Skip to content
Certification architecture map
AWS CERTIFIED · Specialty · SCS-C03

Security

Protect AWS workloads through identity, data protection, detection, infrastructure controls and response planning.

4 study milestonesSelf-pacedApplied exercises

Who this path is for

Build experience securing AWS workloads before specializing. Use the current SCS-C03 guide.

How to use this roadmap

Study each topic, complete the applied exercise, and keep evidence of what you learned. These are original study milestones, not a claim to reproduce the full exam blueprint. Use the linked AWS exam guide to check all in-scope domains before booking.

LEARN → APPLY → EXPLAIN

Your learning roadmap

01

Identity and boundaries

3 focus areas · applied exercise
+
  • IAM evaluation
  • Federation
  • Organization guardrails
Apply it

Threat-model a cross-account access design.

Evidence to keep

Identify escalation paths and the controls that block them.

02

Protect workloads and data

3 focus areas · applied exercise
+
  • Network controls
  • KMS policies
  • Data classification
Apply it

Design key ownership and access for a sensitive document store.

Evidence to keep

Explain key-policy and identity-policy responsibilities.

03

Detect and investigate

3 focus areas · applied exercise
+
  • CloudTrail
  • Security Hub and GuardDuty
  • Evidence retention
Apply it

Create a detection plan for unexpected resource access.

Evidence to keep

List the evidence needed to validate an alert.

04

Respond and govern

3 focus areas · applied exercise
+
  • Containment
  • Recovery
  • Security assurance
Apply it

Write an incident response workflow for exposed credentials.

Evidence to keep

Specify containment actions, evidence preservation and recovery checks.

Put the learning into practice

Related labs cover selected skills. Completing them does not establish exam readiness.