Security
Protect AWS workloads through identity, data protection, detection, infrastructure controls and response planning.
Who this path is for
Build experience securing AWS workloads before specializing. Use the current SCS-C03 guide.
Study each topic, complete the applied exercise, and keep evidence of what you learned. These are original study milestones, not a claim to reproduce the full exam blueprint. Use the linked AWS exam guide to check all in-scope domains before booking.
Your learning roadmap
01Identity and boundaries
3 focus areas · applied exercise
Identity and boundaries
3 focus areas · applied exercise- IAM evaluation
- Federation
- Organization guardrails
Threat-model a cross-account access design.
Identify escalation paths and the controls that block them.
02Protect workloads and data
3 focus areas · applied exercise
Protect workloads and data
3 focus areas · applied exercise- Network controls
- KMS policies
- Data classification
Design key ownership and access for a sensitive document store.
Explain key-policy and identity-policy responsibilities.
03Detect and investigate
3 focus areas · applied exercise
Detect and investigate
3 focus areas · applied exercise- CloudTrail
- Security Hub and GuardDuty
- Evidence retention
Create a detection plan for unexpected resource access.
List the evidence needed to validate an alert.
04Respond and govern
3 focus areas · applied exercise
Respond and govern
3 focus areas · applied exercise- Containment
- Recovery
- Security assurance
Write an incident response workflow for exposed credentials.
Specify containment actions, evidence preservation and recovery checks.
Put the learning into practice
Related labs cover selected skills. Completing them does not establish exam readiness.
