SCS-C03 exam at a glance
AWS Certified Security – Specialty · Specialty level
| Exam code | SCS-C03 |
|---|---|
| Certification | AWS Certified Security – Specialty |
| Level | Specialty |
| Number of questions | 65 total: 50 scored and 15 unscored |
| Duration | 170 minutes |
| Passing score | 750 on a scale of 100–1,000 |
| Question formats | Multiple choice, multiple response, ordering, and matching |
| Delivery | Pearson VUE testing center or online proctored exam |
| Exam cost | USD 300; EUR 256; AUD 449; JPY 40,000; KRW 394,575; CNY 2,113; or INR 25,659 for Pearson Mindhub voucher purchases only. Applicable taxes may apply. |
| Languages | English, Japanese, Korean, Portuguese (Brazil), Simplified Chinese, and Spanish (Latin America) |
| Certification validity | 3 years |
| Retake policy | After a failed attempt, candidates must wait 14 calendar days. There is no limit on attempts, and the full registration fee applies to each attempt. After passing, the same exam cannot be retaken for two years unless a new exam guide and exam series code are released. |
| Prerequisites | No specific prerequisites are required. |
| Exam guide version | Version 1.0, published 26 March 2026 |
The exam is intended for individuals responsible for securing cloud solutions. The target candidate should have the equivalent of 3–5 years of experience securing cloud solutions.
Skills measured and their weighting
| Skill area | Weight |
|---|---|
| Detection | 16% |
| Incident Response | 14% |
| Infrastructure Security | 18% |
| Identity and Access Management | 20% |
| Data Protection | 18% |
| Security Foundations and Governance | 14% |
Source: aws.amazon.com — official SCS-C03 exam page. Figures were checked against AWS official documentation and certification policies. Confirm current details there before booking.
The full bank covers every domain, with timed mode and per-domain scoring.
SCS-C03 Practice Questions By Domains
6 domains covered1. Infrastructure Security
6 free questions available
2. Identity and Access Management
7 free questions available
3. Detection
6 free questions available
4. Data Protection
5 free questions available
5. Incident Response
3 free questions available
6. Security Foundations and Governance
3 free questions available
Practice the full exam, not a sample
Unlock the full bank and practise every domain end to end.
Unlock all 230 questionsStart Here: How to Use This Practice Set
Preparing for the AWS Certified Security – Specialty exam is easier when every practice question has a clear purpose. An effective SCS-C03 practice test helps you apply AWS security services to realistic situations, check what you understand, and decide which topics need more review. You can also find your certification practice test before building a study schedule for SCS-C03 or another active certification.
SCS-C03 is the current AWS Security – Specialty exam. It replaced SCS-C02, which was used until December 1, 2025; SCS-C03 has been in use since December 2, 2025. The updated version separates detection from incident response, emphasizes identity and access management, and addresses newer security concerns such as generative AI protections, centralized account controls, sensitive data masking, and modern encryption practices. Candidates should therefore check every book, course, and question set for the exact SCS-C03 code.
This page explains what the current exam tests, how its six domains are weighted, how practice questions should be used, and what to expect during registration and exam day. All exam facts were checked against the current AWS certification page, official SCS-C03 exam guide, AWS testing information, and AWS certification policies.
What Is the AWS SCS-C03 Exam?
SCS-C03 is the exam code for AWS Certified Security Specialty. It is designed for professionals responsible for securing cloud solutions. The exam validates whether a candidate can protect AWS workloads, detect suspicious activity, respond to incidents, manage identities and permissions, secure data, and apply governance controls across AWS environments.
The exam is not limited to remembering security-service definitions. A typical scenario may describe a multi-account organization, an unusual security finding, a missing log source, an exposed workload, an authorization failure, or an encryption requirement. You must select the response that solves the problem while meeting technical, security, cost, and operational requirements.
According to the official SCS-C03 exam guide, candidates should understand how to:
- Apply data classifications and AWS data-protection mechanisms
- Implement encryption methods and AWS encryption services
- Use secure internet protocols and related AWS controls
- Secure production environments with AWS services and features
- Balance security, cost, and deployment complexity
- Understand security operations, threats, and risk
Who Should Take the SCS-C03 Exam?
SCS-C03 is intended for experienced security and cloud professionals. The public AWS certification page describes the target as someone with five years of IT security experience, including two or more years of hands-on experience securing AWS workloads. The exam guide describes the target candidate as having the equivalent of three to five years of experience securing cloud solutions.
