AWS Certified Security – Specialty (SCS-C02) — the complete study guide
The hardest AWS security exam, domain by domain: detection and response, logging, infrastructure, IAM, data protection and governance — plus the service comparisons it tests relentlessly.
This is the hardest exam on this site, and it behaves like a specialty exam should.
So you need working knowledge, not recall. Reading about AWS will not get you through this one. Building things and breaking them will.
Here it is by domain, with the service comparisons the exam keeps coming back to.
Tip
#
#
#
Careful
#
The domain of "which log would show that?".
Things the exam tests hard:
#
The largest domain.
#
Tip
When a question describes access that "should not be possible", trace it through the evaluation order above from the top. The answer is almost always a missing explicit deny, a permissions boundary, or an SCP that never allowed the action in the first place.
#
#
#
Every week here has something you build. That is deliberate — at specialty level, hands-on is not optional.
#
Make a one-page table of these and read it the morning of the exam.
#
#
Working towards this one? It is a big one. Tell me how it goes.
Keep going!
Contents
Exam domains