AWS Certified Security Specialty (SCS-C03) Exam Guide (2026)

If you can say why a resource control policy is not a service control policy, when an S3 presigned URL is the wrong way to grant access, and what "validate the finding" means before anyone touches the instance, you are in the right exam.
SCS-C03 is the current AWS security specialty code. It replaced SCS-C02, which was in use until 1 December 2025. The new code went live on 2 December 2025. Version 1.0 of the official exam guide carries a publication date of 26 March 2026. Anything written against SCS-C02 is now one restructure behind.
This guide is for people who will sit SCS-C03 on the current blueprint, including the reorganized detection and response domains, the generative AI guardrail skill, and the expanded key material and masking tasks.
Who this exam is for
Take it if security is already the job. The exam guide describes the target candidate as having the equivalent of 3 to 5 years securing cloud solutions. The certification page is blunter and asks for five years of IT security experience and two or more years securing AWS workloads specifically.
The recommended knowledge list is worth reading as a gap check rather than a brochure. It names the shared responsibility model, managing identity at scale, multi-account governance, software supply chain risk, incident prevention and response strategy, cloud vulnerability management, writing firewall rules at layers 3 to 7 at scale, incident root cause analysis, responding to an audit, logging and monitoring strategy, encryption at rest and in transit, and disaster recovery controls including backup.
Five job tasks are explicitly out of scope. Designing cryptographic algorithms. Packet-level traffic analysis. Architecting overall cloud deployments. Managing end-user compute. Training machine learning models. That last one matters more than it looks. Amazon Bedrock and Amazon SageMaker AI are both in scope as services, but they show up as things to put controls around, not as things to train.
Skip it if the work is alarms and patch windows. That is CloudOps. Skip it if the question you actually want answered is how to shape a workload end to end. That is Solutions Architect. AWS notes that candidates commonly earn Solutions Architect Associate or Professional before attempting this exam, and often go on to DevOps Engineer Professional or Advanced Networking Specialty afterward.
The candidate AWS wants can read a policy and predict the deny. The sitting punishes people who recognize a service logo but cannot say which layer of control the stem is actually asking about.
Exam shape
SCS-C03 has six domains:
| Domain | Weight | What gets tested |
|---|---|---|
| 1. Detection | 16% | Monitoring and alerting design, logging design, log analysis, troubleshooting missing or broken telemetry |
| 2. Incident Response | 14% | Response plans and runbooks, testing the plan, validating findings, containment, eradication, recovery, root cause |
| 3. Infrastructure Security | 18% | Edge protection, compute hardening and patching, network segmentation, hybrid connectivity, generative AI guardrails |
| 4. Identity and Access Management | 20% | Authentication design, temporary credentials, authorization controls, least privilege, analyzing authorization failures |
| 5. Data Protection | 18% | Encryption in transit and at rest, integrity and retention, secrets, key material, masking, certificates |
| 6. Security Foundations and Governance | 14% | Organizations and Control Tower, organization policies, IaC deployment, cross-account sharing, compliance evidence |
Identity and Access Management is the single heaviest domain at 20%. Data Protection and Infrastructure Security tie at 18%. Those three carry 56% of the scored content between them. If your study plan gives equal calendar time to all six, the math is already against you.
The sitting is 65 questions over 170 minutes. AWS scores 50 of them. Fifteen are unscored research questions, they are not identified on the exam, and they do not affect your result. The cost is 300 USD.
The passing score is 750 on a scaled range of 100 to 1,000. Note that number. It is higher than the 720 used on several AWS associate exams, and studying against the wrong threshold is a quiet way to under-prepare. Scoring is compensatory, so a weak Domain 6 can still pass if Domain 4 is clean. Unanswered questions score as incorrect and there is no separate penalty for guessing, so leave nothing blank.
One practical detail from the certification page: the exam uses short names for some AWS services, and a short name to full name list is available behind the Help button during the sitting. Read that list before exam day so the abbreviations do not cost you reading time.
What changed from SCS-C02 to SCS-C03
The exam guide ships an appendix that maps the old blueprint onto the new one. The domain count stayed at six. Almost everything else about the first two domains moved.
| SCS-C02 domain | SCS-C03 domain |
|---|---|
| 1. Threat Detection and Incident Response, 14% | 1. Detection, 16% |
| 2. Security Logging and Monitoring, 18% | 2. Incident Response, 14% |
| 3. Infrastructure Security, 20% | 3. Infrastructure Security, 18% |
| 4. Identity and Access Management, 16% | 4. Identity and Access Management, 20% |
| 5. Data Protection, 18% | 5. Data Protection, 18% |
| 6. Management and Security Governance, 14% | 6. Security Foundations and Governance, 14% |
Read that table as a restructure, not a renumbering. "Threat Detection and Incident Response" and "Security Logging and Monitoring" were broken apart and rebuilt as "Detection" and "Incident Response". Logging moved into Detection. Response became its own domain with its own task statements. Domain 6 was renamed from "Management and Security Governance" to "Security Foundations and Governance".
