AWS Certified Security – Specialty
SCS-C02 is a deep security exam: incident response and threat detection with GuardDuty, Detective and Security Hub; logging and monitoring; infrastructure and network security; advanced IAM including permission boundaries and SCPs; data protection with KMS, CloudHSM, ACM and Macie; and organization-wide security governance.
Ready to sit the mock exam?
The timer starts as soon as you begin. You can flag questions, move freely between them, and review everything before submitting. No sign-in required — sign in afterwards to save the result to your history.
Start SCS-C02 examSkills measured
Threat Detection and Incident Response
14%GuardDuty, Detective, Security Hub, and automated incident response runbooks.
Security Logging and Monitoring
18%CloudTrail, VPC Flow Logs, CloudWatch, and log integrity and analysis.
Infrastructure Security
20%VPC design, edge protection (WAF, Shield), and host and network hardening.
Identity and Access Management
16%IAM policy evaluation, permission boundaries, SCPs, federation, and least privilege.
Data Protection
18%KMS and CloudHSM key management, encryption strategies, and Macie.
Management and Security Governance
14%Organizations, Config, multi-account guardrails, and compliance.