SCS-C03 — AWS Certified Security – Specialty Study Plan

A practical study plan for AWS Certified Security – Specialty (SCS-C03), with 7-day, 14-day, 30-day, and 60/90-day preparation paths.

Orientation

This study plan is for candidates preparing for the AWS Certified Security – Specialty (SCS-C03) exam. It is designed for practical scheduling: what to review, when to practice, when to take timed mocks, and how to use missed questions to improve.

Use the official AWS exam guide for SCS-C03 as your objective list. This page is an independent study planning resource and does not claim affiliation with AWS.

The strongest SCS-C03 preparation usually combines:

  • Scenario-based practice questions
  • IAM and policy evaluation review
  • AWS security service selection drills
  • Logging, detection, and incident response workflows
  • Network and infrastructure security review
  • Data protection, encryption, and key management practice
  • Timed mock exams with detailed review

Which plan should you use?

Time until examBest planUse this ifMain goal
7 daysFinal review sprintYou have already studied most topics or cannot move the dateStabilize weak areas and avoid late overload
14 daysFocused planYou know AWS basics but need structured security reviewCover high-value SCS-C03 topics and practice daily
30 daysBalanced planYou can study most days and want a realistic full reviewBuild knowledge, practice, mock, and revise
60 daysFull preparation pathYou need deeper AWS security reviewLearn, apply, test, and remediate weak areas
90 daysFull preparation with spacingYou are starting early or have limited weekly timeAdd repetition, labs, and multiple mock cycles

If you have fewer than 14 days and have not worked with AWS security concepts before, focus on triage rather than attempting to learn every service in depth.

Core SCS-C03 topic rotation

Use these topic clusters throughout the plan. They are not a substitute for the AWS exam guide, but they give you a practical study structure.

Topic clusterWhat to practice
Identity and accessIAM policies, resource policies, roles, trust policies, permissions boundaries, session policies, federation, cross-account access, AWS Organizations, SCPs
Logging and monitoringCloudTrail, CloudWatch, AWS Config, VPC Flow Logs, centralized logging, log integrity, alerting patterns
Threat detection and incident responseGuardDuty, Security Hub, Detective, Inspector, EventBridge-driven response, containment, credential compromise workflows
Infrastructure securityVPC design, security groups, network ACLs, route tables, VPC endpoints, PrivateLink, AWS Network Firewall, load balancer and edge protections
Data protectionKMS, key policies, encryption at rest and in transit, S3 security, Secrets Manager, Certificate Manager, data classification patterns
Governance and compliance operationsAWS Organizations, delegated administration, Config rules, conformance packs, control monitoring, multi-account security architecture
Scenario decision-makingChoosing the least disruptive, most secure, operationally appropriate AWS control for a described requirement

Daily practice rhythm

Use this rhythm on most study days. Adjust the time blocks to your available schedule.

Time blockActionOutput
5 minutesPick one SCS-C03 objective or weak-area tagClear focus for the session
20-30 minutesReview notes, AWS documentation, or architecture diagramsShort topic summary
30-45 minutesAnswer scenario-based practice questionsMark confidence before checking answers
20-30 minutesReview every missed or guessed questionUpdated error log
10-20 minutesDo one hands-on or architecture review taskDiagram, command output, or decision notes
5 minutesWrite tomorrow’s target topicReduced decision fatigue

For weekend or long sessions, do two cycles with a break between them. Do not spend an entire session only reading; SCS-C03 readiness depends heavily on applying concepts in scenarios.

Start with a diagnostic

Before choosing what to study first, take a diagnostic practice set under light time pressure.

StepWhat to doWhy it matters
1Take a mixed SCS-C03 practice set before heavy reviewReveals your real weak areas
2Mark each question as confident, uncertain, or guessedSeparates knowledge from test-taking luck
3Review missed and guessed questions togetherGuessed-correct questions are still risks
4Tag each miss by topicCreates your study order
5Choose the top 3 weak tags for the next 3 study daysKeeps review focused

Use the diagnostic result as a planning tool, not as a prediction of your exam result.

Missed-question review method

A missed question is useful only if you extract the reason you missed it.

