Skip to content
BytePatterns
Specialty · SCS-C03Prep available

AWS Certified Security - Specialty (SCS-C03) practice exam and study path

A free, timed 65-question SCS-C03 practice exam — 170 minutes, the same length as the real exam, scored by domain, with every option explained after you submit. Also 145 practice questions you can check one at a time, a page for every task in the exam guide, and a study path. No sign-up.

Security - Specialty exam pack:

$39once

Security in depth: detection, incident response, infrastructure security, identity and access, data protection, and governance across accounts.

The exam

Exam code
SCS-C03
Questions
65 questions (50 scored)
Time
170 minutes
Passing score
750 of 1,000 (scaled)
Exam fee
$300 (USD)
Question types
multiple choice, multiple response, ordering, matching

From AWS's certification page and exam guide, checked Oct 10, 2026. The exam is scored as a whole (compensatory): there is no pass mark per domain.

Domains and weights

  • Domain 1: Detection

    16%

  • Domain 2: Incident Response

    14%

  • Domain 3: Infrastructure Security

    18%

  • Domain 4: Identity and Access Management

    20%

  • Domain 5: Data Protection

    18%

  • Domain 6: Security Foundations and Governance

    14%

On our roadmap this comes after Solutions Architect - Associate or CloudOps Engineer - Associate. See the whole roadmap.

Practice

145 original practice questions, every option explained with the AWS documentation page that proves it. Free, no sign-up; progress stays on this device.

Your results on this device →

More practice exams

The lessons, the sample questions on every task page and the first full practice exam are free and stay free. A pack adds the further timed SCS-C03 practice exams.

Security - Specialty exam pack

$39once

  • Every paid SCS-C03 practice exam, timed, with every option explained
  • The next version of this exam included when it changes
  • Lifetime access — one payment, no subscription
  • 14-day refund, no conditions
  • 14-day refund, no conditions: ask within 14 days of buying and you get the whole payment back.
  • No pass guarantee. These are practice exams written by us from the exam guide and the AWS documentation; a score here does not predict your result on the real exam.

Study path

One module per exam domain. Lessons that already exist on BytePatterns are linked; the rest are being written.

  1. Module 1: Detection

    1. 1What to watch: monitoring requirements, health checks and CloudWatch alarmsTask 1.1

      Partly covered by: CloudWatch, Alarms & X-Ray, Observability Basics

    2. 2Findings in one place: GuardDuty, Macie, Security Hub, Security Hub CSPM and delegated administratorsTask 1.1

      Lesson coming

    3. 3Assessments on a schedule: AWS Config conformance packs and Systems ManagerTask 1.1

      Lesson coming

    4. 4Organization trails, a logging account and the CloudWatch agentTask 1.2

      Partly covered by: CloudWatch, Alarms & X-Ray

    5. 5Network log sources: VPC and transit gateway flow logs, Route 53 Resolver query logsTask 1.2

      Lesson coming

    6. 6A security data lake: Security Lake, OCSF and subscribersTask 1.2

      Lesson coming

    7. 7Searching logs: CloudWatch Logs Insights, Athena and OpenSearchTask 1.2

      Lesson coming

    8. 8Missing logs and silent alarms: permissions, agents and service logging settingsTask 1.3

      Lesson coming

  2. Module 2: Incident Response

    1. 9Response plans and runbooks: Systems Manager OpsCenter and AutomationTask 2.1

      Lesson coming

    2. 10Prepared in advance: access, tools, blast radius and Shield AdvancedTask 2.1

      Lesson coming

    3. 11Testing the plan: Fault Injection Service and Resilience HubTask 2.1

      Lesson coming

    4. 12Automatic remediation: EventBridge, Step Functions, Lambda and Systems ManagerTask 2.1

      Lesson coming

    5. 13Forensic evidence: snapshots, memory, logs and their custodyTask 2.2

      Lesson coming

    6. 14Containment and recovery: isolating instances, revoking credentials, restoring backupsTask 2.2

      Lesson coming

    7. 15Scope and root cause: validating findings and investigating with DetectiveTask 2.2

      Lesson coming

  3. Module 3: Infrastructure Security

    1. 16AWS WAF: managed rule groups, OWASP Top 10, geographic rules and fingerprintsTask 3.1

      Lesson coming

    2. 17Rate limiting at the edge: rate-based rulesTask 3.1

      Partly covered by: Rate Limiting

    3. 18CloudFront security: origin access control, headers, signed URLs and S3 CORSTask 3.1

      Partly covered by: CloudFront & Caching Layers

    4. 19DDoS protection: Shield Standard and Shield AdvancedTask 3.1

      Lesson coming

    5. 20Hardened images: EC2 Image Builder, AMIs and container imagesTask 3.2

      Partly covered by: Images, Layers & Multi-Stage Builds

    6. 21Roles for compute: instance profiles, service roles and execution rolesTask 3.2

      Partly covered by: Shared Responsibility & IAM

    7. 22Vulnerabilities and runtime threats: Inspector, GuardDuty and Patch ManagerTask 3.2

      Lesson coming

    8. 23Admin access without SSH keys: Session Manager and EC2 Instance ConnectTask 3.2

      Lesson coming

    9. 24Securing the pipeline and generative AI applicationsTask 3.2

      Partly covered by: Guardrails

    10. 25Security groups, network ACLs and AWS Network FirewallTask 3.3

      Partly covered by: VPC: Subnets, NAT & Firewalls

    11. 26Hybrid links: Site-to-Site VPN, Direct Connect and MACsec, Verified AccessTask 3.3

      Partly covered by: Hybrid Networking & DNS

    12. 27Segmentation and unneeded paths: isolated subnets, Network Access AnalyzerTask 3.3

