AWS SCS-C03 30-, 60-, and 90-day study plan for detection, incident response, encryption, review loops, and final-week priorities.
This study plan is for AWS Certified Security - Specialty (SCS-C03) candidates who need a structured route through AWS security operations, IAM, data protection, infrastructure controls, detection, incident response, and governance.
SCS-C03 is not a generic cybersecurity vocabulary exam. AWS’s current exam guide validates whether you can secure AWS products and services, reason about cost/security/deployment trade-offs, preserve evidence, and make incident-response decisions under operational pressure.
I verified these current AWS exam facts on May 16, 2026.
| Item | Value |
|---|---|
| Exam | AWS Certified Security - Specialty |
| Exam code | SCS-C03 |
| Questions | 65 total |
| Scoring | 50 scored + 15 unscored (unscored items are not identified) |
| Question types | Multiple choice, multiple response, ordering, and matching |
| Time | 170 minutes |
| Passing score | 750, scaled 100-1000 |
| Cost | 300 USD |
| Target candidate | 3-5 years of experience securing cloud solutions |
| Domain | Weight | What it means for planning |
|---|---|---|
| Identity and Access Management | 20% | Spend the most time on IAM evaluation, SCPs, permission boundaries, resource policies, federation, and cross-account access. |
| Infrastructure Security | 18% | Practice VPC security, endpoint controls, WAF, Shield, Network Firewall, compute hardening, and workload isolation. |
| Data Protection | 18% | Drill KMS, key policies, encryption in transit, S3 controls, secrets, certificates, classification, and backup protection. |
| Detection | 16% | Study CloudTrail, GuardDuty, Security Hub, Config, VPC Flow Logs, monitoring, alerting, and evidence quality. |
| Incident Response | 14% | Learn containment, evidence preservation, compromised credentials, runbooks, automation, validation, and recovery. |
| Security Foundations and Governance | 14% | Cover multi-account governance, secure deployment, audit evidence, compliance evaluation, and supply-chain risk. |
IAM is the largest single domain, but hard questions usually cross domains. A KMS failure may also be an IAM failure. A GuardDuty finding may also be an incident-response sequencing question. A network control may also be a governance or audit-evidence problem.
| Starting point | Typical study time | Best-fit timeline |
|---|---|---|
| You secure AWS workloads or cloud platforms today | 50-75 hours | 30-60 days |
| You know AWS architecture but have less security operations depth | 75-110 hours | 60 days |
| You know cybersecurity but are newer to AWS services | 90-130 hours | 60-90 days |
| You are new to both AWS operations and cloud security | 130+ hours | 90 days before scheduling |
If IAM policy evaluation, KMS key policy behavior, organization guardrails, evidence preservation, and network control placement are still fuzzy, choose the longer route. SCS-C03 punishes shallow “security service recognition.”
Use the same loop every week:
flowchart LR
S["Security scenario"] --> B["Boundary: identity, data, network, or account"]
B --> E["Evidence source"]
E --> R["Response or control"]
R --> Q["Question drill"]
Q --> M["Miss log"]
You do not need a full enterprise lab, but you should be able to explain these paths without guessing:
| Path | What you should know |
|---|---|
| IAM authorization | Identity policy, resource policy, SCP, permission boundary, session policy, federation, and explicit deny behavior |
| KMS access | Key policy, IAM permission, grants, encryption context, cross-account use, and service integration |
| Detection pipeline | CloudTrail, GuardDuty, Security Hub, Config, CloudWatch, VPC Flow Logs, and alert routing |
| Incident response | Detect, preserve evidence, contain, eradicate, recover, validate, and improve |
| Network security | Security groups, NACLs, endpoints, WAF, Shield, Network Firewall, GWLB, and private connectivity |
| Data protection | S3 access, encryption, secrets, certificates, sensitive data discovery, backup, retention, and classification |
| Governance | Organizations, Control Tower, SCPs, delegated admin, audit accounts, secure deployment, and compliance evidence |
Use this only if you already have strong AWS security exposure.
| Week | Focus | What to produce |
|---|---|---|
| 1 | IAM and data protection | An authorization checklist covering IAM, resource policies, SCPs, boundaries, KMS, S3, secrets, and encryption. |
| 2 | Detection and incident response | An incident runbook map covering signals, evidence, containment, automation, and recovery validation. |
| 3 | Infrastructure security | A network/workload control map for WAF, Shield, Network Firewall, endpoints, compute hardening, and segmentation. |
| 4 | Governance, ordering/matching practice, and mixed review | A governance matrix for Organizations, Control Tower, Config, audit trails, secure deployment, and compliance evidence. |
Every study day should create one concrete artifact:
| Artifact | Why it matters |
|---|---|
| Authorization path | Prevents stopping at one IAM Allow when another policy layer blocks access. |
| Key-access checklist | Helps separate S3, IAM, KMS key policy, grants, and service-principal failures. |
| Incident sequence | Prepares for ordering questions and real containment logic. |
| Control map | Shows where a security control belongs: identity, network, data, account, workload, or evidence layer. |
| Miss log | Converts plausible security distractors into reusable decision rules. |
This is the best default route for most candidates.
