Certification guide

SCS-C03

AWS Certified Security Specialty: the honest guide

Security Specialty is where AWS stops asking what a service does and starts asking what you would do at three in the morning. It assumes you already operate on AWS and tests whether you can reason about permissions, keys, logging and incident response under pressure.

It is the hardest AWS exam in this catalog and the one most sensitive to real experience. Candidates who pass tend to have worked with CloudTrail, GuardDuty, KMS and IAM in anger. Candidates who fail tend to have read about all four.

Who Security Specialty is for

A good fit if

  • You work in cloud security or DevOps on AWS and want the credential that matches what you already do.
  • You hold an associate certification and are moving deliberately toward a security-focused role.
  • Your organisation needs demonstrable AWS security competence for a customer or an audit.
  • You want the AWS certification that is hardest to bluff, which is precisely why it carries weight.

Probably not, if

  • You are new to AWS. This exam assumes operational familiarity it does not teach, and sitting it early is an expensive way to discover that.
  • You want a general security certification. Security+ or CySA+ are vendor neutral and cover a much broader surface; this one is AWS all the way down.
  • You need a certification quickly. This is a long preparation for anyone not already working in the material.

Is Security Specialty worth it?

For someone already doing AWS security work, yes, clearly. It is the credential that separates people who have configured a key policy from people who have read about one, and it is treated that way in hiring.

For someone using it to break into cloud security, it is the wrong first move. The exam assumes the experience the job would give you, so the sequence that works is a security role first and this exam second, rather than the other way around.

The cost argument is real at this level. At $300 a sitting with a fourteen day wait between attempts, sitting it unprepared is expensive in a way the associate exams are not, and that should shift your judgement toward waiting.

What the exam actually asks you to do

Multiple choice and multiple response only. No simulations, no labs, and nothing to configure.

Item formats

  • Multiple choice
  • Multiple response

Nothing here needs a lab. Reading carefully and eliminating options is the whole skill. AWS, Security Specialty exam guide

Domain breakdown and official weightings

From the official AWS exam guides. Infrastructure Security is the heaviest domain at 20 percent, followed by Security Logging and Monitoring at 18 percent.

  • Threat Detection and Incident Response14%
  • Security Logging and Monitoring18%
  • Infrastructure Security20%
  • Identity and Access Management16%
  • Data Protection18%
  • Management and Security Governance14%

Where to focus: Logging, data protection, and infrastructure security are 56 percent together. Know exactly which service produces which log, and where each one lands.

Amazon Web Services (AWS): AWS exam guides

Study plans by experience level

Working in AWS security already

4 to 6 weeksat 6 hours

  1. 1Week 1: read the exam guide and mark the services you do not use daily. On this exam that list is the whole of your study plan.
  2. 2Weeks 2 to 3: key management in depth. The interaction between key policies, IAM policies, grants and cross-account access decides more questions than any other single topic.
  3. 3Week 4: logging and monitoring. CloudTrail, Config, GuardDuty, Security Hub and Detective all overlap, and the exam asks which one answers a given question.
  4. 4Weeks 5 to 6: scenario practice and the free official sample questions, which are closer to the exam's wording than anything else available.

Associate certified, limited security work

10 to 12 weeksat 6 to 8 hours

  1. 1Weeks 1 to 3: the identity model properly. IAM policies, resource policies, permission boundaries, service control policies and how they combine. This is the foundation everything else sits on.
  2. 2Weeks 4 to 6: data protection. KMS, envelope encryption, key rotation, and the difference between encryption in transit and at rest across the storage services.
  3. 3Weeks 7 to 8: detection and response. Turn on GuardDuty in a lab account, generate findings, and follow one through to a conclusion.
  4. 4Weeks 9 to 10: infrastructure security and governance, including the network controls the exam expects you to reach for.
  5. 5Weeks 11 to 12: full scenario sets under time, then the official samples.

Security background, new to AWS

12 to 16 weeksat 6 hours

  1. 1Sit Solutions Architect Associate first. This exam assumes you know how AWS is put together, and the half-price voucher from passing applies to this one.
  2. 2Weeks 1 to 6: map your existing security knowledge onto AWS primitives. Identity, network segmentation, logging and key management all exist in your world already under other names.
  3. 3Weeks 7 to 10: the AWS-specific parts with no on-premises equivalent, particularly the policy evaluation logic and the shared responsibility boundary for each service type.
  4. 4Weeks 11 to 14: detection services and incident response in a real account.
  5. 5Weeks 15 to 16: scenario practice under time.

Common mistakes

Sitting it too early
The most expensive mistake on this exam and the most common. A uniformly middling score report looks like bad luck and usually means the candidate lacked operational familiarity rather than facts. Rebooking against that report tends to produce the same spread again.
Treating KMS as a single topic
Key policies, IAM policies and grants combine in ways that are not intuitive, and cross-account key access is examined directly. This is the densest area of the exam and it rewards working through the developer guide rather than a summary.
Confusing the detection services
GuardDuty, Config, Security Hub, Inspector, Macie and Detective overlap enough to be confusable and are distinct enough to be examined. Build a one-line description of what each one watches and what it produces, and learn that before anything deeper.
Ignoring the shared responsibility detail
At fundamentals level the shared responsibility model is a diagram. Here it is a series of specific questions about who patches what for a given managed service, and the boundary moves service by service.
Studying without an account
This exam asks what a finding looks like and what an action changes. Both are hard to learn from prose. Even a free-tier account with GuardDuty enabled for a fortnight teaches things reading does not.

What comes after passing

There is no higher exam in this track that recertifies it, so unlike an associate certification this one has to be renewed by sitting it again in three years.

Passing earns a benefit including a fifty percent voucher toward your next AWS exam, which is worth claiming even if your next exam is this one again at renewal.

In hiring terms this is a strong signal precisely because it is hard to obtain without doing the work. It pairs well with a vendor-neutral security certification, which shows breadth alongside the AWS depth.

Expect the service surface to move. Three years is long enough that services which did not exist at your first sitting will be examinable at your second, so treat recertification as genuine study.

Costs across the full renewal cycle are on the Security Specialty cost page.

Frequently asked questions

How much AWS experience do I need for Security Specialty?

AWS suggests around five years of IT security experience and two years securing AWS workloads. Those numbers are a guide rather than a gate, but the exam genuinely assumes operational familiarity, and the common failure is a candidate who studied the services without ever having operated them.

Is Security Specialty harder than Solutions Architect Professional?

They are hard in different ways. The professional exam is broader and its questions are longer; this one is narrower and deeper, and it punishes gaps in the policy evaluation and key management material specifically. Most people find the professional exam more tiring and this one more technical.

Do I need an associate certification first?

Not formally, since AWS removed the prerequisites. In practice Solutions Architect Associate first is the sensible order: it establishes how AWS fits together, and passing it earns a half-price voucher toward this exam.

What is the single highest-value topic to study?

How permissions combine. IAM policies, resource policies, permission boundaries, service control policies and KMS key policies all interact, and questions about whether a given call succeeds appear throughout the exam rather than in one domain. It is the topic that repays study most.

Does it expire?

Yes, after three years, and there is no higher exam in the same track that renews it automatically. Recertifying means sitting Security Specialty again at full price, though the fifty percent benefit voucher from your previous pass applies if you claim it.

Keep reading

Cheat sheets

Printable reference tables, free.

Every guide and cost breakdown, by vendor

Practise Security Specialty for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free Security Specialty questions