      Partly covered by: VPC: Subnets, NAT & Firewalls

  4. Module 4: Identity and Access Management

    1. 28Workforce identity: IAM Identity Center, permission sets and external IdPsTask 4.1

      Lesson coming

    2. 29Customer identity: Cognito user pools, identity pools and MFATask 4.1

      Lesson coming

    3. 30Temporary credentials: STS, roles and presigned URLsTask 4.1

      Partly covered by: Shared Responsibility & IAM, Design a System on AWS

    4. 31Troubleshooting sign-in: CloudTrail, Identity Center and Directory ServiceTask 4.1

      Lesson coming

    5. 32Policy evaluation: identity, resource, trust and session policiesTask 4.2

      Partly covered by: Shared Responsibility & IAM

    6. 33Cross-account access and IAM Roles AnywhereTask 4.2

      Lesson coming

    7. 34ABAC with tags, RBAC, and Verified Permissions for applicationsTask 4.2

      Lesson coming

    8. 35Least privilege: permissions boundaries, Access Analyzer and the policy simulatorTask 4.2

      Lesson coming

  5. Module 5: Data Protection

    1. 36Requiring TLS: load balancer security policies and policy conditionsTask 5.1

      Lesson coming

    2. 37Private access: VPC endpoints, PrivateLink, Client VPN and Verified AccessTask 5.1

      Partly covered by: VPC: Subnets, NAT & Firewalls

    3. 38Encryption between nodes: EMR, EKS, SageMaker AI and NitroTask 5.1

      Lesson coming

    4. 39Encryption at rest: KMS, CloudHSM, client-side and server-sideTask 5.2

      Partly covered by: KMS, Envelope Encryption & Private CA

    5. 40Integrity: Object Lock, Glacier Vault Lock, versioning and signingTask 5.2

      Lesson coming

    6. 41Retention and lifecycle: S3 Lifecycle, EFS lifecycle and backup policiesTask 5.2

      Partly covered by: S3: Consistency, Classes, Lifecycle

    7. 42Backups that survive ransomware: AWS Backup, Vault Lock and Data Lifecycle ManagerTask 5.2

      Lesson coming

    8. 43Secrets: Secrets Manager rotation and keeping secrets out of codeTask 5.3

      Partly covered by: ConfigMaps, Secrets & Env

    9. 44Key material: imported keys, external key stores and multi-Region keysTask 5.3

      Partly covered by: KMS, Envelope Encryption & Private CA

    10. 45Masking sensitive data: CloudWatch Logs data protection policiesTask 5.3

      Lesson coming

    11. 46Certificates: ACM and AWS Private CATask 5.3

      Partly covered by: KMS, Envelope Encryption & Private CA

  6. Module 6: Security Foundations and Governance

    1. 47Organizations and Control Tower: structure, controls and account factoryTask 6.1

      Partly covered by: Organizations, SCPs & Control Tower

    2. 48Organization policies: SCPs, RCPs, declarative and AI opt-out policiesTask 6.1

      Partly covered by: Organizations, SCPs & Control Tower

    3. 49Delegated administrators and central root accessTask 6.1

      Lesson coming

    4. 50Infrastructure as code that stays safe: StackSets, CloudFormation Guard and cfn-lintTask 6.2

      Lesson coming

    5. 51Tags, Firewall Manager, Service Catalog and AWS RAMTask 6.2

      Lesson coming

    6. 52Compliance checks: AWS Config rules, aggregators, remediation and Security Hub CSPM controlsTask 6.3

      Lesson coming

    7. 53Audit evidence: AWS Artifact, Config conformance packs and the Well-Architected ToolTask 6.3

      Lesson coming

Every task in the exam guide

The exam guide splits each domain into task statements. Each one has a page with a short summary, the lessons that teach it and open sample questions.

How these questions are made

  • Written by us from the exam guide's task statements and the AWS documentation — never from real exam content.
  • Every option carries its own explanation and a link to the AWS page that proves it.
  • A question enters a timed exam only after an independent check; until then it is a practice question.
  • Results are a plain percentage, per domain too — not an imitation of AWS's scaled score.

Questions about the SCS-C03 practice exam

Is the SCS-C03 practice exam free?
Yes. The full practice exam (65 questions, 170 minutes) is free with no sign-up, and so are the 145 practice questions, the task pages and the study path. Your attempts are saved in this browser, on this device.
How many questions does it have, and is it timed?
65 questions in 170 minutes: the same number of questions and the same time as the real SCS-C03 exam. When the time runs out, the exam is submitted as it stands, and unanswered questions count as wrong.
Are the answers explained?
After you submit, not during: like the real exam, the timed exam gives no feedback until the end. Then you get your score overall and per exam domain, and every question with each option explained and a link to the AWS documentation page behind it. In practice mode an answer is explained as soon as you check it.
What does the Security - Specialty exam pack add?
3 more timed practice exams (Practice exam 1: 65 questions, 170 minutes; Practice exam 2: 65 questions, 170 minutes; Practice exam 3: 65 questions, 170 minutes), each scored and explained the same way, and the next version of this exam when it changes. One payment, lifetime access, no subscription. Everything above stays free. See the pack.
Can I get a refund?
Yes, with no conditions: ask within 14 days of buying and you get the whole payment back. The details are in the terms.
Is this an official AWS practice exam?
No. BytePatterns is not affiliated with, endorsed or sponsored by Amazon Web Services. Every question is written by us from the public exam guide and the AWS documentation, never from real exam content, and a score here does not predict your result on the real exam. AWS lists its own preparation resources on its certification page.