AWS Certified Security - Specialty (SCS-C02)
The specialty certification for securing AWS workloads — threat detection and incident response, logging, infrastructure security, identity, data protection and multi-account governance.
- src
- AWS Certification — AWS Certified Security - Specialty exam page (aws.amazon.com/certification)
- chk
The Security Specialty is the AWS certification that assumes you already run things on AWS. It does not teach you the platform — it asks whether you can tell why a request that should have been denied was allowed, and find the answer in logs you configured yourself.
What the weights tell you to study
Infrastructure Security leads at 20%, with Logging and Monitoring and Data Protection at 18% each. Those three are more than half the exam, and all three reward hands-on work over reading.
Identity and Access Management is nominally 16%, and that number understates it badly. Policy evaluation logic is the machinery underneath questions in every other domain: an infrastructure question about a VPC endpoint, a data question about a KMS key, a governance question about an SCP all resolve to whether a specific principal is allowed a specific action. Learn the evaluation order first and the rest of the exam gets easier.
Threat Detection and Incident Response and Management and Security Governance sit at 14% each. They are the smallest domains and they overlap heavily — both assume a multi-account organisation with centralised, automated controls.
What the exam is actually like
170 minutes, 65 questions, and only 50 of them count. Fifteen are unscored and unmarked, so a question that seems unreasonably obscure may simply not be scored. Answer it and move on rather than losing four minutes to it.
Scaled scoring, 100 to 1,000, pass at 750, compensatory across the whole exam. No individual domain has to be passed. There is no penalty for a wrong answer, which makes leaving anything blank strictly worse than guessing.
Questions are scenarios with long stems. Most describe an architecture, state a symptom, and offer four plausible remedies. The skill being tested is elimination under time pressure — reading the last sentence first, to find out what is actually being asked, is worth practising.
Where the marks are lost
Two places. The first is the boundary between a resource policy and an identity policy — S3 bucket policies and KMS key policies both need to agree with IAM, and questions are built precisely on that seam. The second is troubleshooting: several task statements are explicitly about diagnosing something already broken, and candidates who only ever built working configurations have never seen the failure mode being described.
Before you book
The exam is $300 and the certification is valid for three years. AWS publishes the in-scope and out-of-scope service lists in the exam guide appendix — read them before planning your study, because the surface is narrower than "AWS security" implies, and weeks are lost to services that cannot appear.
New to Linux and the command line?
This path assumes fundamentals you may not have yet. Our Foundations Pack is out and free — Linux, the shell and Git, with exercises that mark your work and explain why you got it wrong. We're writing an agents pack next; leave your email if you want to hear when it ships.
One email when the pack launches. No spam, unsubscribe any time.
Exam domains
Threat Detection and Incident Response
14%Security Logging and Monitoring
18%Infrastructure Security
20%Identity and Access Management
16%Data Protection
18%Management and Security Governance
14%Preparation path
- 1
Read the exam guide and the sample questions first
The guide is where the weights, the task statements and the in-scope service list live, and the last of those is the one people skip. Knowing which services are explicitly out of scope saves weeks — this exam is narrower than the AWS security surface suggests.
~3 hours - 2
Master IAM policy evaluation logic before anything else
Identity is 16% by weight and far more by influence: infrastructure, data protection and governance questions all resolve to 'is this request allowed?'. Learn the order — explicit deny, SCP, resource policy, permissions boundary, identity policy — until you can trace it without hesitating.
~25 hours - 3
Build the logging pipeline in a real account
Logging and Monitoring is 18%. Turn on an organization CloudTrail, ship to a locked S3 bucket in a separate account, query it in Athena, and then break it — remove the bucket policy statement CloudTrail needs and watch what the failure looks like. Troubleshooting is a named task statement.
~25 hours - 4
Work Infrastructure Security, the largest domain
At 20% it is the biggest single block. Security groups against NACLs, VPC endpoint policies, WAF rule evaluation order, and where traffic is actually inspected — the questions are usually 'why is this request still reaching the instance?', which is a troubleshooting skill and not a recall one.
~30 hours - 5
Learn KMS properly — key policies, grants and multi-Region
Data Protection is 18% and most of it is KMS. The recurring trap is a key policy and an IAM policy that disagree: access to a key needs both, and knowing which one is missing from an error message is worth several questions on its own.
~20 hours - 6
Cover incident response and governance last, together
They are 14% each and they share a mental model: multi-account, centralised, automated. Organizations, Control Tower, Config rules, GuardDuty and Security Hub all answer the same question at different layers, and studying them as one block is faster than as two domains.
~20 hours
Frequently asked questions
Career Roadmaps
- Cloud Security Engineer RoadmapA path into cloud security as an engineering discipline, covering the shared responsibility model, identity, network segmentation, encryption, workload hardening, detection, governance as code, threat modelling and incident response.
- Cloud Architect RoadmapA path into cloud architecture as the job it actually is — trade-off analysis, migration of systems you did not write, disaster recovery you have rehearsed, decision records, and influence without formal authority.