Error log fields

FieldWhat to write
Topic tagIAM, KMS, logging, GuardDuty, VPC, S3, Organizations, incident response, etc.
Scenario triggerWhat requirement drove the answer? Least privilege, central logging, encryption, isolation, detection, audit, cost-aware operations
My wrong choiceThe option you selected or almost selected
Correct choiceThe best answer and the AWS service/control involved
Why correctThe exact reason it satisfies the scenario
Why wrong answers failMissing requirement, wrong scope, insecure, too manual, not operationally suitable
Rule to rememberOne sentence you can reuse on future questions
Retest dateWhen you will attempt similar questions again

Common SCS-C03 miss patterns

Miss patternFix
Confusing SCPs with IAM permissionsRemember: SCPs set maximum available permissions; they do not grant access by themselves
Choosing a detection service for a prevention requirementIdentify whether the question asks to prevent, detect, respond, or audit
Ignoring resource policy requirementsFor cross-account access, evaluate identity policy, resource policy, trust policy, and explicit denies
Overlooking explicit denyExplicit deny overrides allows in AWS policy evaluation
Mixing up security groups and network ACLsReview stateful vs stateless behavior and where each control applies
Treating KMS as only an encryption checkboxReview key policies, grants, IAM permissions, rotation, and service integration
Picking manual response when automation is requiredLook for EventBridge, Lambda, Systems Manager, Security Hub automation, or containment workflows
Missing the account scopeDecide whether the answer applies to one account, many accounts, an organization, or delegated admin model

7-day final review sprint

Use this if the exam is one week away. This is not a full learning plan; it is a stabilization plan.

DayFocusStudy actionsPractice target
7Diagnostic and planningTake a mixed timed set. Build your top 3 weak-area list. Review the SCS-C03 exam guide objectives.Mixed diagnostic
6IAM and policy evaluationReview IAM policies, resource policies, trust policies, permissions boundaries, SCPs, cross-account roles, explicit deny.Identity-focused questions
5Logging, monitoring, and detectionReview CloudTrail, CloudWatch, AWS Config, GuardDuty, Security Hub, Detective, VPC Flow Logs, centralized logging.Logging and detection questions
4Infrastructure securityReview VPC controls, security groups, network ACLs, route tables, endpoints, PrivateLink, Network Firewall, WAF, Shield, CloudFront patterns.Network and infrastructure questions
3Data protectionReview KMS, S3 security, Secrets Manager, ACM, encryption in transit, encryption at rest, key policies, access to encrypted data.Data protection questions
2Full timed mockTake one full timed mock. Spend at least the same amount of time reviewing it.Full mock plus review
1Final consolidationReview only your error log, service-selection notes, and high-risk diagrams. Do not add major new material.Light mixed set only

Final 24 hours

Do:

  • Review your error log.
  • Revisit questions you missed twice.
  • Memorize decision rules, not answer letters.
  • Sleep and preserve exam focus.

Do not:

  • Start a new course.
  • Attempt multiple full mocks back to back.
  • Cram obscure service details without scenario context.
  • Rewrite your entire note set.

14-day focused plan

Use this if you have two weeks and can study most days. The plan assumes you already understand basic AWS services and now need security-specialty focus.

DayFocusPrimary workPractice work
1BaselineDiagnostic set, objective review, build weak-area trackerMixed questions
2IAM policy basicsIdentity policies, resource policies, explicit deny, condition keys, least privilegeIAM questions
3Advanced access scenariosCross-account roles, trust policies, permissions boundaries, SCPs, federation, temporary credentialsPolicy scenario drills
4Logging architectureCloudTrail, CloudWatch Logs, AWS Config, VPC Flow Logs, central log accountsLogging questions
5Detection and responseGuardDuty, Security Hub, Detective, Inspector, EventBridge response patternsIncident response questions
6Data protectionKMS, key policies, grants, encryption patterns, S3 access controls, Secrets ManagerEncryption questions
7Review checkpointRetest Days 2-6 weak areas. Update service-selection notes.Timed mixed set
8Network securityVPC routing, security groups, network ACLs, VPC endpoints, PrivateLink, Network FirewallNetwork scenario questions
9Edge and application protectionWAF, Shield, CloudFront security patterns, load balancer controls, certificate handlingEdge security questions
10GovernanceAWS Organizations, SCPs, delegated administration, Config, Security Hub, account structureGovernance questions
11Incident runbooksCredential compromise, exposed S3 bucket, suspicious instance, malware finding, exfiltration indicatorsResponse workflow drills
12Mixed scenario dayPractice mixed questions in timed blocks. Review all guessed answers.Timed mixed blocks
13Full timed mockTake one full mock. Review deeply and tag every miss.Full mock
14Final reviewError log, weak-area retest, decision rules, light review onlyShort mixed set

Stop adding new major topics after Day 12 unless a repeated miss shows a fundamental gap.

30-day balanced plan

Use this if you want enough time for learning, practice, and correction without cramming.