Likely candidates include:
- Cloud security engineers
- Security architects
- DevSecOps engineers
- Incident-response professionals working with AWS
- Solutions architects with security responsibilities
- IAM specialists
- Cloud governance and compliance professionals
- Network or platform engineers who secure AWS workloads
AWS does not require another certification before SCS-C03. However, candidates commonly earn AWS Certified Solutions Architect – Associate or Professional first because those paths build useful knowledge of AWS architecture, networking, storage, compute, and shared responsibility.
You are more likely to be ready for SCS-C03 if you can explain not only what an AWS security service does, but also when to choose it, how it integrates with other services, what evidence it produces, and how to troubleshoot it.
Why Use an SCS-C03 Practice Test?
A practice test turns study notes into decisions. It gives you a situation, several possible actions, and a limited amount of time. That process reveals whether you can apply knowledge instead of only recognizing service names.
Practice questions can help you:
- Check your starting level before creating a study plan
- Learn the four response formats used in the current exam guide
- Identify weak domains and misunderstood services
- Practice separating detection, investigation, containment, and recovery actions
- Compare authentication and authorization controls
- Recognize the correct encryption or key-management option
- Build speed for long, scenario-based questions
- Reduce uncertainty about the proctored testing experience
For additional cloud-security and AWS preparation, View all AWS practice tests and select material that matches the exact active exam code.
Do not use practice questions only to memorize a correct letter. Review the explanation and identify the security principle behind the answer. A memorized option may not help when a new scenario changes the account structure, data classification, threat, compliance rule, or operational requirement.
SCS-C03 Domains and Exam Weightings
The scored portion of SCS-C03 is organized into six domains:
Domain 1: Detection — 16%
Detection covers the monitoring, logging, alerting, and analysis needed to identify security problems. You should know how to collect the right evidence, centralize findings, create alerts, and troubleshoot missing or incorrect security data.
Important topics include:
- Amazon GuardDuty, AWS Security Hub, Amazon Macie, and Amazon Security Lake
- AWS CloudTrail, CloudWatch Logs, VPC Flow Logs, and Route 53 Resolver logs
- Organization-wide logging and dedicated security accounts
- Metrics, alerts, health checks, dashboards, and automated assessments
- Log storage, normalization, correlation, and integration with third-party security tools
- CloudWatch Logs Insights, Amazon Athena, OpenSearch Service, and Lambda-based processing
- Troubleshooting missing logs, incorrect permissions, and agent configuration
Practice tip: decide what evidence is needed before choosing a logging or detection service. A network-flow question, API-activity question, sensitive-data question, and workload-threat question usually require different sources.
Domain 2: Incident Response — 14%
Incident Response begins after a potential security event has been identified. It covers preparation, investigation, containment, threat removal, recovery, and root-cause analysis.
Focus on:
- Response plans, runbooks, playbooks, and testing procedures
- Preparing access and security tools before an incident
- Reducing blast radius through account and network design
- Automated remediation using Systems Manager, Step Functions, and Lambda
- Capturing logs and system evidence for investigation
- Validating Security Hub, GuardDuty, Inspector, and other service findings
- Containing affected resources and restoring known-good data
- Using Amazon Detective and correlated logs for root-cause analysis
Practice tip: identify the response phase. A question asking how to prepare for an event needs a different answer from one asking how to preserve evidence, isolate a resource, remove a threat, or recover a workload.
Domain 3: Infrastructure Security — 18%
Infrastructure Security covers security at the network edge, inside networks, and across compute workloads. It also includes vulnerability management and secure administrative access.
Study these areas:
- Amazon CloudFront, AWS WAF, AWS Shield Advanced, and rate-based protections
- OWASP threats, edge rules, geographic restrictions, and third-party WAF integrations
- Open Cybersecurity Schema Framework integrations
- Hardened EC2 AMIs and container images
- Amazon Inspector, GuardDuty runtime monitoring, Systems Manager Patch Manager, and EC2 Image Builder
- Service roles, execution roles, and instance profiles for workloads
- Systems Manager Session Manager and EC2 Instance Connect
- Security groups, network ACLs, AWS Network Firewall, and network segmentation
- Site-to-Site VPN, Direct Connect, MAC Security, and AWS Verified Access
- Security protections for generative AI applications
SCS-C03 specifically includes protections and guardrails for generative AI applications. Candidates do not need to train machine-learning models, but they should understand security concerns such as controlling access, protecting data, filtering unsafe interactions, and reducing risks described by recognized GenAI security guidance.
Domain 4: Identity and Access Management — 20%
Identity and Access Management is the largest SCS-C03 domain. It covers authentication—proving who or what an identity is—and authorization—deciding what that identity may do.
