowledge into security evidence

Diagnose gaps with questions, reinforce distinctions with flashcards, then build and tear down both synthetic multi-account projects.