Official SCS-C03 domains
The official guide validates the ability to secure AWS products and services, choose among cost, security, and deployment-complexity trade-offs, implement data protection and secure protocols, and understand security operations and risks.
| Official content domain | Weight |
|---|---|
| Content Domain 1: Detection | 16% |
| Content Domain 2: Incident Response | 14% |
| Content Domain 3: Infrastructure Security | 18% |
| Content Domain 4: Identity and Access Management | 20% |
| Content Domain 5: Data Protection | 18% |
| Content Domain 6: Security Foundations and Governance | 14% |
Detection, logging, and finding validation
Weeks 1–2Build evidence before automation. Learn which source answers which question, how coverage scales across accounts and Regions, and how to distinguish a finding from a proven incident.
- Design organization CloudTrail and dedicated log-archive patterns
- Distinguish management, data, Insights, and network log sources
- Configure S3/KMS delivery policies, validation, retention, and mutation alerts
- Use VPC Flow Logs, transit gateway flow logs, and Route 53 Resolver query logs deliberately
- Centralize GuardDuty administration and understand protection-plan coverage
- Use Security Hub central configuration, standards, automation rules, and finding aggregation
- Compare Security Hub findings, Security Lake OCSF data, and Detective investigations
- Use Macie for scoped S3 classification and sensitive-data findings
- Troubleshoot missing logs from selectors, permissions, resources, Regions, agents, and delivery paths
- Validate actor, API, resource, network, time, severity, scope, and impact before remediation
Incident readiness, containment, forensics, and recovery
Weeks 3–4Practice a complete response lifecycle with synthetic findings and disposable resources. Access, evidence destinations, isolation, recovery, and communications must exist before the alarm.
- Design runbooks, escalation, severity, ownership, communications, and legal/evidence decisions
- Pre-provision cross-account response roles, evidence KMS access, and break-glass paths
- Test plans through game days, sample findings, and authorized fault exercises
- Route findings with EventBridge and add approval-aware Systems Manager, Lambda, or Step Functions automation
- Make response actions least-privilege, idempotent, bounded, reversible, and fully logged
- Contain disposable EC2 resources without immediately destroying volatile evidence
- Capture approved logs, snapshots, memory, metadata, and timelines with chain-of-custody
- Use Detective and log correlation to find related identities, resources, connections, and root cause
- Revoke synthetic credentials and remove persistence before recovery
- Restore from a trusted source, monitor the recovered workload, and conduct lessons learned
Infrastructure and application security
Weeks 5–7Protect distinct layers with the right controls: web requests at the edge, routed flows in the network, and workload identity, patching, vulnerability, and administrative paths on compute.
- Protect CloudFront, ALB, API endpoints, and other supported resources with AWS WAF
- Stage managed/custom WAF rules in Count, use labels and rate rules, inspect logs, then enforce
- Understand Shield Standard versus Shield Advanced capabilities and response requirements
- Evaluate third-party WAF rules and OCSF-compatible edge/security integrations
- Design security groups, stateless network ACLs, private subnets, and VPC endpoints
- Route traffic symmetrically through Network Firewall endpoints and test every Availability Zone
- Design segmentation, Transit Gateway inspection, centralized egress, VPN, Direct Connect, and MACsec requirements
- Use Verified Access for identity-aware application access where appropriate
- Build hardened AMIs/images, patch with Systems Manager, scan with Inspector, and use GuardDuty runtime coverage where applicable
- Administer EC2 through Session Manager without public SSH or persistent keys
- Apply least-privilege service and execution roles to EC2, Lambda, ECS, EKS, and pipelines
- Threat-model generative AI prompt injection, tool misuse, data boundaries, output trust, and excessive agency
Identity, authorization, and data protection
Weeks 8–10This phase joins the two 18–20% domains. Follow a request from human or workload authentication through every policy layer to encrypted data, secrets, keys, certificates, backups, and retention.
