Certification guideSCS-C03

AWS Certified Security Specialty: the honest guide

Everything AWS publishes about SCS-C03, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.

This guide page is built from the registry, not written yet.

Everything below comes from Security Specialty’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.

Practise Security Specialty questions in the meantime

What the exam actually asks you to do

Multiple choice and multiple response only. No simulations, no labs, and nothing to configure.

  • Multiple choice
  • Multiple response

Nothing here needs a lab. Reading carefully and eliminating options is the whole skill. AWS, Security Specialty exam guide

Domain breakdown and official weightings

From the official AWS exam guides. Infrastructure Security is the heaviest domain at 20 percent, followed by Security Logging and Monitoring at 18 percent.

  • Threat Detection and Incident Response14%
  • Security Logging and Monitoring18%
  • Infrastructure Security20%
  • Identity and Access Management16%
  • Data Protection18%
  • Management and Security Governance14%

Where to focus: Logging, data protection, and infrastructure security are 56 percent together. Know exactly which service produces which log, and where each one lands.

Official Security Specialty exam objectives ↗

What comes after passing

Security Specialty is valid for 3 years. Recertify by passing the current version of this exam, or a higher one.

Costs across the full renewal cycle are on the Security Specialty cost page.

Frequently asked questions

How hard is the AWS Security Specialty?

It is one of the less forgiving AWS exams. Questions are long, several options are defensible, and the right answer usually turns on one detail of IAM policy evaluation or KMS key policy. Associate-level pattern matching does not carry you through it.

Do I need Solutions Architect Associate first?

AWS removed the formal prerequisite, but the exam assumes you can already read a VPC design and reason about cross-account access. Most people who pass have real operational time in AWS, not just an associate cert.

What should I study first for SCS-C03?

IAM policy evaluation logic, then KMS. Between identity, data protection, and infrastructure security they are more than half the exam, and almost every scenario question reduces to which policy or key grant applies.

Are there labs on this exam?

No. It is multiple choice and multiple response only. That does not make it easier, because the questions describe situations you can only answer if you have built the thing being described.

Keep reading

Every guide and cost breakdown, by vendor

Practise Security Specialty for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free Security Specialty questions