The weight shift is the part to act on. Identity and Access Management gained four points, from 16% to 20%. Infrastructure Security lost two, from 20% to 18%. Detection gained two. Incident Response lost four relative to the old combined framing.
Content AWS added for SCS-C03:
- Validate findings from AWS security services to assess the scope and impact of an event
- Configure integrations with AWS edge services and third-party services, with OCSF format ingestion and third-party WAF rules as the examples
- Implement protections and guardrails for generative AI applications, with the GenAI OWASP Top 10 for LLM Applications named directly
- Design and configure inter-resource encryption in transit, naming inter-node encryption for Amazon EMR, Amazon EKS, SageMaker AI, and Nitro encryption
- Describe the differences between imported key material and AWS generated key material
- Mask sensitive data, naming CloudWatch Logs data protection policies and Amazon SNS message data protection
- Create and manage encryption keys and certificates across a single Region or multiple Regions, naming KMS customer managed keys and AWS Private Certificate Authority
Content AWS removed:
- AWS Security Finding Format (ASFF)
- The AWS Security Incident Response Guide as a named study object
- Log format and components, for example the anatomy of a CloudTrail log record
- Host-based security, host firewalls, and hardening as a standalone skill
- Fundamental TCP/IP concepts, the OSI model, and reachability troubleshooting depth
- The components of a policy stated as Principal, Action, Resource, Condition
- TLS concepts as theory, and cross-Region design using private and public virtual interfaces
- Configuring S3 static website hosting
- Identifying security gaps through architectural reviews and cost analysis
Be careful with one of those removals. TCP/IP fundamentals and reachability troubleshooting left Task 3.4 of the old guide, but Skill 3.3.5 on the current outline still names Network Access Analyzer and Amazon Inspector network reachability findings as ways to identify unnecessary network access. The tools did not disappear. The expectation that you reason from first principles about ports and the OSI model did.
Two services are explicitly out of scope: Amazon MWAA and AWS Payment Cryptography. The in-scope list, by contrast, now reads as a security operations tool catalog, with Amazon Security Lake, AWS CloudTrail Lake, Amazon Detective, AWS Verified Access, Amazon Verified Permissions, Automated Forensics Orchestrator for Amazon EC2, AWS Fault Injection Service, AWS Resilience Hub, Amazon Application Recovery Controller, Amazon Managed Grafana, AWS Private Certificate Authority, Amazon CodeGuru Security, Amazon Q Developer, and Amazon Q Business all named.
The response types are not what the overview box says
This is the single most useful thing to know before booking a seat.
The SCS-C03 exam guide lists four question types, not two:
- Multiple choice. One correct response and three distractors.
- Multiple response. Two or more correct responses out of five or more options.
- Ordering. A list of 3 to 5 responses that you place in the correct order to complete a task.
- Matching. A list of responses matched against 3 to 7 prompts.
Ordering and matching are all-or-nothing. On an ordering question you must select the correct responses and put them in the correct sequence to receive credit. On a matching question every pair has to be right. Partial credit does not apply.
Worth flagging as an observed inconsistency: the exam overview box on the AWS certification page still describes the format as "65 questions, either multiple choice or multiple response". The exam guide is the authoritative document for content and response types, and it lists all four. Prepare for ordering and matching regardless of which page you read last.
That format change rewards a specific kind of study. Incident response runbooks are sequences. Containment before eradication before recovery. Detect, validate scope, contain, eradicate, recover, then root cause. Key material workflows are sequences too. If your notes are a flat list of service names, an ordering question has nothing to grab.
How detection and response actually split
Domain 1 stops at knowing. Domain 2 starts at doing. The boundary between them is the skill AWS added for SCS-C03: validate findings from AWS security services to assess the scope and impact of an event.

Detection owns the telemetry. Organization-wide CloudTrail trails, a dedicated CloudWatch logging account, VPC Flow Logs, transit gateway flow logs, Route 53 Resolver logs. It owns where that lands, which on the current outline means Amazon Security Lake as the log data lake and Amazon OpenSearch Service, Lambda, or Amazon Managed Grafana for normalizing and correlating. It owns the analysis surface, which is CloudWatch Logs Insights, Amazon Athena, and Security Hub findings. Domain 1 also owns the unglamorous third task statement, troubleshooting why a log is missing or a CloudWatch Agent configuration is wrong.
