Cloud security is one of the most in-demand specialisations in IT, and the AWS Certified Security – Specialty is AWS’s dedicated credential for it. It is aimed at experienced professionals, not beginners, and is now delivered as exam SCS-C03.
Details checked on the official AWS certification page in October 2026.
Exam facts
| Exam code | SCS-C03 |
| Fee | US$300 |
| Duration | 170 minutes |
| Questions | 65, multiple choice or multiple response |
| Recommended experience | 5 years of IT security experience designing and implementing security solutions, plus 2 or more years securing AWS workloads |
| Validity | 3 years |
What you need to know
- Identity and access management: IAM policies and their evaluation logic, roles, permission boundaries, AWS Organizations and service control policies, and IAM Identity Center.
- Data protection: encryption with AWS KMS, key policies, Secrets Manager, certificate management, and protecting data in S3 and databases.
- Infrastructure security: VPC design, security groups, network ACLs, AWS WAF, Shield and Network Firewall.
- Threat detection and incident response: GuardDuty, Security Hub, Detective, CloudTrail, CloudWatch and automated responses.
- Governance and compliance: AWS Config, audit evidence, and multi-account security strategies.
Read the official SCS-C03 exam guide for the exact domains and weightings, and avoid older SCS-C02 study material that has not been updated.
Is it right for you?
It suits cloud security engineers, security architects and DevSecOps engineers working mainly on AWS. If you are new to security or to AWS, build up first: Solutions Architect – Associate plus an entry security certification such as Security+ gives you the foundation this exam assumes.
How to prepare
- Master IAM policy evaluation, including how explicit denies, service control policies, resource policies and permission boundaries interact. Many questions hinge on it.
- Practise KMS key policies and cross-account access in a lab.
- Enable GuardDuty, Security Hub and Config in a test account and study the findings they produce.
- Build an automated response, for example a rule that isolates a compromised instance.
- Use AWS Skill Builder’s official practice questions before booking.
Security services can generate charges, so set a billing alert and turn services off after practice.
Leave a Reply