AWS Certified Security - Specialty (SCS-C03) practice exam and study path
A free, timed 65-question SCS-C03 practice exam — 170 minutes, the same length as the real exam, scored by domain, with every option explained after you submit. Also 145 practice questions you can check one at a time, a page for every task in the exam guide, and a study path. No sign-up.
$39once
Security in depth: detection, incident response, infrastructure security, identity and access, data protection, and governance across accounts.
The exam
- Exam code
- SCS-C03
- Questions
- 65 questions (50 scored)
- Time
- 170 minutes
- Passing score
- 750 of 1,000 (scaled)
- Exam fee
- $300 (USD)
- Question types
- multiple choice, multiple response, ordering, matching
From AWS's certification page and exam guide, checked Oct 10, 2026. The exam is scored as a whole (compensatory): there is no pass mark per domain.
Domains and weights
Domain 1: Detection
16%
Domain 2: Incident Response
14%
Domain 3: Infrastructure Security
18%
Domain 4: Identity and Access Management
20%
Domain 5: Data Protection
18%
Domain 6: Security Foundations and Governance
14%
On our roadmap this comes after Solutions Architect - Associate or CloudOps Engineer - Associate. See the whole roadmap.
Practice
145 original practice questions, every option explained with the AWS documentation page that proves it. Free, no sign-up; progress stays on this device.
145 questions · practice mode
All domains
Every sample question for this exam, in domain order.
25 questions · practice mode
Topic quiz — Domain 1: Detection
A topic quiz on domain 1 (16% of the exam).
19 questions · practice mode
Topic quiz — Domain 2: Incident Response
A topic quiz on domain 2 (14% of the exam).
27 questions · practice mode
Topic quiz — Domain 3: Infrastructure Security
A topic quiz on domain 3 (18% of the exam).
23 questions · practice mode
Topic quiz — Domain 4: Identity and Access Management
A topic quiz on domain 4 (20% of the exam).
27 questions · practice mode
Topic quiz — Domain 5: Data Protection
A topic quiz on domain 5 (18% of the exam).
24 questions · practice mode
Topic quiz — Domain 6: Security Foundations and Governance
A topic quiz on domain 6 (14% of the exam).
65 questions · 170 min · timed
Full practice exam
The real exam's pace, no feedback until you submit.
65 questions · 170 min · timed · exam pack
Practice exam 1
Included in the Security - Specialty exam pack.
65 questions · 170 min · timed · exam pack
Practice exam 2
Included in the Security - Specialty exam pack.
65 questions · 170 min · timed · exam pack
Practice exam 3
Included in the Security - Specialty exam pack.
More practice exams
The lessons, the sample questions on every task page and the first full practice exam are free and stay free. A pack adds the further timed SCS-C03 practice exams.
Security - Specialty exam pack
$39once
- Every paid SCS-C03 practice exam, timed, with every option explained
- The next version of this exam included when it changes
- Lifetime access — one payment, no subscription
- 14-day refund, no conditions
- 14-day refund, no conditions: ask within 14 days of buying and you get the whole payment back.
- No pass guarantee. These are practice exams written by us from the exam guide and the AWS documentation; a score here does not predict your result on the real exam.
Study path
One module per exam domain. Lessons that already exist on BytePatterns are linked; the rest are being written.
