Official blueprint
The SCS-C02 exam covers 2 domains. Each domain has a defined weight — the percentage of exam questions it contributes. Courseiva has 1,851 practice questions mapped across these objectives.
Click any objective to see practice questions for that domain.
Infrastructure Security is 20% of SCS-C02 and covers protecting AWS compute, network and edge resources. Expect scenario questions on VPC security groups versus NACLs, AWS WAF and Shield, Network Firewall, PrivateLink endpoints, EC2 instance access, Systems Manager Session Manager, and hardening with IAM, KMS and logging. Questions test choosing the correct control for a stated threat.
353 practice questions available
Data Protection covers encryption at rest and in transit, KMS key policies and grants, ACM certificate management, S3 bucket policies and Object Lock, and Secrets Manager rotation. SCS-C02 tests these through scenario questions: choosing between SSE-KMS and SSE-S3, troubleshooting AccessDenied from key policies, enforcing TLS with aws:SecureTransport, and designing cross-account key access.
321 practice questions available
Start with the highest-weight domain — that's where most of your exam questions will come from. Work through each objective's practice questions until you can answer at least 85% correctly. Return to lower-weight domains last, and use the full practice test to test cross-domain recall.