AWS Security Specialty

Master AWS security architecture, incident response, data protection, and compliance. Become an expert in securing AWS workloads and achieving regulatory compliance.

⏱️ 12-14 weeks
📊 6 Phases
🎓 SCS-C02 Certification
💼 Specialty Level
🎯 Specialty Level Certification

What Does an AWS Security Specialist Do?

AWS Security Specialists design and implement secure AWS architectures, respond to security incidents, ensure compliance with industry standards, and protect sensitive data. You'll implement threat detection and monitoring, configure identity and access management, encrypt data at rest and in transit, and maintain security governance across multi-account AWS environments.

Is This Roadmap For You?

📜 Recommended Certification Path

SAA-C03

Solutions Architect

Recommended Foundation

SCS-C02

Security Specialty

After Phase 6

📋 SCS-C02 Exam Syllabus Overview

The AWS Certified Security - Specialty (SCS-C02) exam tests your knowledge across six key domains:

14%
Incident Response
  • Design and implement incident response plans
  • Detect security threats and anomalies
  • Respond to compromised resources
16%
Logging and Monitoring
  • Design and implement logging solutions
  • Troubleshoot security monitoring and alerting
  • Analyze logs for security events
20%
Infrastructure Security
  • Design edge security on AWS
  • Design and implement network security
  • Design and implement compute resource security
20%
Identity and Access Management
  • Design and implement authentication and authorization
  • Troubleshoot authentication and authorization
  • Implement AWS Organizations for multi-account security
18%
Data Protection
  • Design and implement data encryption at rest
  • Design and implement data encryption in transit
  • Implement key management and rotation
12%
Management and Security Governance
  • Develop governance and compliance strategies
  • Automate security response
  • Assess security posture and recommend improvements

🚀 Start Here

This is an advanced specialty certification. You should have solid AWS foundational knowledge and hands-on security experience before starting.

If you're new to AWS Security:

Complete AWS Solutions Architect Associate (SAA-C03) first

Then begin with Phase 1: Incident Response (expand below)

Gain hands-on experience with AWS security services

Focus on one phase at a time — finish it completely before moving forward

Already have AWS security experience?

Jump to the phase that matches your current skill level

Focus on filling knowledge gaps identified in your practice exams

1
Incident Response
3-4 weeks
CRITICAL
🛡️ Amazon GuardDuty

Threat detection, finding types, ML-based analysis, suppression rules, EventBridge integration

CRITICAL
🔍 AWS Security Hub

Centralized security findings, compliance standards, automated remediation, security score

IMPORTANT
🔎 Amazon Detective

Investigation workflows, behavior graphs, root cause analysis, relationship visualization

CRITICAL
🚨 Incident Response Best Practices

Preparation, detection, containment, eradication, recovery, lessons learned

2
Logging & Monitoring
3-4 weeks
CRITICAL
📝 AWS CloudTrail

API logging, log file validation, organizational trails, Insights events, integration with CloudWatch

IMPORTANT
📊 Amazon CloudWatch

Security monitoring, metric filters, anomaly detection, VPC Flow Logs analysis

CRITICAL
⚙️ AWS Config

Compliance monitoring, Config rules, remediation actions, conformance packs for compliance frameworks

3
Infrastructure Security
4-5 weeks
CRITICAL
🌐 VPC Security

Security Groups, NACLs, VPC Flow Logs, network segmentation, PrivateLink, endpoints

IMPORTANT
🔥 AWS Network Firewall

Managed network firewall, stateful/stateless rules, IPS/IDS, domain filtering, TLS inspection

CRITICAL
🛡️ AWS WAF

Web ACLs, managed rule groups, rate limiting, bot control, integration with CloudFront and ALB

IMPORTANT
🔰 AWS Shield

DDoS protection, Shield Standard vs Advanced, DDoS Response Team, cost protection

4
Identity & Access Management
4-5 weeks
CRITICAL
🔐 IAM Deep Dive

Policy types, evaluation logic, cross-account access, permission boundaries, best practices

IMPORTANT
🔍 IAM Access Analyzer

External access identification, policy validation, policy generation from CloudTrail

CRITICAL
🏢 AWS Organizations

Service Control Policies, multi-account strategy, centralized security, tag policies

IMPORTANT
👤 AWS SSO & Directory Services

Centralized SSO, permission sets, Active Directory integration, Cognito for application auth

5
Data Protection
4-5 weeks
CRITICAL
🔑 AWS KMS

Key types, key policies, envelope encryption, key rotation, multi-region keys, grants

IMPORTANT
🔒 AWS CloudHSM

Dedicated HSM, FIPS 140-2 Level 3, single-tenant, use cases vs KMS

CRITICAL
🔐 AWS Secrets Manager

Secret storage, automatic rotation, versioning, cross-region replication, integration with RDS

IMPORTANT
🔍 Amazon Macie

Sensitive data discovery in S3, PII detection, data classification, findings integration

CRITICAL
📦 S3 Security

Bucket policies, encryption options, Block Public Access, Object Lock, versioning, MFA Delete

6
Management & Security Governance
2-3 weeks
IMPORTANT
🏗️ AWS Control Tower

Landing Zone, guardrails (preventive SCPs, detective Config rules), Account Factory

IMPORTANT
🔥 AWS Firewall Manager

Centralized firewall management across accounts, WAF, Shield, Security Groups, Network Firewall

IMPORTANT
📋 AWS Audit Manager

Automated evidence collection, pre-built frameworks (GDPR, PCI-DSS, HIPAA), assessment reports

🎓 Target Certification

SCS-C02: AWS Certified Security - Specialty

This specialty certification validates your expertise in securing AWS workloads, implementing incident response, managing identity and access, protecting data, and ensuring compliance. Focus areas: Threat Detection (14%), Logging & Monitoring (18%), Infrastructure Security (20%), IAM (22%), Data Protection (26%). Exam: 170 minutes, 65 questions, $300 USD, passing score 750/1000.

Practice SCS-C02 Questions

🎯 You're Job-Ready When You Can:

✅ Respond to Security Incidents

Use GuardDuty, Security Hub, and Detective to detect, investigate, and respond to security threats

✅ Implement Comprehensive Logging

Configure CloudTrail, VPC Flow Logs, and CloudWatch for security monitoring and compliance

✅ Secure Infrastructure

Design secure VPCs, configure WAF and Shield, implement Network Firewall for traffic inspection

✅ Manage Identity & Access

Design least-privilege IAM policies, implement SCPs, configure SSO and cross-account access

✅ Protect Sensitive Data

Implement KMS encryption, manage secrets with Secrets Manager, use Macie for data classification

✅ Pass SCS-C02 Certification

Validate your AWS security expertise at the specialty level with industry recognition