- Federate workforce users with IAM Identity Center, groups, MFA policy, permission sets, and temporary sessions
- Use Cognito for application identities and STS, role sessions, Roles Anywhere, or presigned URLs for temporary credentials
- Design cross-account trust and external IDs for third-party confused-deputy scenarios
- Apply RBAC, trusted ABAC attributes, permission boundaries, session policies, and resource policies
- Use IAM Access Analyzer, policy validation, simulation, CloudTrail, and denial context to troubleshoot
- Understand union/intersection logic, explicit deny, SCPs, RCPs, key policies, grants, and service control boundaries
- Require supported TLS policies, private connectivity, and service-specific inter-node encryption
- Compare SSE-S3, SSE-KMS, client-side envelope encryption, KMS, CloudHSM, and external key stores
- Distinguish AWS-generated and imported KMS key material, expiration, backup, reimport, and availability
- Use key policies, aliases, grants, encryption context, rotation, deletion windows, and multi-Region keys safely
- Protect secrets with Secrets Manager rotation and certificates with ACM or AWS Private CA where required
- Use versioning, Object Lock, lifecycle, replication, AWS Backup, and tested restore for integrity and resilience
- Discover sensitive S3 data with Macie and mask log or SNS data using supported protection policies
Governance, secure deployment, compliance, and readiness
Weeks 11–14Finish at organization scale. A secure configuration must survive account creation, code deployment, drift, exceptions, audits, incidents, and cost review.
- Design OUs, management/security/log-archive accounts, delegated administrators, and root-access procedures
- Use SCPs, RCPs, tag policies, AI service opt-out policies, and declarative policies for their intended purposes
- Apply AWS Control Tower controls to new or existing environments where appropriate
- Deploy baselines with CloudFormation StackSets and validate IaC with CloudFormation Guard and linting
- Use Firewall Manager to centrally manage supported WAF, Shield, security group, DNS, and Network Firewall policies
- Share approved resources with Service Catalog and AWS RAM rather than unmanaged copies
- Evaluate resources with Config organization rules, conformance packs, aggregators, and bounded remediation
- Use Audit Manager to organize evidence and Artifact for AWS compliance reports and agreements
- Use the Well-Architected Tool and security best practices without confusing review with automatic compliance
- Run the two synthetic portfolio projects and complete cost and deletion rehearsals
- Answer timed original questions across all response types and explain every distractor from AWS documentation
- Recheck the official guide, in-scope services, updates, exam logistics, and current AWS service behavior
PrepKloud SCS-C03 study surfaces
Use 25 original, zero-based scenario questions with detailed explanations and official AWS references. Flashcards
Retrieve current domain weights, service boundaries, policy evaluation, response, and cryptographic distinctions. Portfolio projects
Build a multi-account response environment and a governed zero-trust/data-protection platform using synthetic data. Cloud security jobs
Connect SCS-C03 evidence to cloud security engineer, incident responder, IAM, platform security, and governance roles. SCS-C03 guide
Read the domain strategy, SCS-C02 comparison, study plan, project guidance, and common mistakes. Career paths
Compare cloud security and adjacent architecture, operations, IAM, DevSecOps, and governance paths.
Official AWS sources
Confirm target candidate, response types, scoring, exact domain weights, tasks, and services.
Open AWS exam guideReview dates, weight changes, additions, deletions, and recategorized objectives.
Open official comparisonReview monitoring, alerting, organization logging, analysis, normalization, and troubleshooting.
Open Domain 1Review plans, testing, automated remediation, evidence, finding validation, containment, and root cause.
Open Domain 2Review human/workload authentication, temporary credentials, policy design, ABAC/RBAC, and authorization diagnosis.
Open Domain 4Review transit/at-rest controls, integrity, backups, imported keys, masking, secrets, certificates, and multi-Region management.
Open Domain 5Frequently asked questions
Is SCS-C03 the active AWS Security Specialty exam?
Yes. AWS says SCS-C03 began use on December 2, 2025. SCS-C02 was in use until December 1, 2025. Use current SCS-C03 domain names, weights, tasks, and additions.
What are the six official weights?
Detection 16%, Incident Response 14%, Infrastructure Security 18%, Identity and Access Management 20%, Data Protection 18%, and Security Foundations and Governance 14% of scored content.
What changed from SCS-C02?
Detection and Incident Response were restructured; IAM rose to 20%; Infrastructure Security became 18%; Domain 6 was renamed. New content includes finding validation, OCSF/edge integrations, generative AI guardrails, internal encryption, imported-key differences, masking, and multi-Region key/certificate management.
How much experience does AWS recommend?
The official target candidate has the equivalent of 3–5 years of experience securing cloud solutions, including identity at scale, multi-account governance, incident response, vulnerability management, firewall rules, audits, logging, encryption, and recovery controls.
Are these materials exam dumps?
No. PrepKloud creates original scenarios and projects from public objectives and AWS documentation. No live, recalled, leaked, proprietary, or marketplace questions are used, and no passing result is guaranteed.
Turn SCS-C03 knowledge into security evidence
Diagnose gaps with questions, reinforce distinctions with flashcards, then build and tear down both synthetic multi-account projects.