A structured learning curriculum covering all official exam domains for the AWS Certified Security Specialty certification.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
19 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery SCS-C02term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideIAM Fundamentals and Policy Basics
Objective 1.1 · Design and implement IAM policies
IAM Permissions Boundaries, Roles, and Advanced Concepts
Objective 1.2 · Design and implement IAM roles and permissions boundaries
IAM Identity Federation and Temporary Credentials
Objective 1.3 · Design and implement identity federation and temporary credentials
Data Encryption at Rest with KMS and CloudHSM
Objective 2.1 · Design and implement encryption at rest
Data Encryption in Transit and TLS Termination
Objective 2.2 · Design and implement encryption in transit
Key Management, Secrets Manager, and Parameter Store
Objective 2.3 · Design and implement key management solutions
Data Protection Tools and Services (Macie, S3 Object Lock, Glacier Vault Lock)
Objective 2.4 · Design and implement data protection controls
CloudTrail Logging and Management Events
Objective 3.1 · Design and implement logging and monitoring with CloudTrail
CloudWatch Logs, Metrics, and Alarms for Security
Objective 3.2 · Design and implement logging and monitoring with CloudWatch
Centralized Logging, VPC Flow Logs, and Log Aggregation
Objective 3.3 · Design and implement centralized logging and VPC Flow Logs
Threat Detection with GuardDuty and Inspector
Objective 4.1 · Design and implement threat detection services
Security Hub, Detective, and Automated Response
Objective 4.2 · Design and implement security incident detection and response
Advanced Threat Detection and Incident Response
Objective 4.3 · Design and implement advanced threat detection including Lambda and Step Functions
Security Governance, Compliance, and AWS Config
Objective 5.1 · Design and implement security governance and compliance controls
Auditing, Compliance Frameworks, and Automated Remediation
Objective 5.2 · Design and implement auditing and automated remediation
VPC Security and Network ACLs
Objective 6.1 · Design and implement VPC security components
Security Groups, Network Firewall, and Web Application Firewall
Objective 6.2 · Design and implement security groups and network firewalls
Edge Security, Shield, and DDoS Protection
Objective 6.3 · Design and implement edge security and DDoS protection
Secure Infrastructure Design with Private Subnets and Endpoints
Objective 6.4 · Design and implement secure network infrastructure
Free SCS-C02 practice questions with full explanations. Test what you learn chapter by chapter.
SCS-C02 Practice Questions