CertGrid
AWS Study Guide

AWS SCS-C03: Security Specialty Study Guide

The AWS Certified Security - Specialty (SCS-C03) validates deep expertise in securing AWS workloads across six domains: detection, incident response, infrastructure security, identity and access management, data protection, and security foundations and governance. AWS recommends five years of IT security experience designing and implementing security solutions, plus two or more years of hands-on experience securing AWS workloads. The exam runs 170 minutes and contains 65 questions, of which 50 are scored and 15 are unscored trial questions that are not identified. Scores are scaled from 100 to 1,000 with 750 to pass, and scoring is compensatory, so you do not have to pass every domain individually.

Objective-mapped study guide, aligned to current exam objectives · Published Sep 2026 · Question bank reviewed Aug 2026 · Independent practice platform.

Real exam: 65 qs · 170 min

Domain 1: Detection

Key concepts you must know · 165 practice questions

Domain 2: Incident Response

Key concepts you must know · 151 practice questions

Domain 3: Infrastructure Security

Key concepts you must know · 185 practice questions

Domain 4: Identity and Access Management

Key concepts you must know · 171 practice questions

Domain 5: Data Protection

Key concepts you must know · 177 practice questions

Domain 6: Security Foundations and Governance

Key concepts you must know · 93 practice questions

AWS SCS-C03 exam tips

Study guide FAQ

How long is the SCS-C03 exam and what score do I need to pass?

The exam is 170 minutes and contains 65 questions. Only 50 of those are scored - the other 15 are unscored trial questions that AWS does not identify, so answer every question. Scores are scaled from 100 to 1,000 and 750 passes. Scoring is compensatory, so you need the overall score rather than a pass in each domain.

What is the difference between GuardDuty, Inspector, Macie, and Security Hub?

GuardDuty detects active threats and malicious behavior from CloudTrail, VPC Flow Logs, and DNS logs. Inspector scans EC2, containers, and Lambda for software vulnerabilities. Macie discovers and classifies sensitive data in S3. Security Hub aggregates and normalizes findings from all of these (plus third parties) and runs compliance standards checks.

When should I use an SCP versus an IAM policy versus a permissions boundary?

SCPs are Organization-level guardrails that set the maximum permissions for member accounts but grant nothing themselves. IAM identity policies actually grant permissions to users and roles. Permissions boundaries cap what a specific user or role can be granted, which is ideal for safely delegating role creation. The effective access is the intersection of all of them, and any explicit Deny overrides everything.

How much hands-on AWS experience does the exam assume?

AWS recommends five years of IT security experience designing and implementing security solutions, plus two or more years of hands-on experience securing AWS workloads, with knowledge spanning the shared responsibility model, identity at scale, multi-account governance, incident response, vulnerability management, layer 3-7 firewall rules, logging strategies, encryption at rest and in transit, and disaster recovery controls. The exam is heavily scenario-based and often turns on exact service behaviour, so reading alone is rarely enough.

What changed between SCS-C02 and SCS-C03?

The biggest structural change is that the combined threat-detection-and-incident-response domain was split in two, and the separate logging and monitoring domain was folded into Detection. The current six domains are Detection 16%, Incident Response 14%, Infrastructure Security 18%, Identity and Access Management 20%, Data Protection 18%, and Security Foundations and Governance 14%.

Official exam sources

The domain names and weightings on this page follow the published exam blueprint. Each source below records what it confirmed and when it was read, so the split can be checked rather than taken on trust.

Related AWS resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by AWS. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.