Independent study system · Amazon Web Services

AWS Certified Security - Specialty

A decision-first SCS-C03 system with the current six-domain blueprint, intensive and extended study paths, original review questions, and source-linked cloud security labs.

By

Exam code SCS-C03 · SCS-C03 · facts checked
Current exam snapshot

SCS-C03 at a glance

official
Version
SCS-C03
Effective
2025-12-02
Time
170 minutes
Items
65
Scored / unscored
50 / 15
Passing standard
750 on AWS's 100–1,000 scaled score

Formats: multiple-choice, multiple-response, ordering, matching.

Delivery: Pearson VUE testing center or Online proctored exam.

Baitaphish raw percentages are not AWS scaled scores.

Who this system is for

Provider statement · official

Exam-guide target

Equivalent of 3–5 years securing cloud solutions.

Provider statement · official

Certification-page guidance

Five years of IT security experience and two or more years securing AWS workloads.

AWS publishes both descriptions; Baitaphish keeps them distinct.

Preparation prerequisites

  • IAM policy evaluation and federation
  • AWS Organizations and multi-account governance
  • VPC routing and layered network controls
  • CloudTrail and security telemetry
  • KMS, certificates, secrets, and data classification
  • Cloud incident response
Foundation-path triggers
  • Cannot trace an API call from principal to central log
  • Cannot explain explicit versus implicit deny
  • Cannot diagram a private VPC traffic path
  • Has not practiced evidence-preserving containment
Blueprint coverage

Official domains and objective lessons

16 objectives
D1 · 16%

Detection

Design organization-scale monitoring, capture the right telemetry, and diagnose gaps between signals, findings, alerts, and responders.

  • 1.1 Design and implement monitoring and alerting
  • 1.2 Implement logging
  • 1.3 Troubleshoot monitoring, logging, and alerting
Open domain lesson →
D2 · 14%

Incident Response

Prepare repeatable cloud incident procedures, preserve evidence, contain safely, eradicate causes, and restore trusted operation.

  • 2.1 Design and test an incident response plan
  • 2.2 Respond to security incidents
Open domain lesson →
D3 · 18%

Infrastructure Security

Select and troubleshoot layered controls for network edges, compute workloads, VPCs, hybrid paths, service endpoints, and workload isolation.

  • 3.1 Secure network edge services
  • 3.2 Secure compute workloads
  • 3.3 Secure networks
Open domain lesson →
D4 · 20%

Identity and Access Management

Evaluate authentication and authorization across identities, sessions, resource policies, organization guardrails, delegated administration, and cross-account access.

  • 4.1 Design, implement, and troubleshoot authentication
  • 4.2 Design, implement, and troubleshoot authorization
Open domain lesson →
D5 · 18%

Data Protection

Protect data in transit, at rest, and in use through ownership-aware encryption, key lifecycle decisions, secret handling, discovery, masking, and evidence.

  • 5.1 Protect data in transit
  • 5.2 Protect data at rest
  • 5.3 Protect confidential data, credentials, secrets, and key material
Open domain lesson →
D6 · 14%

Security Foundations and Governance

Apply repeatable account governance, secure deployment, compliance evidence, policy enforcement, delegated administration, and exception handling.

  • 6.1 Centrally deploy and manage AWS accounts
  • 6.2 Deploy resources consistently and securely
  • 6.3 Meet compliance requirements
Open domain lesson →

Learn, apply, assess

Diagnose

Route preparation depth

30 objective-linked items route the 7-, 14-, or 30-day path.

Open diagnostic →
Schedule

Every day is actionable

Lesson, decision matrix, application, recall, check, and remediation are specified for each day.

Choose a study plan →
Apply

8 labs or scenarios

Each includes prerequisites, cost, procedure, validation, cleanup, objectives, and publication status.

Review applications →
Recall

32 source-linked cards

Keyboard-operable recall with private mastery tracking.

Study flashcards →
Compare

6 decision matrices

Practice choosing controls and patterns from requirements, failure modes, and evidence.

Open cheat sheet →
Assess

Two fresh mixed sets

Internal raw-score practice with domain floors and readiness hard gates; never provider score equivalence.

Open practice center →

Version and scope notes

  • SCS-C03 began December 2, 2025.
  • Detection and Incident Response are separate domains.
  • Identity and Access Management increased to 20%.
  • The current guide includes ordering and matching response types.
  • New or expanded scope includes OCSF, generative-AI protections, inter-resource encryption, imported key material, masking, and multi-Region keys.
Private by design

Progress on this device

0/57lessons
0/8applications
0/32flashcards
0assessment attempts

Scores, confidence, answers, and weak objectives remain in browser storage and are not sent to Baitaphish.

Trust and provenance

Editorial record

AI-assistance disclosure

AI assisted with curriculum drafting and implementation. Provider facts were rechecked against first-party sources. Questions and application procedures remain separately gated until named technical review and execution validation.

This record says human review did not occur.

Sources