Incident response owns everything after a finding exists. Runbooks in Systems Manager OpsCenter. Testing the plan with AWS Fault Injection Service and AWS Resilience Hub, which is a genuinely new emphasis. Automated remediation through Systems Manager, Step Functions, Lambda, Automated Forensics Orchestrator for Amazon EC2, and Amazon Application Recovery Controller. Capturing logs as forensic artifacts. Containment through network controls, then eradication, then recovery from backups. Root cause analysis with Amazon Detective.
A stem that says "a GuardDuty finding appeared" and asks what to configure is usually Domain 1. A stem that says "a GuardDuty finding appeared" and asks what to do next is Domain 2, and the first answer is almost never "terminate the instance". Validate the scope, preserve the artifacts, contain the blast radius, then remediate.
How to study without wasting a month
Order the weeks by weight, not by the order the domains are printed in.

Week 1. Identity, because it is 20%. IAM Identity Center, Amazon Cognito, MFA, and identity provider integration for authentication. AWS STS and S3 presigned URLs for temporary credentials. Then authorization, which is where the points are. Permission boundaries and session policies for least privilege. ABAC and RBAC driven by tags. IAM Roles Anywhere, IAM paths, resource policies for cross-account access, and role trust policies. Amazon Verified Permissions for application-level authorization. Practice reading a failure and naming the cause with IAM Policy Simulator and IAM Access Analyzer. The old guide asked you to recite Principal, Action, Resource, Condition. The current one assumes you already can and asks you to predict the outcome.
Week 2. Data protection, 18%. In transit means ELB security policies, enforced TLS configuration, AWS PrivateLink, VPC endpoints, AWS Client VPN, and AWS Verified Access. Add the new skill: inter-node encryption for Amazon EMR, Amazon EKS, and SageMaker AI, and Nitro encryption. At rest means choosing between AWS KMS and AWS CloudHSM, and between client-side and server-side encryption, for a stated requirement. Integrity means S3 Object Lock, S3 Glacier Vault Lock, versioning, digital code signing, and file validation. Retention means S3 Lifecycle, Amazon EFS Lifecycle policies, and FSx for Lustre backup policies. Backup means AWS Backup, Amazon Data Lifecycle Manager, AWS DataSync, and ransomware protection. Then Task 5.3, which carries most of what is new: Secrets Manager rotation, imported key material and external key stores, the difference between imported and AWS generated key material, masking through CloudWatch Logs data protection policies and SNS message data protection, and multi-Region keys and certificates through KMS and AWS Private Certificate Authority.
Week 3. Infrastructure security, 18%. Edge first. CloudFront headers, AWS WAF, Shield Advanced, S3 CORS, AWS IoT policies, and rules built on geography, geolocation, rate limiting, and client fingerprinting. Then the new integration skill, which is ingesting data in OCSF format and applying third-party WAF rules. Compute next. Hardened AMIs and container images through EC2 Image Builder and Systems Manager. Instance profiles, service roles, and execution roles. Amazon Inspector for container image and Lambda scanning, GuardDuty for runtime monitoring, Systems Manager Patch Manager for patching, Session Manager and EC2 Instance Connect for administrative access, and Amazon Q Developer or Amazon CodeGuru Security in the pipeline. Then Skill 3.2.7, guardrails for generative AI applications against the GenAI OWASP Top 10 for LLM Applications. Finish with network controls: security groups, network ACLs, AWS Network Firewall, Site-to-Site VPN, AWS Direct Connect, MACsec, north/south and east/west segmentation, and Network Access Analyzer for unnecessary access.
Week 4. Detection, response, and governance, 44% combined. Build one worked incident end to end and write it as an ordered sequence, because the exam now asks for sequences. Then governance. AWS Organizations and Control Tower including custom controls. Organization policies, which on the current outline means SCPs, RCPs, AI service opt-out policies, and declarative policies, not just SCPs. Delegated administrator accounts for centrally managed security services. Root user credential management, centralized root access for member accounts, and break-glass procedures. CloudFormation StackSets, CloudFormation Guard, and cfn-lint for IaC. AWS Firewall Manager for central enforcement. AWS RAM and Service Catalog for sharing. AWS Config, Security Hub, AWS Audit Manager, AWS Artifact, and the Well-Architected Tool for compliance evidence.
Do not spend the month building a second organization "for the cert". Spend it reading stems and naming the control layer before looking at the options.
Traps that look like easy elimination
Specialty items rarely give you one plausible answer and three absurd ones. They give you two controls that both work and one constraint that picks between them.
