Study SCS-C03 incident response for containment, evidence, automation, and recovery sequencing.
Incident response on SCS-C03 is about acting fast without destroying evidence or widening blast radius. AWS is not only testing whether you know how to isolate a resource. It is testing whether the team was prepared before the incident, whether the response path preserves forensic value, and whether containment, eradication, recovery, and root-cause work happen in the right order.
As of May 11, 2026, the current AWS Documentation exam guide splits this domain into two tasks:
That split matters on the exam. If the question is about runbooks, access preparation, blast-radius reduction, testing, or automated remediation design, it belongs in task 2.1. If it is about what to collect, validate, contain, restore, or analyze after an event occurs, it belongs in task 2.2.
AWS currently weights this domain at 14% of scored content.
Start with 2.1 Incident Response Plans and Testing to lock down runbooks, pre-provisioned access, automation, blast-radius reduction, and validation exercises.
Then move to 2.2 Responding to Security Events for forensic evidence capture, finding validation, containment, eradication, recovery, and root-cause analysis.
| If the scenario is really about… | Go first to… |
|---|---|
| runbooks, access readiness, response automation, tabletop exercises, fault injection, or minimizing blast radius before an incident | 2.1 Incident Response Plans and Testing |
| forensic artifacts, log correlation, validating GuardDuty or Security Hub findings, containment, restoring from backup, or Detective-style root cause work | 2.2 Responding to Security Events |
Revisit this chapter when: