AWS Certified Security – Specialty (SCS-C03) Study Guide: Domains and Study Plan

An AWS SCS-C03 guide covering the six exam domains, detection and response, and a practical preparation plan.

The AWS Certified Security – Specialty (SCS-C03) exam is for security professionals responsible for protecting cloud solutions. It covers threat detection, incident response, infrastructure security, identity and access management, data protection, and security foundations and governance. SCS-C03 reorganized the domains from SCS-C02, so prepare with the current guide.

Use the latest AWS SCS-C03 exam guide as your source of truth.

Who is this exam for? What background helps?

The exam suits cloud security, compliance, and security operations engineers, as well as architects responsible for security baselines or incident response. AWS describes its target candidate as having roughly three to five years of experience securing cloud solutions; this is a profile, not a registration requirement. First become comfortable with the IAM, VPC, encryption, and logging foundations in SAA-C03.

SAA-C03 treats security as one part of architecture design. SCS-C03 goes deeper into controls, investigations, and governance.

Exam domains and weights

Domain Official name Main focus Weight
1 Detection Monitoring, logging, and threat discovery 16%
2 Incident Response Plans, containment, recovery, and lessons learned 14%
3 Infrastructure Security Network edge, compute, and infrastructure protection 18%
4 Identity and Access Management Identity, permissions, and access at scale 20%
5 Data Protection Data classification, encryption, and privacy 18%
6 Security Foundations and Governance Shared responsibility, governance, and security foundations 14%

Identity and Access Management has the largest weight, but detection, infrastructure, and data protection also account for substantial content. SCS-C03 separates detection and incident response into two domains; do not reuse the old SCS-C02 grouping.

How to study each domain

Domain 1: Detection

Learn to design monitoring and alarms for accounts or organizations, collect and analyze logs, and troubleshoot detection, logging, and alerting configurations.

Common mix-up: assuming that enabling a threat-detection service completes monitoring. Explain where signals come from, how they map to resources, and what investigation follows an alert.

Domain 2: Incident Response

Understand how to create and test response plans, investigate security events, contain impact, restore services, and improve the process afterward.

Common mix-up: isolating resources without preserving evidence or assessing business impact. Map the decision sequence: identify, contain, investigate, recover, and review.

Domain 3: Infrastructure Security

Focus on designing, implementing, and troubleshooting controls for network edges, compute workloads, and network security.

Common mix-up: treating WAF, network firewalls, security groups, and network ACLs as the same layer. Choose controls based on traffic location and protection goals, then validate allowed and denied paths.

Domain 4: Identity and Access Management

Study human and workload identities, permission boundaries, cross-account access, and credential lifecycles.

Common mix-up: calling a policy least privilege while overlooking trust relationships, privilege escalation paths, or temporary credential lifetimes. Trace how an identity receives permission and where it can pass that permission.

Domain 5: Data Protection

Choose classification, encryption, key management, masking, and access controls based on data sensitivity. Consider data in transit, at rest, in backups, and in logs.

Common mix-up: checking only encryption at rest while ignoring key access, transport protection, backups, or sensitive data in logs. Review the full data lifecycle.

Domain 6: Security Foundations and Governance

Understand how shared responsibility, multi-account governance, security policies, and risk management apply to AWS environments.

Common mix-up: having policy documents without continuous checks or exception handling. Turn each governance requirement into a verifiable control, owner, and audit record.

Check your readiness with three questions

  1. After an unusual sign-in alert, how do you trace the identity, resources, and related logs?
  2. During an incident, when do you isolate, how do you preserve evidence, and what must be verified before recovery?
  3. How do you limit access across multiple accounts while retaining an auditable record?

Suggested study order

  1. Identity and access management, shared responsibility, and multi-account governance.
  2. Detection, log analysis, and incident response.
  3. Network and compute infrastructure protection.
  4. Data classification, encryption, keys, and privacy.
  5. Convert controls into continuous validation and audit processes.

A three-step preparation plan

  1. Use the SCS-C03 guide. Review tasks in all six current domains instead of relying on the SCS-C02 outline.
  2. Practice the full security-event lifecycle. Explain the evidence and permissions from signal through investigation, containment, recovery, and audit.
  3. Practice and review. Group misses by domain and decide whether the issue was control selection, investigation order, or a missed governance requirement.

Start practicing

When you are ready, use exam code SCS-C03 to practice by domain, then review weak areas against the official skill statements.

WeChat mini program

IT知习 mini program QR code

Search WeChat for: IT知习