Module 1: Detection
1What to watch: monitoring requirements, health checks and CloudWatch alarmsTask 1.1
Partly covered by: CloudWatch, Alarms & X-Ray, Observability Basics
2Findings in one place: GuardDuty, Macie, Security Hub, Security Hub CSPM and delegated administratorsTask 1.1
Lesson coming
3Assessments on a schedule: AWS Config conformance packs and Systems ManagerTask 1.1
Lesson coming
4Organization trails, a logging account and the CloudWatch agentTask 1.2
Partly covered by: CloudWatch, Alarms & X-Ray
5Network log sources: VPC and transit gateway flow logs, Route 53 Resolver query logsTask 1.2
Lesson coming
6A security data lake: Security Lake, OCSF and subscribersTask 1.2
Lesson coming
7Searching logs: CloudWatch Logs Insights, Athena and OpenSearchTask 1.2
Lesson coming
8Missing logs and silent alarms: permissions, agents and service logging settingsTask 1.3
Lesson coming
Module 2: Incident Response
9Response plans and runbooks: Systems Manager OpsCenter and AutomationTask 2.1
Lesson coming
10Prepared in advance: access, tools, blast radius and Shield AdvancedTask 2.1
Lesson coming
11Testing the plan: Fault Injection Service and Resilience HubTask 2.1
Lesson coming
12Automatic remediation: EventBridge, Step Functions, Lambda and Systems ManagerTask 2.1
Lesson coming
13Forensic evidence: snapshots, memory, logs and their custodyTask 2.2
Lesson coming
14Containment and recovery: isolating instances, revoking credentials, restoring backupsTask 2.2
Lesson coming
15Scope and root cause: validating findings and investigating with DetectiveTask 2.2
Lesson coming
Module 3: Infrastructure Security
16AWS WAF: managed rule groups, OWASP Top 10, geographic rules and fingerprintsTask 3.1
Lesson coming
17Rate limiting at the edge: rate-based rulesTask 3.1
Partly covered by: Rate Limiting
18CloudFront security: origin access control, headers, signed URLs and S3 CORSTask 3.1
Partly covered by: CloudFront & Caching Layers
19DDoS protection: Shield Standard and Shield AdvancedTask 3.1
Lesson coming
20Hardened images: EC2 Image Builder, AMIs and container imagesTask 3.2
Partly covered by: Images, Layers & Multi-Stage Builds
21Roles for compute: instance profiles, service roles and execution rolesTask 3.2
Partly covered by: Shared Responsibility & IAM
22Vulnerabilities and runtime threats: Inspector, GuardDuty and Patch ManagerTask 3.2
Lesson coming
23Admin access without SSH keys: Session Manager and EC2 Instance ConnectTask 3.2
Lesson coming
24Securing the pipeline and generative AI applicationsTask 3.2
Partly covered by: Guardrails
25Security groups, network ACLs and AWS Network FirewallTask 3.3
Partly covered by: VPC: Subnets, NAT & Firewalls
26Hybrid links: Site-to-Site VPN, Direct Connect and MACsec, Verified AccessTask 3.3
Partly covered by: Hybrid Networking & DNS
27Segmentation and unneeded paths: isolated subnets, Network Access AnalyzerTask 3.3
Partly covered by: VPC: Subnets, NAT & Firewalls
Module 4: Identity and Access Management
28Workforce identity: IAM Identity Center, permission sets and external IdPsTask 4.1
Lesson coming
29Customer identity: Cognito user pools, identity pools and MFATask 4.1
Lesson coming
30Temporary credentials: STS, roles and presigned URLsTask 4.1
Partly covered by: Shared Responsibility & IAM, Design a System on AWS
31Troubleshooting sign-in: CloudTrail, Identity Center and Directory ServiceTask 4.1
Lesson coming
32Policy evaluation: identity, resource, trust and session policiesTask 4.2
Partly covered by: Shared Responsibility & IAM
33Cross-account access and IAM Roles AnywhereTask 4.2
Lesson coming
34ABAC with tags, RBAC, and Verified Permissions for applicationsTask 4.2
Lesson coming
35Least privilege: permissions boundaries, Access Analyzer and the policy simulatorTask 4.2
Lesson coming
Module 5: Data Protection
36Requiring TLS: load balancer security policies and policy conditionsTask 5.1
Lesson coming
37Private access: VPC endpoints, PrivateLink, Client VPN and Verified AccessTask 5.1
Partly covered by: VPC: Subnets, NAT & Firewalls
38Encryption between nodes: EMR, EKS, SageMaker AI and NitroTask 5.1
Lesson coming
39Encryption at rest: KMS, CloudHSM, client-side and server-sideTask 5.2
