0.1 SCS-C03 Exam Format, Domains & Study Strategy
Key Takeaways
SCS-C03 has 65 questions (50 scored and 15 unidentified unscored items) with a 170-minute time limit and costs $300 USD.
Results are pass/fail on a 100–1,000 scaled score; 750 passes, and scoring is compensatory across domains.
Domain weights are Detection 16%, Incident Response 14%, Infrastructure Security 18%, Identity and Access Management 20%, Data Protection 18%, and Security Foundations and Governance 14%.
New SCS-C03 skills include validating findings, OCSF and third-party edge integrations, generative AI guardrails, inter-resource encryption in transit, and data masking.
Constraint words such as least operational overhead, preventive, organization-wide, and cross-account usually decide between two technically valid answers.
0.1 SCS-C03 Exam Format, Domains & Study Strategy
The AWS Certified Security – Specialty (SCS-C03) exam checks whether you can secure real AWS workloads: choosing the right control, configuring it correctly, and troubleshooting it when it fails. AWS's exam guide describes the target candidate as someone with the equivalent of 3–5 years of experience securing cloud solutions. SCS-C03 replaced SCS-C02, which was used until December 1, 2025; SCS-C03 has been in use since December 2, 2025.
This section explains how the exam works, how its six domains map to this guide, and how to approach the scenario questions.
Exam Logistics at a Glance
| Item | SCS-C03 Detail |
|---|---|
| Questions | 65 total: 50 scored and 15 unscored (the unscored items are not identified) |
| Time | 170 minutes |
| Question types | Multiple choice (one correct answer), multiple response (two or more correct answers out of five or more options), ordering (put 3–5 responses in order), and matching (match responses to 3–7 prompts) |
| Scoring | Scaled score from 100 to 1,000; 750 passes; pass/fail result |
| Scoring model | Compensatory: you need to pass the exam as a whole, not each domain |
| Guessing | Unanswered questions are scored as incorrect, and there is no penalty for guessing |
| Cost | $300 USD (a 50% discount voucher is available after you earn any AWS Certification) |
| Delivery | Pearson VUE test center or online proctored exam |
| Languages | English, Japanese, Korean, Portuguese (Brazil), Simplified Chinese, and Spanish (Latin America) |
| Validity | 3 years; recertify by passing the latest version of the exam |
Ordering and matching items give credit only when every response is placed or matched correctly. The exam uses short names for some AWS services; the full names are available through the Help button during the exam.
The Six Content Domains
| Domain | Weight | Approx. scored items (of 50) | Where this guide teaches it |
|---|---|---|---|
| 1. Detection | 16% | ~8 | Chapters 1–2 |
| 2. Incident Response | 14% | ~7 | Chapters 3–4 |
| 3. Infrastructure Security | 18% | ~9 | Chapters 5–7 (edge, compute, network) |
| 4. Identity and Access Management | 20% | ~10 | Chapters 8–10 |
| 5. Data Protection | 18% | ~9 | Chapters 11–13, plus the data-in-transit sections 7.4–7.6 |
| 6. Security Foundations and Governance | 14% | ~7 | Chapters 14–15 |
The item counts are estimates calculated from the published weights; AWS publishes percentages, not per-domain question counts. Identity and access management carries the most weight, so policy evaluation, permissions boundaries, federation, and troubleshooting access denials deserve extra practice.
What Changed from SCS-C02
AWS reorganized the first two domains: the old "Threat Detection and Incident Response" and "Security Logging and Monitoring" domains became Detection and Incident Response, and Domain 6 was renamed Security Foundations and Governance. New skills include:
- 2.2.3 Validating findings from AWS security services to assess scope and impact.
- 3.1.4 Configuring integrations with edge and third-party services, such as OCSF-format ingestion and third-party WAF rules.
- 3.2.7 Implementing guardrails for generative AI applications, using the OWASP Top 10 for LLM Applications.
- 5.1.3 Inter-resource encryption in transit (Amazon EMR, Amazon EKS, SageMaker AI, Nitro encryption).
- 5.3.3–5.3.5 Imported versus AWS-generated key material, masking sensitive data, and managing keys and certificates across Regions.
