AWS Security Specialty SCS-C02 — Study Guide
Practice as you learn. Every concept maps to real exam questions with verified answers in the Amazon exam hub, or drill the full exam with timed practice on ExamRoll.io.
This guide covers each SCS-C02 domain in depth. Pick a domain to go deep, or work through them in order.
The domains
- Identity & Access Management — IAM distinguishes between identities (users, groups, roles) and principals (the authenticated entity making a request). Users are long-lived with
- Threat Detection & Alerting — Amazon GuardDuty is a continuous threat detection service that analyzes CloudTrail management and data events, VPC Flow Logs, DNS query logs, EKS
- Logging, Audit & Forensics — GuardDuty is a managed threat-detection service that continuously ingests three telemetry streams behind the scenes: CloudTrail management (and
- Encryption, KMS & Secrets — AWS KMS supports three broad categories of keys, and picking the right one dictates who controls the key material, where it lives, and how it can be
- Data Protection & S3 — An S3 bucket policy is a resource-based JSON document evaluated alongside identity-based policies. Two rules dominate its behavior. First, an
- Networking & VPC Security — VPC endpoints keep traffic to AWS services on the AWS network, bypassing the public internet, NAT gateways, and internet gateways. There are two
- Edge & Application Security — CloudFront offers two mechanisms to block traffic by country, and choosing between them matters for cost and functionality. The built-in **geo
- Governance, Config & Automation — Service Control Policies form the outermost boundary of what any principal in an AWS Organization can do. An SCP is not an IAM policy — it grants
- Vulnerability, Patch & Host Security — Amazon Inspector is a continuous, agent-supported vulnerability management service that discovers CVEs in EC2 instances, container images stored in
- Container & Serverless Security — ECS Exec provides an interactive shell into a running container — including Fargate tasks — without exposing SSH, bastion hosts, or public IPs. It
- Incident Response & Forensics — The first operational objective when an EC2 instance is suspected of compromise is containment without destruction of evidence. Containment on AWS is
Ready to practice?
- Browse every question with verified answers → — free, with explanations.
- Start timed practice tests on ExamRoll.io → — the full question bank, in 20+ languages.
Pass the whole exam — not just this question
You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.
Pass your exam →