Key topics include:
- IAM Identity Center, Amazon Cognito, MFA, and external identity providers
- Human, application, and system authentication
- AWS STS temporary credentials and S3 presigned URLs
- Permission sets, AWS Directory Service, and authentication troubleshooting
- IAM roles, trust policies, resource policies, and cross-account access
- Attribute-based and role-based access control
- Permission boundaries, session policies, and least privilege
- IAM Access Analyzer, IAM Policy Simulator, and authorization troubleshooting
- Amazon Verified Permissions and IAM Roles Anywhere
Practice tip: first decide whether a scenario is an authentication or authorization problem. If an identity cannot sign in or receive credentials, investigate authentication. If the identity is known but an action is allowed or denied incorrectly, investigate authorization and policy evaluation.
Domain 5: Data Protection — 18%
Data Protection covers data in transit, data at rest, backups, secrets, certificates, and cryptographic key materials.
Study:
- TLS policies, private access, VPC endpoints, PrivateLink, Client VPN, and Verified Access
- Inter-resource encryption for services such as EKS, EMR, and SageMaker AI
- AWS KMS, AWS CloudHSM, client-side encryption, and server-side encryption
- S3 Object Lock, S3 Glacier Vault Lock, versioning, and code signing
- Data lifecycle, retention, secure replication, AWS Backup, and ransomware protection
- AWS Secrets Manager and credential rotation
- Imported key material, external key stores, and AWS-generated key material
- Sensitive-data masking in CloudWatch Logs and Amazon SNS
- Multi-Region keys and certificate management with AWS Private CA
Practice tip: write down the exact requirement. “Encrypt data,” “customer controls keys,” “keys remain outside AWS,” “protect against deletion,” “rotate credentials,” and “mask sensitive values” point to different services and configurations.
Domain 6: Security Foundations and Governance — 14%
This domain covers the controls used to manage security consistently across accounts and evaluate compliance.
Focus on:
- AWS Organizations and AWS Control Tower
- Service control policies, resource control policies, AI service opt-out policies, and declarative policies
- Delegated administrator accounts for security services
- Root-user protection, centralized root access, MFA, and break-glass procedures
- Infrastructure as code, CloudFormation StackSets, CloudFormation Guard, and cfn-lint
- Central policy deployment with AWS Firewall Manager
- Secure resource sharing with AWS RAM and AWS Service Catalog
- AWS Config rules, conformance packs, aggregation, and automated remediation
- AWS Audit Manager, AWS Artifact, Security Hub, and the AWS Well-Architected Tool
Practice tip: account-level governance questions usually need a central solution. Repeating manual changes in every member account is rarely the best long-term design when AWS Organizations, Control Tower, delegated administration, StackSets, or Firewall Manager can enforce consistent controls.
What Changed from SCS-C02 to SCS-C03?
SCS-C03 is not simply SCS-C02 with a new code. AWS reorganized the domains and added or expanded several current security topics.
Major changes include:
- Detection and Incident Response are now separate domains.
- Identity and Access Management increased from 16% to 20%.
- The governance domain was renamed Security Foundations and Governance.
- SCS-C03 adds validation of security-service findings during incidents.
- It adds OCSF and third-party WAF integration examples.
- It includes protections for generative AI applications.
- Data Protection includes inter-resource encryption, imported key material, sensitive-data masking, and key or certificate management across Regions.
- Governance includes newer organization-wide policies and centralized controls.
The official AWS comparison of SCS-C02 and SCS-C03 confirms that SCS-C03 has been in use since December 2, 2025. If practice material still uses the old six-domain names and weights, do not assume it fully covers the current test.
AWS Services to Prioritize for SCS-C03 Practice
The official service list is broad because security affects almost every AWS workload. Organize your review by security purpose:
| Security purpose | Services and features to understand |
| Detection and findings | GuardDuty, Security Hub, Macie, Inspector, Security Lake |
| Logging and analysis | CloudTrail, CloudWatch, Athena, OpenSearch Service, VPC Flow Logs |
| Incident response | Systems Manager, Step Functions, Lambda, Detective, AWS Backup |
| Edge and network security | WAF, Shield Advanced, Network Firewall, CloudFront, Verified Access |
| Identity | IAM, IAM Identity Center, STS, Cognito, Directory Service, Verified Permissions |
| Data security | KMS, CloudHSM, Secrets Manager, ACM, AWS Private CA, S3 Object Lock |
| Governance | Organizations, Control Tower, Config, Audit Manager, Artifact, Firewall Manager |
AWS notes that its SCS-C03 in-scope service list is non-exhaustive and may change. Learn the security role of each service rather than attempting to memorize a large list without context.
