Skip to content

AWS Certified Security - Specialty (SCS-C02)

The specialty certification for securing AWS workloads — threat detection and incident response, logging, infrastructure security, identity, data protection and multi-account governance.

Amazon Web Services
Exam cost
$300 USD
src
AWS Certification — AWS Certified Security - Specialty exam page (aws.amazon.com/certification)
chk
Duration
170 minutes
Passing score
750 on a scaled score of 100–1,000
Valid for
3 years

The Security Specialty is the AWS certification that assumes you already run things on AWS. It does not teach you the platform — it asks whether you can tell why a request that should have been denied was allowed, and find the answer in logs you configured yourself.

What the weights tell you to study

Infrastructure Security leads at 20%, with Logging and Monitoring and Data Protection at 18% each. Those three are more than half the exam, and all three reward hands-on work over reading.

Identity and Access Management is nominally 16%, and that number understates it badly. Policy evaluation logic is the machinery underneath questions in every other domain: an infrastructure question about a VPC endpoint, a data question about a KMS key, a governance question about an SCP all resolve to whether a specific principal is allowed a specific action. Learn the evaluation order first and the rest of the exam gets easier.

Threat Detection and Incident Response and Management and Security Governance sit at 14% each. They are the smallest domains and they overlap heavily — both assume a multi-account organisation with centralised, automated controls.

What the exam is actually like

170 minutes, 65 questions, and only 50 of them count. Fifteen are unscored and unmarked, so a question that seems unreasonably obscure may simply not be scored. Answer it and move on rather than losing four minutes to it.

Scaled scoring, 100 to 1,000, pass at 750, compensatory across the whole exam. No individual domain has to be passed. There is no penalty for a wrong answer, which makes leaving anything blank strictly worse than guessing.

Questions are scenarios with long stems. Most describe an architecture, state a symptom, and offer four plausible remedies. The skill being tested is elimination under time pressure — reading the last sentence first, to find out what is actually being asked, is worth practising.

Where the marks are lost

Two places. The first is the boundary between a resource policy and an identity policy — S3 bucket policies and KMS key policies both need to agree with IAM, and questions are built precisely on that seam. The second is troubleshooting: several task statements are explicitly about diagnosing something already broken, and candidates who only ever built working configurations have never seen the failure mode being described.

Before you book

The exam is $300 and the certification is valid for three years. AWS publishes the in-scope and out-of-scope service lists in the exam guide appendix — read them before planning your study, because the surface is narrower than "AWS security" implies, and weeks are lost to services that cannot appear.

New to Linux and the command line?

This path assumes fundamentals you may not have yet. Our Foundations Pack is out and free — Linux, the shell and Git, with exercises that mark your work and explain why you got it wrong. We're writing an agents pack next; leave your email if you want to hear when it ships.

One email when the pack launches. No spam, unsubscribe any time.

Your progress0%

Exam domains

Threat Detection and Incident Response

14%
Design and implement an incident response planDetect security threats and anomalies by using AWS servicesRespond to compromised resources and workloadsGuardDuty, Security Hub, Detective and the AWS Security Finding Format (ASFF)Credential invalidation and rotation after a compromise

Security Logging and Monitoring

18%
Design and implement monitoring and alerting for security eventsTroubleshoot security monitoring and alertingDesign and implement a logging solutionTroubleshoot logging solutionsDesign a log analysis solution with Athena and CloudWatch Logs Insights

Infrastructure Security

20%
Design and implement security controls for edge servicesDesign and implement network security controlsDesign and implement security controls for compute workloadsTroubleshoot network securityWAF, Shield, CloudFront, Route 53, VPC design and endpoint policies

Identity and Access Management

16%
Design, implement and troubleshoot authentication for AWS resourcesDesign, implement and troubleshoot authorization for AWS resourcesPolicy evaluation logic across identity, resource, SCP and permissions boundariesCross-account access and role assumptionIAM Identity Center and federation

Data Protection

18%
Design and implement controls that provide confidentiality and integrity for data in transitDesign and implement controls that provide confidentiality and integrity for data at restDesign and implement controls to manage the lifecycle of data at restDesign and implement controls to protect credentials, secrets and cryptographic key materialsKMS key policies, grants and multi-Region keys

Management and Security Governance

14%
Develop a strategy to centrally deploy and manage AWS accountsImplement a secure and consistent deployment strategy for cloud resourcesEvaluate the compliance of AWS resourcesIdentify security gaps through architectural reviews and cost analysisAWS Organizations, Control Tower, Config and service control policies

Preparation path

  1. 1

    Read the exam guide and the sample questions first

    The guide is where the weights, the task statements and the in-scope service list live, and the last of those is the one people skip. Knowing which services are explicitly out of scope saves weeks — this exam is narrower than the AWS security surface suggests.

    ~3 hours
  2. 2

    Master IAM policy evaluation logic before anything else

    Identity is 16% by weight and far more by influence: infrastructure, data protection and governance questions all resolve to 'is this request allowed?'. Learn the order — explicit deny, SCP, resource policy, permissions boundary, identity policy — until you can trace it without hesitating.

    ~25 hours
  3. 3

    Build the logging pipeline in a real account

    Logging and Monitoring is 18%. Turn on an organization CloudTrail, ship to a locked S3 bucket in a separate account, query it in Athena, and then break it — remove the bucket policy statement CloudTrail needs and watch what the failure looks like. Troubleshooting is a named task statement.

    ~25 hours
  4. 4

    Work Infrastructure Security, the largest domain

    At 20% it is the biggest single block. Security groups against NACLs, VPC endpoint policies, WAF rule evaluation order, and where traffic is actually inspected — the questions are usually 'why is this request still reaching the instance?', which is a troubleshooting skill and not a recall one.

    ~30 hours
  5. 5

    Learn KMS properly — key policies, grants and multi-Region

    Data Protection is 18% and most of it is KMS. The recurring trap is a key policy and an IAM policy that disagree: access to a key needs both, and knowing which one is missing from an error message is worth several questions on its own.

    ~20 hours
  6. 6

    Cover incident response and governance last, together

    They are 14% each and they share a mental model: multi-account, centralised, automated. Organizations, Control Tower, Config rules, GuardDuty and Security Hub all answer the same question at different layers, and studying them as one block is faster than as two domains.

    ~20 hours

Frequently asked questions

Career Roadmaps