SCS-C02 Exam Blueprint — At a Glance
| # | Domain | Weight | Questions | Practice |
|---|---|---|---|---|
| 3.0 | Infrastructure Security | 20% | 353 | Practice → |
| 5.0 | Data Protection | 18% | 321 | Practice → |
| Total | 38% | 1,851 | ||
Exam reference guide
A concise reference covering every SCS-C02 exam domain — blueprint weights, must-know concepts, common exam traps, and quick-answer summaries. Use this to review the day before your exam or to build your study roadmap.
| # | Domain | Weight | Questions | Practice |
|---|---|---|---|---|
| 3.0 | Infrastructure Security | 20% | 353 | Practice → |
| 5.0 | Data Protection | 18% | 321 | Practice → |
| Total | 38% | 1,851 | ||
Choose and configure Security Groups, NACLs, AWS WAF, Network Firewall, and PrivateLink to protect workloads, then verify access with Reachability Analyzer and harden EC2 using SSM Session Manager instead of SSH.
Key concepts
Watch out for
Choose and troubleshoot SSE-KMS vs SSE-S3, KMS key policies and grants, ACM certificates, S3 Object Lock, and Secrets Manager rotation. Most critical: get KMS key policies and IAM permissions right, since AccessDenied errors usually stem from key policy gaps.
Key concepts
Watch out for