Removed topics include the AWS Security Finding Format (ASFF) from Task 1.1, the AWS Security Incident Response Guide, host-based firewalls, basic TCP/IP concepts, the components of a policy statement, general TLS concepts, and S3 static website hosting. Removed from the outline does not mean irrelevant: you still need policy grammar to answer IAM questions, but you won't be tested on it in isolation.
Out of Scope
The exam guide says candidates are not expected to design cryptographic algorithms, analyze traffic at the packet level, architect overall cloud deployments, manage end-user compute resources, or train machine learning models. When an answer option requires one of these, it is usually a distractor.
How to Read SCS-C03 Scenario Questions
Most items are multi-sentence scenarios with four plausible AWS answers. A repeatable method helps:
- Find the constraint words. Phrases such as least operational overhead, most cost-effective, without code changes, immediately, across all accounts, and even if the root user is compromised decide between two otherwise valid answers.
- Classify the control you need. Is the requirement preventive (SCP, RCP, IAM, bucket policy, declarative policy), detective (GuardDuty, Config, Security Hub CSPM, Access Analyzer), responsive (Systems Manager Automation, Step Functions, Lambda), or recovery (AWS Backup, Vault Lock)? Many distractors offer a detective control for a preventive requirement.
- Check scope and ownership. Management account versus member account, single account versus organization, same Region versus multi-Region, same account versus cross-account. For example, SCPs never restrict the management account, and cross-account KMS access needs both the key policy and the caller's IAM policy.
- Prefer managed, native features when the question stresses operational overhead: an organization-level GuardDuty or Access Analyzer configuration beats custom Lambda scanners.
- Watch for retired or renamed services. AWS renames and retires services frequently (for example, AWS Security Hub became Security Hub CSPM alongside a new unified Security Hub, and Amazon CodeGuru Security was discontinued). This guide flags these changes where they matter, and when it says "Security Hub" for standards, controls, security scores, insights, or custom actions, those are Security Hub CSPM features.
Time and Review Strategy
With 170 minutes for 65 items, you have about 2.6 minutes per question. Answer every item on the first pass, flag the ones you are unsure of, and use the remaining time to revisit flagged items. Because unscored items are hidden, treat every question as if it counts.
Study Plan
Work through the chapters in order, then revisit your weakest domain. After each section, answer the quiz questions and read every explanation, including those for questions you got right. Hands-on practice in a sandbox account (writing SCPs, testing key policies, reading CloudTrail events, and running Access Analyzer) turns memorized facts into the judgment the exam measures.
A candidate is planning study time for the AWS Certified Security – Specialty (SCS-C03) exam. How many of the 65 exam questions count toward the candidate's score?
All 65 questions, because every item is weighted equally.
50 questions; the other 15 are unscored items that are not identified on the exam.
60 questions; 5 unscored items are marked as beta questions during the exam.
The number varies by candidate because the exam is adaptive.
After taking SCS-C03, a candidate's score report shows 'Needs improvement' for Domain 4 (Identity and Access Management) but an overall scaled score of 780. What is the result?
The candidate passes, because the exam uses a compensatory scoring model and only the overall score must reach 750.
The candidate fails, because every domain must be rated at least 'Meets competencies'.
The result is withheld until the candidate retakes Domain 4 separately.
The candidate passes only if Domain 4 accounts for less than 15% of the exam.
Which of the following topics was added to the SCS-C03 exam outline and did not appear as a skill in SCS-C02?
Formatting findings in the AWS Security Finding Format (ASFF).
Configuring Amazon S3 static website hosting.
Implementing guardrails for generative AI applications by applying the OWASP Top 10 for LLM Applications.
Explaining TCP versus UDP and the OSI model.
An SCS-C03 question asks for the solution that detects public S3 buckets across 200 accounts 'with the least operational overhead.' Two options would technically work: an organization-wide managed service configured from a delegated administrator account, and a custom Lambda function that assumes a role in every account on a schedule. How should the candidate choose?
Choose the custom Lambda function, because custom code gives the most control.
Choose whichever option lists more AWS services, because the exam rewards defense in depth.
Choose neither; questions about overhead always expect a manual review process.
Choose the organization-wide managed service, because the constraint 'least operational overhead' favors native, centrally managed features over custom code.
Sections you finish are checked off in the contents.