AWS Certified Security – Specialty (SCS-C03) Study Guide: Domains and Study Plan
An AWS SCS-C03 guide covering the six exam domains, detection and response, and a practical preparation plan.
The AWS Certified Security – Specialty (SCS-C03) exam is for security professionals responsible for protecting cloud solutions. It covers threat detection, incident response, infrastructure security, identity and access management, data protection, and security foundations and governance. SCS-C03 reorganized the domains from SCS-C02, so prepare with the current guide.
Use the latest AWS SCS-C03 exam guide as your source of truth.
Who is this exam for? What background helps?
The exam suits cloud security, compliance, and security operations engineers, as well as architects responsible for security baselines or incident response. AWS describes its target candidate as having roughly three to five years of experience securing cloud solutions; this is a profile, not a registration requirement. First become comfortable with the IAM, VPC, encryption, and logging foundations in SAA-C03.
SAA-C03 treats security as one part of architecture design. SCS-C03 goes deeper into controls, investigations, and governance.
Exam domains and weights
| Domain | Official name | Main focus | Weight |
|---|---|---|---|
| 1 | Detection | Monitoring, logging, and threat discovery | 16% |
| 2 | Incident Response | Plans, containment, recovery, and lessons learned | 14% |
| 3 | Infrastructure Security | Network edge, compute, and infrastructure protection | 18% |
| 4 | Identity and Access Management | Identity, permissions, and access at scale | 20% |
| 5 | Data Protection | Data classification, encryption, and privacy | 18% |
| 6 | Security Foundations and Governance | Shared responsibility, governance, and security foundations | 14% |
Identity and Access Management has the largest weight, but detection, infrastructure, and data protection also account for substantial content. SCS-C03 separates detection and incident response into two domains; do not reuse the old SCS-C02 grouping.
How to study each domain
Domain 1: Detection
Learn to design monitoring and alarms for accounts or organizations, collect and analyze logs, and troubleshoot detection, logging, and alerting configurations.
Common mix-up: assuming that enabling a threat-detection service completes monitoring. Explain where signals come from, how they map to resources, and what investigation follows an alert.
Domain 2: Incident Response
Understand how to create and test response plans, investigate security events, contain impact, restore services, and improve the process afterward.
Common mix-up: isolating resources without preserving evidence or assessing business impact. Map the decision sequence: identify, contain, investigate, recover, and review.
Domain 3: Infrastructure Security
Focus on designing, implementing, and troubleshooting controls for network edges, compute workloads, and network security.
Common mix-up: treating WAF, network firewalls, security groups, and network ACLs as the same layer. Choose controls based on traffic location and protection goals, then validate allowed and denied paths.
Domain 4: Identity and Access Management
Study human and workload identities, permission boundaries, cross-account access, and credential lifecycles.
Common mix-up: calling a policy least privilege while overlooking trust relationships, privilege escalation paths, or temporary credential lifetimes. Trace how an identity receives permission and where it can pass that permission.
Domain 5: Data Protection
Choose classification, encryption, key management, masking, and access controls based on data sensitivity. Consider data in transit, at rest, in backups, and in logs.
Common mix-up: checking only encryption at rest while ignoring key access, transport protection, backups, or sensitive data in logs. Review the full data lifecycle.
Domain 6: Security Foundations and Governance
Understand how shared responsibility, multi-account governance, security policies, and risk management apply to AWS environments.
Common mix-up: having policy documents without continuous checks or exception handling. Turn each governance requirement into a verifiable control, owner, and audit record.
Check your readiness with three questions
- After an unusual sign-in alert, how do you trace the identity, resources, and related logs?
- During an incident, when do you isolate, how do you preserve evidence, and what must be verified before recovery?
- How do you limit access across multiple accounts while retaining an auditable record?
Suggested study order
- Identity and access management, shared responsibility, and multi-account governance.
- Detection, log analysis, and incident response.
- Network and compute infrastructure protection.
- Data classification, encryption, keys, and privacy.
- Convert controls into continuous validation and audit processes.
A three-step preparation plan
- Use the SCS-C03 guide. Review tasks in all six current domains instead of relying on the SCS-C02 outline.
- Practice the full security-event lifecycle. Explain the evidence and permissions from signal through investigation, containment, recovery, and audit.
- Practice and review. Group misses by domain and decide whether the issue was control selection, investigation order, or a missed governance requirement.
Start practicing
When you are ready, use exam code SCS-C03 to practice by domain, then review weak areas against the official skill statements.