AWS / Specialty / SCS-C03
Security Specialty
Trace permissions, protect evidence and contain incidents. Separate preventive, detective and recovery controls.
THE REVISION PATH
Your topics, in order.
Read. Recall. Explain the alternative.
Monitoring & Audit
Metrics show symptoms, logs explain events, traces follow requests, and audit records identify changes.
IAM Advanced
First identify the caller, then find its grants, its permission ceilings and every applicable explicit deny.
Security & Encryption
Protect the connection, the stored data, the permission to use it and the evidence of misuse separately.
Networking: VPC
A working connection needs the right address, a forward route, permission and a return path.
S3 security
Encryption protects stored bytes, policies authorize callers, and browser rules do neither job for you.
Containers on AWS
Separate the container image, application task, compute capacity and permissions before choosing an orchestrator.
AI Security, Privacy and Governance
Protect the data path and the action path, then keep evidence of both.
Detection Engineering and Incident Response
Prepare, detect, contain, preserve evidence, eradicate, recover and learn.
Policy Evaluation and Security at Scale
A grant, a ceiling, a trust relationship and a network path are four separate checks.
CloudFormation and Systems Manager Operations
Inspect the intended change, the actual state and the identity performing it.
How this guide is organised
Original revision notes arranged around practical decisions. The linked official objectives define the mapped scope; primary documentation supports the explanations. Read each topic, answer without looking, then explain why another option would fail.
- Official exam guide ↗ Scope authority
Revision material supports preparation; it does not guarantee every possible exam question. Check the exam version and official objectives before booking.