Weekly structure

WeekMain goalEnd-of-week checkpoint
1Establish baseline and master IAM/security foundationsYou can explain AWS policy evaluation and access scope
2Build logging, monitoring, detection, and response workflowsYou can choose the right AWS service for detect/respond scenarios
3Cover infrastructure security and data protection deeplyYou can reason through VPC, KMS, S3, and encryption scenarios
4Timed practice, governance review, and weak-area sprintYou are stable on mixed timed questions

30-day schedule

DaysFocusActions
1DiagnosticTake a mixed diagnostic. Create your error log and weak-area tags.
2-3IAM fundamentalsReview identity policies, resource policies, explicit deny, conditions, roles, trust policies.
4-5Cross-account and organization accessStudy SCPs, permissions boundaries, delegated access, federation, account boundaries.
6IAM practice dayTimed identity-focused question block. Review every miss.
7Weekly reviewRewrite your IAM decision rules from memory.
8-9Logging and auditReview CloudTrail, CloudWatch, AWS Config, log aggregation, audit trails.
10-11Detection servicesReview GuardDuty, Security Hub, Detective, Inspector, Macie, finding workflows.
12Incident responsePractice containment, credential compromise, instance isolation, evidence preservation.
13Timed mixed setMix IAM, logging, detection, and incident response questions.
14Weekly reviewRetest all Week 2 misses.
15-16Network securityReview VPC security groups, network ACLs, routing, endpoints, PrivateLink, Network Firewall.
17Edge and application securityReview WAF, Shield, CloudFront, load balancer security, certificate patterns.
18-19Data protectionReview KMS, key policies, grants, S3 security, Secrets Manager, encryption choices.
20Scenario diagramsDraw network and encryption flows for common scenarios.
21Weekly reviewTimed mixed set across Weeks 1-3.
22GovernanceReview Organizations, SCP strategy, delegated admin, Config, Security Hub, central security accounts.
23Full timed mock 1Take a full timed mock. Do not study during the mock.
24Mock reviewSpend the session only reviewing the mock and updating the error log.
25-26Weak-area sprintStudy the top two weak tags from the mock.
27Full timed mock 2 or long timed setUse a fresh set if available. Review guessed-correct answers too.
28Final remediationRetest repeated misses. Consolidate decision rules.
29Light mixed reviewShort timed set, no heavy new material.
30Final reviewError log, service-selection notes, exam logistics, rest.

60/90-day full preparation path

Use this if you are starting earlier, changing roles, or need hands-on AWS security reinforcement.

60-day path

PhaseDaysFocusDeliverables
Baseline1-5Diagnostic, exam guide mapping, AWS security vocabularyError log, study calendar
IAM foundation6-15IAM policy evaluation, roles, trust, cross-account access, SCPs, boundariesPolicy decision notes
Governance and accounts16-22AWS Organizations, delegated administration, account structure, Config, Security HubMulti-account security diagram
Logging and monitoring23-31CloudTrail, CloudWatch, VPC Flow Logs, Config, centralized loggingLogging architecture notes
Detection and response32-39GuardDuty, Detective, Inspector, Macie, EventBridge workflows, containmentIncident response runbooks
Infrastructure security40-47VPC controls, endpoints, Network Firewall, WAF, Shield, CloudFront, load balancingNetwork security diagrams
Data protection48-53KMS, S3, Secrets Manager, ACM, encryption choices, key policy scenariosEncryption decision notes
Mock and remediation54-58Full timed mock, review, weak-area retestUpdated error log
Final review59-60Light review, decision rules, exam readiness checkFinal checklist

90-day path

For 90 days, keep the same topic order but add spacing and repetition.

Extra timeHow to use it
Add 1 hands-on review day per weekBuild or inspect a sandbox configuration, then write what each control does
Add spaced repetitionRetest old missed questions 3, 7, and 14 days later
Add a second mock cycleUse one mock around the two-thirds point and another near the final week
Add architecture practiceDraw multi-account logging, cross-account access, encrypted data flow, and incident response diagrams
Add service comparison drillsCompare services that appear similar but solve different security problems

A 90-day plan should not mean 90 days of passive reading. Keep weekly practice active.

Hands-on concept review

If you have access to a safe AWS sandbox, use hands-on review to reinforce concepts. Avoid experimenting in production accounts.

