Study SCS-C03 infrastructure security for network protection, segmentation, inspection, and service hardening.
Infrastructure security on SCS-C03 is about putting the right protection on the real traffic and workload path. AWS is not only testing whether you know the names of WAF, Shield Advanced, Network Firewall, Inspector, or Session Manager. It is testing whether you can choose the right control plane for edge exposure, compute hardening, and network segmentation without solving the wrong layer.
As of May 11, 2026, the current AWS Documentation exam guide splits this domain into three tasks:
That split matters on the exam. If the problem is about public entry points, WAF rules, CloudFront behavior, or edge integrations, it belongs in task 3.1. If it is about EC2, containers, Lambda, images, patching, workload roles, or administrative access, it belongs in task 3.2. If it is about security groups, network ACLs, Network Firewall, hybrid connectivity, Verified Access, or segmentation, it belongs in task 3.3.
AWS currently weights this domain at 18% of scored content.
Start with 3.1 Edge Security Controls to lock down public entry points, WAF logic, Shield, edge protections, and third-party integration choices.
Then move to 3.2 Compute Workload Security Controls for hardened images, workload roles, patching, Inspector, Session Manager, and secure pipeline controls.
Finish with 3.3 Network Security Controls for security groups, network ACLs, Network Firewall, hybrid/multi-cloud connectivity, Verified Access, and segmentation.
| If the scenario is really about… | Go first to… |
|---|---|
| CloudFront, AWS WAF, Shield Advanced, rate limiting, geography, headers, OWASP-style edge threats, or third-party edge rules | 3.1 Edge Security Controls |
| AMI hardening, container image security, Inspector, patching, instance profiles, Session Manager, EC2 Image Builder, or pipeline vulnerability controls | 3.2 Compute Workload Security Controls |
| security groups, network ACLs, Network Firewall, hybrid secure connectivity, MACsec, Verified Access, east-west isolation, or unnecessary access discovery | 3.3 Network Security Controls |
Revisit this chapter when: