Study SCS-C03 security foundations, governance, auditability, and continuous compliance controls.
This domain is about proving that security works consistently across accounts and keeps working over time. AWS is not only testing whether you recognize Organizations, Control Tower, Config, Audit Manager, or Firewall Manager. It is testing whether you can turn multi-account structure, central policy, and compliance evidence into a durable operating model instead of one-off fixes.
As of May 11, 2026, the current AWS Documentation exam guide splits this domain into three tasks:
That split matters on the exam. If the question is really about Organizations, Control Tower, delegated administration, root user handling, or organization-wide policy, it belongs in task 6.1. If it is about IaC, StackSets, centrally enforced controls, tagging, or secure resource sharing, it belongs in task 6.2. If it is about Config, Security Hub, Audit Manager, Artifact, or proving compliance evidence, it belongs in task 6.3.
AWS currently weights this domain at 14% of scored content.
Start with 6.1 Multi-Account Strategy and Central Governance to lock down Organizations, Control Tower, delegated administration, organization policies, and root user governance.
Then move to 6.2 Secure and Consistent Resource Deployment for IaC, StackSets, central policy enforcement, tagging, Firewall Manager, and secure cross-account sharing.
Finish with 6.3 Compliance Evaluation and Audit Evidence for Config, Security Hub, Audit Manager, Artifact, notifications, remediation, and architecture review against best practices.
| If the scenario is really about… | Go first to… |
|---|---|
| Organizations, Control Tower, delegated admin, SCPs, RCPs, AI service opt-out, root user MFA, or break-glass design | 6.1 Multi-Account Strategy and Central Governance |
| IaC, StackSets, CloudFormation Guard, cfn-lint, Firewall Manager, tagging, AWS RAM, or secure deployment consistency | 6.2 Secure and Consistent Resource Deployment |
| Config, Security Hub, Audit Manager, Artifact, remediation of noncompliance, or evidence collection for audits | 6.3 Compliance Evaluation and Audit Evidence |
Revisit this chapter when: