title: "SCS-C03 Decision Cheat Sheet" summary: "A compact decision framework for AWS security detection, response, infrastructure, identity, data protection, and governance scenarios."
How to use the matrices
Cover the recommended mechanism and work from the requirement column. State the trust boundary, owner, failure mode, and evidence before revealing the answer. Then alter one constraint—account ownership, Region, recovery objective, data classification, or latency—and explain whether the decision changes.
The matrices are compression aids, not substitutes for the official blueprint or operational experience. If a row feels like a service-name lookup, add the missing conditions and rejected alternatives.
Final decision sequence
- Identify the asset, principal, data, and business outcome.
- State the explicit security, compliance, recovery, performance, cost, and operational constraints.
- Trace the request, identity, network, data, and evidence paths.
- Apply the narrowest control that meets the whole requirement.
- Reject alternatives using a named constraint or failure mode.
- Explain how the control is deployed, monitored, tested, recovered, and governed.
For incident questions, preserve safety, evidence, and reversibility. For authorization questions, evaluate every applicable policy layer. For data questions, start with ownership and lifecycle. For governance questions, connect requirements to proof and exception ownership.