How Is the SCS-C03 Exam Scored?
The exam reports a scaled score from 100 to 1,000, and the minimum passing score is 750. A scaled score is not a raw percentage. A score of 750 does not necessarily mean exactly 75% of the questions were answered correctly.
AWS uses scaled scoring because candidates may receive different exam forms with small differences in question difficulty. Statistical scaling allows the result to represent the same performance standard across forms.
Of the 65 questions, 50 affect your score and 15 are unscored. AWS uses the unscored questions to evaluate possible future scored items. They are not identified, so answer every question seriously.
Unanswered questions are scored as incorrect, and there is no penalty for guessing. If time is nearly finished, choose your best answer instead of leaving an item blank.
What Question Types Appear on SCS-C03?
The current exam guide documents four response types:
- Multiple choice: Choose one correct answer from four options.
- Multiple response: Choose two or more correct answers from at least five options.
- Ordering: Select the required steps and place them in the correct sequence.
- Matching: Match each prompt with its correct response.
The public AWS exam overview summarizes the format as multiple choice or multiple response, while the more detailed current exam guide also documents ordering and matching. Practice all four formats so the interface and response method do not distract you from the security problem.
For ordering questions, identify the required starting condition, dependency, and final outcome. For matching questions, solve the most certain pair first, then use the remaining choices to complete the set.
Can I Take the SCS-C03 Exam Online?
Yes. SCS-C03 can be taken through Pearson VUE online proctoring or at a Pearson VUE testing center. AWS says online proctoring is available for all AWS Certification exams.
For an online appointment, you need:
- A compatible computer with a webcam and microphone
- A stable internet connection
- A quiet, private, well-lit room
- A clear desk without notes, mobile devices, or extra screens
- Identification that meets the requirements in your confirmation email
Run the Pearson VUE system test on the same computer and connection you plan to use. Avoid relying on a work-managed computer unless you know its security settings allow the exam application. The proctor will monitor the room, your webcam, and your screen during the session.
Online proctor languages and available hours are not identical to exam languages. Confirm that a suitable proctoring option is available when scheduling.
How to Register for SCS-C03
- Sign in to your AWS Certification Account.
- Select the option to schedule a new exam.
- Find AWS Certified Security – Specialty (SCS-C03).
- Continue to Pearson VUE.
- Choose online proctoring or a testing center.
- Select your preferred date, time, and exam language.
- Review the name, ID requirements, time zone, price, and delivery option.
- Pay the fee and read the confirmation email carefully.
AWS allows candidates to reschedule or cancel up to 24 hours before the appointment. Each appointment may be rescheduled twice. Inside the 24-hour period, changes are generally unavailable and the exam fee may be lost. Check the current AWS before-testing policy before changing an appointment.
Six-Week SCS-C03 Study Plan
This plan is designed for candidates who already understand basic AWS architecture and security. Add more time if IAM, networking, logging, or encryption is new to you.
Week 1: Baseline, Detection, and Logging
Take a short diagnostic test without using notes. Study Detection, including CloudTrail, CloudWatch, GuardDuty, Security Hub, Macie, Security Lake, VPC Flow Logs, and log-analysis choices. Create an error log for missed questions.
Week 2: Incident Response
Review preparation, runbooks, evidence collection, finding validation, containment, threat removal, recovery, and root-cause analysis. Practice placing response actions in the correct order.
Week 3: Infrastructure Security
Study edge protections, WAF, Shield Advanced, workload hardening, Inspector, patching, secure administration, network controls, segmentation, hybrid connectivity, and generative AI guardrails.
Week 4: Identity and Access Management
Spend a full week on the largest domain. Review federation, Identity Center, Cognito, STS, roles, trust policies, cross-account access, permission boundaries, session policies, ABAC, RBAC, Access Analyzer, and policy troubleshooting.
Week 5: Data Protection and Governance
Study encryption in transit and at rest, KMS, CloudHSM, Secrets Manager, certificates, backups, retention, imported keys, and data masking. Then review Organizations, Control Tower, SCPs, RCPs, Config, Firewall Manager, Audit Manager, and Artifact.
Week 6: Timed Practice and Final Review
Use Mock Tests Online under closed-book, timed conditions. Complete at least two mixed simulations. Review every mistake, revisit weak objectives in the official guide, and avoid heavy last-minute study on the day before the exam.