ScenarioWhat to inspect or buildWhat you should be able to explain
IAM policy evaluationCompare an identity policy, resource policy, permissions boundary, and SCP in a sample access decisionWhich policy grants, which policy limits, and where explicit deny applies
Cross-account accessTrace a role assumption from Account A to Account BTrust policy vs permissions policy vs caller permissions
Centralized loggingSketch organization-level CloudTrail and log delivery to a security accountWho owns logs, who can modify them, and how alerts are triggered
GuardDuty finding responseMap finding to EventBridge rule, notification, and containment actionDifference between detection, investigation, and response
S3 data protectionReview bucket policy, Block Public Access, encryption settings, access points, and loggingHow public exposure and unauthorized access are prevented
KMS key useInspect key policy, IAM permissions, grants, and service integrationWhy access to the key and access to the data are separate concerns
VPC endpoint securityCompare public service access with VPC endpoint accessHow routing, endpoint policies, and private connectivity affect exposure
Edge protectionCompare CloudFront, WAF, Shield, and load balancer controlsWhich layer each service protects

Optional read-oriented AWS CLI checks can help you connect exam concepts to real configurations:

aws sts get-caller-identity
aws iam get-policy --policy-arn <policy-arn>
aws kms get-key-policy --key-id <key-id> --policy-name default
aws s3api get-public-access-block --bucket <bucket-name>
aws cloudtrail describe-trails
aws guardduty list-detectors

Use commands only in accounts where you are authorized to inspect resources.

Service-selection drills

SCS-C03 questions often test whether you choose the right AWS control for the requirement.

Requirement in scenarioThink first about
Prevent an account or OU from using a serviceAWS Organizations SCPs
Grant cross-account access to a resourceRole trust, identity policy, and resource policy requirements
Detect suspicious activityGuardDuty, Security Hub, CloudTrail, VPC Flow Logs, Detective
Preserve audit historyCloudTrail, centralized logging, log protection, Config history
Respond automatically to findingsEventBridge, Lambda, Systems Manager, Security Hub automation patterns
Encrypt application dataKMS integration, key policy, IAM permissions, data service encryption options
Protect secretsSecrets Manager, rotation patterns, IAM access, audit logging
Reduce public network exposureVPC endpoints, PrivateLink, security groups, route design, WAF or CloudFront where appropriate
Monitor configuration driftAWS Config rules, aggregators, conformance packs
Govern many accountsAWS Organizations, delegated administrator, central security tooling

Timed mock exam strategy

Timed mocks are most useful after you have reviewed enough material to understand the explanations.

Plan lengthWhen to use timed mocks
7 daysOne full timed mock around Day 2 before the exam, then deep review
14 daysOne full timed mock on Day 13, with timed mixed sets earlier
30 daysFull mocks around Days 23 and 27 if fresh questions are available
60 daysOne mock around the final 1-2 weeks, plus timed blocks during the plan
90 daysOne mid-plan mock and one final-week mock, plus weekly timed blocks

Mock review rules

After every mock:

  1. Review all wrong answers.
  2. Review all guessed-correct answers.
  3. Tag each miss by topic and cause.
  4. Identify repeated errors.
  5. Spend the next study session on the top weak tag.
  6. Retest with fresh questions later.

Do not take multiple full mocks in a row without review. The improvement comes from analysis, not from accumulating scores.

Practice readiness checks

Practice scores are not official AWS passing standards, but they can help you decide whether your preparation is stable.

You are trending ready when you can:

  • Complete timed mixed sets without rushing the final questions.
  • Explain why the correct answer is best and why the distractors are weaker.
  • Handle IAM policy evaluation questions consistently.
  • Choose between SCPs, IAM policies, permissions boundaries, and resource policies.
  • Identify the right logging source for an investigation.
  • Match detection findings to response actions.
  • Reason through VPC exposure and traffic flow.
  • Explain KMS access requirements without guessing.
  • Solve multi-account governance scenarios.
  • Avoid repeating the same error-log tags.

If your misses are scattered but explanations make sense, focus on timed practice. If your misses cluster around one topic, pause mixed practice and repair that topic first.

Final-week rules

RuleReason
Stop adding major new material 2-3 days before the examLate overload creates confusion
Review the error log dailyRepeated misses are the highest-value fixes
Use short timed sets, not marathon sessionsKeeps recall sharp without fatigue
Revisit IAM, KMS, logging, and incident responseThese are common security-specialty decision areas
Practice reading the final sentence of each question firstHelps identify the actual requirement
Sleep before the examSecurity scenario questions require careful reasoning

Exam-day question approach

For each scenario, use a consistent process:

  1. Identify the goal: prevent, detect, respond, recover, audit, encrypt, or govern.
  2. Identify the scope: user, role, resource, account, OU, organization, VPC, region, or workload.
  3. Eliminate answers that solve the wrong goal.
  4. Check whether the answer is operationally realistic.
  5. Watch for least privilege, centralized control, automation, and evidence preservation.
  6. If stuck, mark and move on; return after easier questions are complete.

Practical next step

Start with a mixed diagnostic practice set for AWS Certified Security – Specialty (SCS-C03). Build an error log from that result, choose the 7-day, 14-day, 30-day, or 60/90-day path above, and schedule your next three study sessions by weak area rather than by guesswork.

Browse Certification Practice Tests by Exam Family