| Weeks | Focus | What to do |
|---|---|---|
| 1-2 | Identity and Access Management | Drill IAM evaluation, SCPs, permission boundaries, session policies, resource policies, federation, and cross-account roles. |
| 3 | Data Protection | Study KMS, S3 controls, secrets, certificates, encryption in transit, classification, retention, and backup protection. |
| 4 | Detection | Practice CloudTrail, GuardDuty, Security Hub, Config, CloudWatch, VPC Flow Logs, finding triage, and alert routing. |
| 5 | Incident Response | Drill containment, evidence preservation, compromised credentials, isolation, remediation workflows, and recovery validation. |
| 6 | Infrastructure Security | Cover edge security, VPC controls, endpoint security, compute workload hardening, WAF, Shield, Network Firewall, and GWLB. |
| 7 | Security Foundations and Governance | Study multi-account governance, Control Tower, Organizations, secure deployment, compliance evaluation, and audit evidence. |
| 8 | Mixed practice and final repair | Run timed sets, group misses by control boundary, revisit weak chapters, and schedule only if misses are narrow. |
Use this if you are building AWS security depth while studying.
| Phase | Weeks | Outcome |
|---|---|---|
| Identity and data foundation | 1-3 | You can evaluate IAM and KMS failures across identity, resource, organization, and key-policy layers. |
| Detection and response | 4-6 | You can choose evidence sources, route findings, preserve logs, contain threats, and validate recovery. |
| Infrastructure controls | 7-8 | You can place network, edge, endpoint, and compute controls without breaking legitimate access. |
| Governance and audit | 9-10 | You can design account-level guardrails, secure deployment, compliance checks, and audit evidence. |
| Exam execution | 11-12 | You can answer mixed, ordering, and matching scenarios under time pressure. |
| Domain | Drill questions until you can answer… |
|---|---|
| Detection | Which signal proves what happened: API call, configuration change, threat finding, network flow, metric, log, or audit trail? |
| Incident Response | What comes first: preserve evidence, contain, rotate, isolate, revoke, restore, validate, or improve? |
| Infrastructure Security | Where should the control live: edge, subnet, endpoint, firewall, workload, security group, NACL, or policy? |
| Identity and Access Management | Which authorization layer decides the request and where can an explicit deny appear? |
| Data Protection | Which key, policy, encryption mode, secret, certificate, classification, or backup control satisfies the requirement? |
| Security Foundations and Governance | Which account, organization, deployment, audit, or compliance pattern scales the control safely? |
Use the final week for response sequence and cross-domain decision speed.
| Day | Work |
|---|---|
| 7 days out | Reread the cheat sheet and summarize every domain in one failure mode. |
| 6 days out | Drill IAM, SCPs, permission boundaries, resource policies, federation, and KMS access. |
| 5 days out | Drill data protection: S3, KMS, secrets, certificates, encryption in transit, backup, and retention. |
| 4 days out | Drill detection: CloudTrail, GuardDuty, Security Hub, Config, CloudWatch, VPC Flow Logs, and alert routing. |
| 3 days out | Drill incident response ordering: preserve, contain, eradicate, recover, validate, and improve. |
| 2 days out | Drill infrastructure security and governance: WAF, Shield, Network Firewall, endpoints, Organizations, Control Tower, audit evidence. |
| 1 day out | Review only your miss log, ordering/matching traps, domain weights, and high-yield security tables. |
SCS-C03 can include ordering and matching items. Practice these explicitly:
| Format | Practice habit |
|---|---|
| Ordering | Write the operational sequence before looking at choices: detect, preserve evidence, contain, eradicate, recover, validate, improve. |
| Matching | Match by control purpose, not service familiarity: threat finding, API audit, config compliance, key control, sensitive data discovery, network telemetry, or governance boundary. |
For ordering and matching, partial intuition is not enough. You need the exact sequence or exact pairings.
You are close to ready when:
This is not ideal for a specialty exam, but if you are already near-ready:
Schedule only when your misses are narrow and explainable. If you still answer by service familiarity instead of authorization path, evidence source, containment order, or control boundary, keep studying. SCS-C03 rewards secure reasoning under constraints.