Partly covered by: KMS, Envelope Encryption & Private CA
40Integrity: Object Lock, Glacier Vault Lock, versioning and signingTask 5.2
Lesson coming
41Retention and lifecycle: S3 Lifecycle, EFS lifecycle and backup policiesTask 5.2
Partly covered by: S3: Consistency, Classes, Lifecycle
42Backups that survive ransomware: AWS Backup, Vault Lock and Data Lifecycle ManagerTask 5.2
Lesson coming
43Secrets: Secrets Manager rotation and keeping secrets out of codeTask 5.3
Partly covered by: ConfigMaps, Secrets & Env
44Key material: imported keys, external key stores and multi-Region keysTask 5.3
Partly covered by: KMS, Envelope Encryption & Private CA
45Masking sensitive data: CloudWatch Logs data protection policiesTask 5.3
Lesson coming
46Certificates: ACM and AWS Private CATask 5.3
Partly covered by: KMS, Envelope Encryption & Private CA
Module 6: Security Foundations and Governance
47Organizations and Control Tower: structure, controls and account factoryTask 6.1
Partly covered by: Organizations, SCPs & Control Tower
48Organization policies: SCPs, RCPs, declarative and AI opt-out policiesTask 6.1
Partly covered by: Organizations, SCPs & Control Tower
49Delegated administrators and central root accessTask 6.1
Lesson coming
50Infrastructure as code that stays safe: StackSets, CloudFormation Guard and cfn-lintTask 6.2
Lesson coming
51Tags, Firewall Manager, Service Catalog and AWS RAMTask 6.2
Lesson coming
52Compliance checks: AWS Config rules, aggregators, remediation and Security Hub CSPM controlsTask 6.3
Lesson coming
53Audit evidence: AWS Artifact, Config conformance packs and the Well-Architected ToolTask 6.3
Lesson coming
Every task in the exam guide
The exam guide splits each domain into task statements. Each one has a page with a short summary, the lessons that teach it and open sample questions.
Domain 1: Detection
Domain 2: Incident Response
Domain 3: Infrastructure Security
Domain 4: Identity and Access Management
Domain 5: Data Protection
How these questions are made
- Written by us from the exam guide's task statements and the AWS documentation — never from real exam content.
- Every option carries its own explanation and a link to the AWS page that proves it.
- A question enters a timed exam only after an independent check; until then it is a practice question.
- Results are a plain percentage, per domain too — not an imitation of AWS's scaled score.
Questions about the SCS-C03 practice exam
- Is the SCS-C03 practice exam free?
- Yes. The full practice exam (65 questions, 170 minutes) is free with no sign-up, and so are the 145 practice questions, the task pages and the study path. Your attempts are saved in this browser, on this device.
- How many questions does it have, and is it timed?
- 65 questions in 170 minutes: the same number of questions and the same time as the real SCS-C03 exam. When the time runs out, the exam is submitted as it stands, and unanswered questions count as wrong.
- Are the answers explained?
- After you submit, not during: like the real exam, the timed exam gives no feedback until the end. Then you get your score overall and per exam domain, and every question with each option explained and a link to the AWS documentation page behind it. In practice mode an answer is explained as soon as you check it.
- What does the Security - Specialty exam pack add?
- 3 more timed practice exams (Practice exam 1: 65 questions, 170 minutes; Practice exam 2: 65 questions, 170 minutes; Practice exam 3: 65 questions, 170 minutes), each scored and explained the same way, and the next version of this exam when it changes. One payment, lifetime access, no subscription. Everything above stays free. See the pack.
- Can I get a refund?
- Yes, with no conditions: ask within 14 days of buying and you get the whole payment back. The details are in the terms.
- Is this an official AWS practice exam?
- No. BytePatterns is not affiliated with, endorsed or sponsored by Amazon Web Services. Every question is written by us from the public exam guide and the AWS documentation, never from real exam content, and a score here does not predict your result on the real exam. AWS lists its own preparation resources on its certification page.