Master AWS security architecture, incident response, data protection, and compliance. Become an expert in securing AWS workloads and achieving regulatory compliance.
AWS Security Specialists design and implement secure AWS architectures, respond to security incidents, ensure compliance with industry standards, and protect sensitive data. You'll implement threat detection and monitoring, configure identity and access management, encrypt data at rest and in transit, and maintain security governance across multi-account AWS environments.
Solutions Architect
Recommended FoundationSecurity Specialty
After Phase 6The AWS Certified Security - Specialty (SCS-C02) exam tests your knowledge across six key domains:
This is an advanced specialty certification. You should have solid AWS foundational knowledge and hands-on security experience before starting.
If you're new to AWS Security:
→Complete AWS Solutions Architect Associate (SAA-C03) first
→Then begin with Phase 1: Incident Response (expand below)
→Gain hands-on experience with AWS security services
→Focus on one phase at a time — finish it completely before moving forward
Already have AWS security experience?
→Jump to the phase that matches your current skill level
→Focus on filling knowledge gaps identified in your practice exams
Threat detection, finding types, ML-based analysis, suppression rules, EventBridge integration
Centralized security findings, compliance standards, automated remediation, security score
Investigation workflows, behavior graphs, root cause analysis, relationship visualization
Preparation, detection, containment, eradication, recovery, lessons learned
API logging, log file validation, organizational trails, Insights events, integration with CloudWatch
Security monitoring, metric filters, anomaly detection, VPC Flow Logs analysis
Compliance monitoring, Config rules, remediation actions, conformance packs for compliance frameworks
Security Groups, NACLs, VPC Flow Logs, network segmentation, PrivateLink, endpoints
Managed network firewall, stateful/stateless rules, IPS/IDS, domain filtering, TLS inspection
Web ACLs, managed rule groups, rate limiting, bot control, integration with CloudFront and ALB
DDoS protection, Shield Standard vs Advanced, DDoS Response Team, cost protection
Policy types, evaluation logic, cross-account access, permission boundaries, best practices
External access identification, policy validation, policy generation from CloudTrail
Service Control Policies, multi-account strategy, centralized security, tag policies
Centralized SSO, permission sets, Active Directory integration, Cognito for application auth
Key types, key policies, envelope encryption, key rotation, multi-region keys, grants
Dedicated HSM, FIPS 140-2 Level 3, single-tenant, use cases vs KMS
Secret storage, automatic rotation, versioning, cross-region replication, integration with RDS
Sensitive data discovery in S3, PII detection, data classification, findings integration
Bucket policies, encryption options, Block Public Access, Object Lock, versioning, MFA Delete
Landing Zone, guardrails (preventive SCPs, detective Config rules), Account Factory
Centralized firewall management across accounts, WAF, Shield, Security Groups, Network Firewall
Automated evidence collection, pre-built frameworks (GDPR, PCI-DSS, HIPAA), assessment reports
SCS-C02: AWS Certified Security - Specialty
This specialty certification validates your expertise in securing AWS workloads, implementing incident response, managing identity and access, protecting data, and ensuring compliance. Focus areas: Threat Detection (14%), Logging & Monitoring (18%), Infrastructure Security (20%), IAM (22%), Data Protection (26%). Exam: 170 minutes, 65 questions, $300 USD, passing score 750/1000.
Practice SCS-C02 QuestionsUse GuardDuty, Security Hub, and Detective to detect, investigate, and respond to security threats
Configure CloudTrail, VPC Flow Logs, and CloudWatch for security monitoring and compliance
Design secure VPCs, configure WAF and Shield, implement Network Firewall for traffic inspection
Design least-privilege IAM policies, implement SCPs, configure SSO and cross-account access
Implement KMS encryption, manage secrets with Secrets Manager, use Macie for data classification
Validate your AWS security expertise at the specialty level with industry recognition