AWS Certified Security Specialty: the honest guide
Everything AWS publishes about SCS-C03, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.
This guide page is built from the registry, not written yet.
Everything below comes from Security Specialty’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.
Practise Security Specialty questions in the meantimeWhat the exam actually asks you to do
Multiple choice and multiple response only. No simulations, no labs, and nothing to configure.
- Multiple choice
- Multiple response
Nothing here needs a lab. Reading carefully and eliminating options is the whole skill. AWS, Security Specialty exam guide ↗
Domain breakdown and official weightings
From the official AWS exam guides. Infrastructure Security is the heaviest domain at 20 percent, followed by Security Logging and Monitoring at 18 percent.
- Threat Detection and Incident Response14%
- Security Logging and Monitoring18%
- Infrastructure Security20%
- Identity and Access Management16%
- Data Protection18%
- Management and Security Governance14%
Where to focus: Logging, data protection, and infrastructure security are 56 percent together. Know exactly which service produces which log, and where each one lands.
What comes after passing
Security Specialty is valid for 3 years. Recertify by passing the current version of this exam, or a higher one.
Costs across the full renewal cycle are on the Security Specialty cost page.
Frequently asked questions
How hard is the AWS Security Specialty?
It is one of the less forgiving AWS exams. Questions are long, several options are defensible, and the right answer usually turns on one detail of IAM policy evaluation or KMS key policy. Associate-level pattern matching does not carry you through it.
Do I need Solutions Architect Associate first?
AWS removed the formal prerequisite, but the exam assumes you can already read a VPC design and reason about cross-account access. Most people who pass have real operational time in AWS, not just an associate cert.
What should I study first for SCS-C03?
IAM policy evaluation logic, then KMS. Between identity, data protection, and infrastructure security they are more than half the exam, and almost every scenario question reduces to which policy or key grant applies.
Are there labs on this exam?
No. It is multiple choice and multiple response only. That does not make it easier, because the questions describe situations you can only answer if you have built the thing being described.
Keep reading
Every guide and cost breakdown, by vendorPractise Security Specialty for free while you decide
Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.
Start free Security Specialty questions