This three-day course prepares you for the AWS Certified Security – Specialty exam in its new SCS-C03 version. It covers all six official domains, from threat detection to multi-account governance, from a security engineer's point of view: how to design, control and respond on AWS. Demos, incident case studies and exam-style questions shape every day.
Exam voucher : Exam voucher: included or optional depending on the package — contact us.
Objectives
Set up effective detection through logging and monitoring
Prepare for and run the response to a security incident on AWS
Protect infrastructure: network edge, compute and web application firewall
Design sturdy identity and access management at scale
Encrypt and protect data at rest and in transit
Govern a multi-account environment and demonstrate compliance
Program
Detection (16%)
Logging strategy
Monitoring and alerting
Analysing security findings
Incident response (14%)
Response plans and automation
Containment, investigation and evidence
Infrastructure security (18%)
Edge security and DDoS protection
VPC network controls
Compute hardening
Identity and access management (20%)
Authentication and federation
Policies, authorisation and access troubleshooting
Data protection (18%)
Encryption in transit and at rest
Key and secrets management
Data lifecycle
Security foundations and governance (14%)
Multi-account strategy
Secure, compliant deployment
Compliance assessment
Hands-on scenarios and exam practice
Workshop: from a GuardDuty finding to containment
Reading and fixing IAM policies
Timed mock exam and debrief
Prerequisites
AWS targets candidates with three to five years of experience securing cloud solutions
Good command of IAM, VPC and common AWS services
Grounding in encryption, logging and incident response
An AWS Associate certification helps but is not required
Target audience
Cloud security engineers and architects
SOC analysts monitoring AWS environments
Cloud administrators in charge of hardening
Technical auditors and compliance leads
The exam
SCS-C03 has 65 questions, 15 of them unscored, in 170 minutes. Alongside multiple-choice and multiple-response items, it includes ordering and matching questions. You need 750 out of 1000, with no per-domain minimum. It runs at Pearson VUE centres or online with a remote proctor, in English, Japanese, Korean, Portuguese (Brazil), Simplified Chinese and Spanish (Latin America); there is no French version. AWS lists the fee at USD 300 and a three-year validity.
Preparation tips
Practise reading IAM policies and predicting their effect.
Replay a full incident scenario, from alert to containment.
Get used to short service names, which the exam now uses.
Frequently asked questions (FAQ)
What changed between SCS-C02 and SCS-C03?
SCS-C03 is organised into six domains, including one on security foundations and governance, and adds ordering and matching questions. SCS-C02 is no longer offered.
Can I take it in French?
No. We therefore practise questions in English during the course, with explanations in French if you prefer.
How much experience do I really need?
AWS targets three to five years of securing cloud environments. In practice, a security engineer who has worked daily on AWS for a couple of years, and who is comfortable with IAM and logging, is usually ready to start.
Are service names abbreviated in the exam?
Yes, some services appear under their short names. A reference list is available during the exam through the Help button.
Is this course relevant for a SOC team?
Yes. The detection and incident response domains map directly to the work of analysts monitoring AWS workloads.
Securevalley training — online and in-person sessions. Contact us for pricing and registration terms.
Securevalley is not a training partner of AWS. AWS, Amazon Web Services and AWS Certified are trademarks of Amazon Web Services, Inc. or its affiliates.