- A service control policy sets a permissions ceiling on principals in an account. A resource control policy sets one on resources. If the stem is about an external principal reaching your resource, the answer is often the RCP.
- Detection and response are different domains now. "Configure an alert" is Domain 1. "The alert fired, what next" is Domain 2, and validating scope comes before containment.
- Containment comes before eradication, and eradication comes before recovery. Restoring a backup into an environment you have not contained reinfects it.
- AWS KMS and AWS CloudHSM both manage keys. CloudHSM is the answer when the stem names single-tenant hardware, FIPS 140-3 Level 3, or full customer control of the HSM.
- Imported key material means you own rotation and the consequences of losing it. AWS generated key material means AWS can rotate it for you. The current guide asks you to state that difference.
- Masking is not encryption. CloudWatch Logs data protection policies and SNS message data protection obscure sensitive fields in place. A KMS key does not solve that stem.
- Amazon Inspector scans for known vulnerabilities. GuardDuty watches runtime behavior. Amazon Detective explains the root cause after the fact. Security Hub aggregates. They are not interchangeable.
- Amazon Macie finds sensitive data in S3. It does not stop anybody from reading it.
- A bucket policy cannot express row or attribute level intent. Tag-based ABAC and permission boundaries can.
- Bedrock and SageMaker AI appear on the guide as workloads to protect. Training a model is out of scope for the target candidate. An LLM stem is asking about guardrails, not fine-tuning.
- Ordering and matching questions award no partial credit. A half-remembered sequence scores the same as a blank.
- AWS Fault Injection Service and AWS Resilience Hub belong to testing the incident response plan, not to the incident itself.
If deleting the scenario still lets you pick the answer from the service name, the question is easier than the live exam.
How this maps to CloudFluently
Start with the official outline. The AWS Certified Security Specialty (SCS-C03) exam guide carries the task statements and weights, the appendix comparing SCS-C02 and SCS-C03 carries the delta, and the certification page carries the logistics. Browse the full AWS certification prep index for the official practice question set and pretest.
Security Specialty sits on top of associate-level ground, and that ground is already live here. Domain 4 assumes you can read an IAM policy and predict the evaluation result, which is what the AWS Solutions Architect Associate practice exam sets and the Solutions Architect Associate study notes drill. Domain 1 and Domain 6 assume CloudWatch, CloudTrail, AWS Config, and AWS Organizations are already reflexes, which is the AWS CloudOps Associate practice exam sets and the CloudOps Associate study notes. Domain 3 and Domain 5 assume you know how application credentials, roles, and encryption reach a running workload, which is the AWS Developer Associate practice exam sets and the Developer Associate study notes.
Work those associate banks until the fundamentals are automatic, then use this page and the official outline for the specialty-only skills: the Detection and Incident Response split, generative AI guardrails, imported key material, data masking, and the organization policy family beyond SCPs.
Frequently Asked Questions
Is the exam code SCS-C02 or SCS-C03? SCS-C03. SCS-C02 was in use until 1 December 2025 and SCS-C03 began on 2 December 2025. Version 1.0 of the SCS-C03 exam guide is dated 26 March 2026.
What is the passing score? 750 on a scaled range of 100 to 1,000. That is higher than the 720 used on several AWS associate exams. Scoring is compensatory, so there is no per-domain pass requirement.
How many questions count? Fifty scored questions. Fifteen additional unscored research questions are included and are not identified on the exam. The sitting is 65 questions over 170 minutes and costs 300 USD.
Are there really ordering and matching questions? The SCS-C03 exam guide lists four response types: multiple choice, multiple response, ordering, and matching. The exam overview box on the certification page still mentions only multiple choice and multiple response. Prepare for all four, and note that ordering and matching give no partial credit.
Which domain is heaviest? Identity and Access Management at 20%. It gained four points from SCS-C02. Data Protection and Infrastructure Security follow at 18% each.
Does this exam require machine learning? No. Training machine learning models is listed as out of scope for the target candidate. Amazon Bedrock and Amazon SageMaker AI appear as workloads that need guardrails, encryption, and access control.
Do SCS-C02 study notes still work? Partly. IAM, KMS, GuardDuty, and VPC controls carry over. They are thin on the Detection and Incident Response restructure, generative AI guardrails, imported versus AWS generated key material, data masking, and the RCP, AI service opt-out, and declarative policy additions to Task 6.1.
Where is the official outline? AWS Certified Security Specialty (SCS-C03). Use AWS for task statements and weights. Use this page for what changed and how to sequence the study.
Want to learn more?
Check out these related courses to dive deeper into this topic

