Study AWS Certified Security Specialty SCS-C03 from the official six-domain outline. Each lesson teaches a task from first-party AWS docs.
This page shows the complete course curriculum. Enroll now to access all video lessons, hands-on projects, and downloadable resources.
Enroll in This CourseDetection on SCS-C03 starts before a finding exists. Task 1.1 asks you to design monitoring and alerting for an account or an organization. Skills 1.1.1 and 1.1.2 name the first half of that work. Analyze the workload...
Task 1.1 continues after health checks exist. Skills 1.1.3 through 1.1.5 ask you to aggregate security events, turn those events into metrics and dashboards, and run regular assessments. The official examples are Amaz...
Task 1.2 starts with collection. Skills 1.2.1, 1.2.2, and 1.2.6 ask you to pick sources, turn logging on for AWS services and applications, and add network logs that match the design and the threat. The official examp...
Task 1.2 continues after logs arrive. Skills 1.2.3 through 1.2.5 ask you to store them, analyze them, and normalize them so two sources can tell one story. The official examples are Amazon Security Lake, CloudWatch Lo...
Task 1.3 is the unglamorous third Detection task. Skills 1.3.1 and 1.3.2 ask you to read functionality, permissions, and configuration, then fix the misconfiguration that made a log or a health check disappear. The of...
Domain 2 starts after a finding exists. Task 2.1 asks you to design and test the plan before the event. Skills 2.1.1 and 2.1.2 name the first half. Write the runbook. Then leave the account ready so the first hour is...
Skills 2.1.3 and 2.1.4 finish Task 2.1. Test the plan on a quiet day. Then wire the same steps so a finding can run them without a human typing every API.
Task 2.2 is the live event. Skills 2.2.1 through 2.2.3 come first. Capture the logs. Search and correlate. Validate the finding and name the scope. Only then do you contain.
Skills 2.2.4 and 2.2.5 finish the live event. Contain the resource. Eradicate the threat. Recover from a known-good backup. Then explain the root cause.
Domain 3 starts at the network edge. Task 3.1 asks you to pick the control that matches the threat, then put it on the resource that actually takes the request. Skills 3.1.1 and 3.1.2 name that first half. Define the...
Skills 3.1.3 and 3.1.4 finish Task 3.1. Write the rule that matches geography, rate, or a client fingerprint. Then attach a managed or third-party rule group, and send the logs in a format another tool can read.
Task 3.2 starts with the compute image and the role it assumes. Skills 3.2.1 through 3.2.4 name that half. Harden the AMI or container. Attach the right profile or execution role. Scan for CVEs and open paths. Then pa...
Skills 3.2.5 and 3.2.6 finish the human and pipeline half of Task 3.2. Give operators a path that does not open SSH. Then scan the code before it becomes an AMI.
Skill 3.2.7 is the new compute control on SCS-C03. Put a guardrail on a generative AI application the same way you put a WAF on a web app. The official example is GenAI OWASP Top 10 for LLM Applications. On AWS the pr...
Task 3.3 is the path inside the VPC and the path from elsewhere. Skills 3.3.1 through 3.3.5 name the controls. Permit or deny with security groups, NACLs, and Network Firewall. Encrypt the hybrid hop. Use Verified Acc...
Domain 4 starts with who the caller is. Task 4.1 is authentication. Skills 4.1.1 and 4.1.3 name humans, apps, and the trail you read when sign-in fails. IAM Identity Center is workforce. Amazon Cognito is the app. MFA...
Skill 4.1.2 is how AWS hands out keys that die. STS issues a session. An S3 presigned URL issues a time-boxed object action. Neither is a long-lived IAM user access key.
Task 4.2 is what the authenticated principal may do. Skill 4.2.1 names the controls. Amazon Verified Permissions for your app. IAM paths, Roles Anywhere, resource policies, and role trust policies for AWS APIs.
Skills 4.2.2 and 4.2.3 are how you shrink what an identity can do. RBAC is a role per job. ABAC is a tag on the principal and the resource. Least privilege is the intersection of identity policies, permission boundari...
Skills 4.2.4 and 4.2.5 are why a call failed, or why a permission exists that should not. IAM Policy Simulator tests the identity. IAM Access Analyzer finds external, internal, and unused access, validates policies, a...
Domain 5 starts on the wire. Task 5.1 is data in transit. Skill 5.1.1 names the first move. Require encryption when a client connects. Elastic Load Balancing security policies and enforced TLS configurations are the o...
Skill 5.1.2 is the other half of transit. Keep the path off the public internet. AWS PrivateLink, VPC endpoints, AWS Client VPN, and AWS Verified Access are the official examples.
Skill 5.1.3 is encryption between nodes you already own. The official examples are inter-node encryption on Amazon EMR, Amazon EKS, SageMaker AI, and Nitro encryption.
Task 5.2 is data at rest. Skill 5.2.1 is the first question. Which key service, and which encryption type. AWS KMS or AWS CloudHSM. Client-side encryption or server-side encryption.
Skills 5.2.2, 5.2.3, and 5.2.4 finish data at rest. Protect integrity. Then expire or transition on a schedule. Then replicate and back up. Object Lock, Glacier Vault Lock, versioning, S3 and EFS lifecycle, AWS Backup...
Task 5.3 is confidential data, credentials, secrets, and key material. Skills 5.3.1 through 5.3.5 name Secrets Manager, imported key material, external key stores, the difference from AWS-generated material, masking,...
Domain 6 starts with the account map. Task 6.1 is a central strategy for AWS accounts. Skills 6.1.1 and 6.1.2 name AWS Organizations and AWS Control Tower, including optional and custom controls on new and existing en...
Skills 6.1.3 and 6.1.5 finish the account strategy. Implement organization policies. Then manage root user credentials. The official examples are SCPs, RCPs, AI service opt-out policies, declarative policies, centrali...
Task 6.2 is a consistent deployment strategy. Skills 6.2.1 and 6.2.3 name infrastructure as code and a central policy source. CloudFormation StackSets, third-party IaC, CloudFormation Guard, cfn-lint, and AWS Firewall...
Skill 6.2.4 is sharing a resource instead of copying it. AWS Service Catalog and AWS Resource Access Manager are the official examples.
Task 6.3 is evaluate compliance. Skill 6.3.1 detects and remediates with AWS Config and Security Hub. Skill 6.3.2 collects evidence with AWS Audit Manager and AWS Artifact. Skill 6.3.3 measures architecture with the A...
Enroll in AWS Security Specialty SCS-C03 Study Notes today and get instant access to all 31 lessons, hands-on projects, and expert support.
Enroll Now - It's Free!