How to Use SCS-C03 Practice Questions Effectively
Use practice in three stages:
Stage 1: Learn without time pressure
Answer domain-based questions with documentation available. Focus on understanding why one service or action fits the requirement.
Stage 2: Build speed by domain
Set a time limit for short sets. Track whether errors come from missing knowledge, misreading the scenario, confusing similar services, or rushing.
Stage 3: Simulate the exam
Complete mixed questions in a quiet room without notes. Use the same time-management approach you plan to follow on exam day.
After every set, review:
- Incorrect answers
- Correct answers that were guesses
- Questions that took too long
- Services you confused
- Requirements you overlooked
A useful error log can include the topic, your incorrect assumption, the correct security principle, the official source reviewed, and the date for a second attempt.
SCS-C03 Question-Answering Strategy
Follow a consistent process:
- Read the final sentence first. Determine what action or design the question requests.
- Identify the security phase. Is the problem detection, investigation, response, prevention, identity, protection, or governance?
- Mark the hard requirements. Look for multi-account, least privilege, encryption, evidence retention, automatic remediation, or minimal operational work.
- Remove partial solutions. Some answers solve one part but ignore another requirement.
- Prefer the correct scope. Account-level, organization-level, network-level, workload-level, and data-level controls are not interchangeable.
- Check the order. Detection, evidence preservation, containment, eradication, and recovery should not be mixed without considering the scenario.
- Answer every item. There is no penalty for guessing.
For long IAM questions, separate identity, authentication, authorization, policy scope, and policy evaluation. For data questions, separate confidentiality, integrity, retention, backup, deletion protection, secrets, and key control.
SCS-C03 Exam-Day Checklist
Before an online exam
- Run the required system test.
- Confirm the appointment time and time zone.
- Prepare valid identification.
- Clear the desk and remove prohibited devices.
- Close unnecessary programs.
- Make sure nobody enters the room.
- Join early enough to complete check-in.
Before a test-center exam
- Confirm the address and travel time.
- Review identification requirements.
- Arrive early for check-in.
- Store personal belongings as instructed.
During the exam
- Maintain a steady pace across 170 minutes.
- Flag difficult questions and return later.
- Read multiple-response instructions carefully.
- Check the full sequence in ordering questions.
- Complete every pair in matching questions.
- Submit an informed guess rather than leaving a blank response.
AWS says final results are normally available in the AWS Certification Account within five business days, unless a result requires security or technical review.
What Happens If You Do Not Pass SCS-C03?
AWS requires candidates who fail an exam to wait 14 calendar days before taking it again. There is no general limit on attempts, but the full exam fee must be paid for each attempt.
Use a failed attempt as diagnostic information. Review the score report, compare it with your practice error log, and select the two or three areas that need the most improvement. Do not restart every subject automatically. Target the misunderstanding, complete focused questions, and then use another timed simulation to confirm progress.
SCS-C03 Frequently Asked Questions
Is SCS-C03 the current AWS Security Specialty exam?
Yes. SCS-C03 has been in use since December 2, 2025. SCS-C02 was used until December 1, 2025.
How many questions are on SCS-C03?
The exam has 65 questions. According to the current exam guide, 50 affect your score and 15 are unscored.
How long is the SCS-C03 exam?
The exam duration is 170 minutes.
What is the SCS-C03 passing score?
The minimum passing score is 750 on a scale from 100 to 1,000. This is a scaled score, not a simple percentage.
How much does SCS-C03 cost?
AWS lists the fee as USD $300. Taxes, exchange rates, and local pricing can affect the final checkout amount.
Can SCS-C03 be taken online?
Yes. You can choose Pearson VUE online proctoring or a Pearson VUE testing center.
What question types appear on SCS-C03?
The current exam guide lists multiple-choice, multiple-response, ordering, and matching questions.
Is another AWS certification required first?
No. AWS does not require a previous certification, although candidates commonly earn Solutions Architect – Associate or Professional before taking Security – Specialty.
How long is the certification valid?
AWS Certified Security – Specialty is valid for three years. You must complete an eligible recertification option before it expires to keep the certification active.
Is SCS-C03 difficult?
SCS-C03 is an advanced exam because it combines security operations with AWS service selection, troubleshooting, architecture, and policy decisions. It becomes more manageable when you study the exact current domains and practice applying services to scenarios.
Are practice tests enough to pass?
Practice tests are useful for identifying gaps, learning response formats, and improving time management. They work best with the official exam guide, AWS documentation, hands-on configuration, security labs, and real cloud experience.