StudyToCert

All certifications / Security Specialty / Cheat sheet

Security Specialty SCS-C03 cheat sheet

Every exam tip and key term from the free Security Specialty lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Detection (16%)

Exam tips

Key terms

CloudWatch alarm
A rule that watches a metric against a threshold over time and changes state to ALARM, which can trigger notifications or actions.
Composite alarm
An alarm whose state depends on a logical combination of other alarms, used to reduce noisy alerts.
Route 53 health check
A probe from AWS locations that tests whether an endpoint responds, or follows a CloudWatch alarm, and can drive DNS failover.
Monitoring requirement
A written statement of what must be observed for a workload, where the data comes from and who is alerted.
Management event
A control-plane API call, such as creating a user or changing a bucket policy, logged by trails by default.
Data event
A high-volume resource operation, such as reading an S3 object or invoking a Lambda function, logged only when enabled.
Organization trail
A trail created from the management or delegated administrator account that logs all member accounts and cannot be changed by them.
Digest file
An hourly signed file with hashes of delivered log files, used to validate log integrity.
Foundational data sources
CloudTrail management events, VPC Flow Logs and DNS logs that GuardDuty analyzes from its own streams.
Protection plan
An optional GuardDuty feature that adds a data source or scanning capability, such as S3 Protection or Runtime Monitoring.
Suppression rule
A filter that automatically archives findings matching criteria, used for known benign activity.
Delegated administrator
A member account given permission by the management account to manage a service for the whole organization.
ASFF
AWS Security Finding Format, the JSON format Security Hub uses for findings from all sources.
Security standard
A set of controls, such as CIS or AWS Foundational Security Best Practices, that Security Hub checks against your resources.
Cross-Region aggregation
A setting that brings findings from linked Regions into one aggregation Region.
Automation rule
A rule that automatically updates or suppresses findings that match criteria when Security Hub receives them.
VPC Flow Logs
Records of IP traffic metadata on network interfaces, subnets or VPCs, including ACCEPT or REJECT, without payloads.
Resolver query logging
A feature that logs DNS queries made by resources in a VPC to the Route 53 Resolver.
S3 server access logs
Best-effort logs of requests made to an S3 bucket, delivered to another bucket.
Traffic Mirroring
A VPC feature that copies actual network packets from an interface to a monitoring target.
CloudWatch Logs Insights
A query language and console for searching and aggregating data in CloudWatch Logs.
Amazon Athena
A serverless SQL engine that queries data where it sits in S3, billed by data scanned.
OCSF
Open Cybersecurity Schema Framework, an open, vendor-neutral schema for security events.
Amazon Security Lake
A service that collects and normalizes security data to OCSF in an S3 data lake owned by the customer.
Event pattern
A JSON filter in an EventBridge rule that selects which events trigger its targets.
Metric filter
A CloudWatch Logs pattern that turns matching log events into a CloudWatch metric.
SNS topic
A publish and subscribe channel that fans out notifications to subscribers such as email or Lambda.
Cross-account event bus
An EventBridge bus in another account that receives events, used to centralize security events.
Service principal
An identifier such as cloudtrail.amazonaws.com that represents an AWS service in policies.
get-trail-status
A CloudTrail API call that shows whether a trail is logging and any recent delivery errors.
aws:SourceArn
A condition key that ties a service principal's permission to one specific resource, such as a trail.
Encryption context
Extra key-value data bound to a KMS operation, used in policies and logged in CloudTrail.

Domain 2: Incident Response (14%)

Exam tips

Key terms

Playbook
A plan for handling one type of incident, including its detection, decision points and runbooks.
Runbook
A step-by-step procedure, ideally automated, for carrying out a response task.
Systems Manager Automation
A service that runs runbook documents with steps that call AWS APIs and scripts, triggered manually or by events.
OpsCenter
A Systems Manager capability that tracks operational issues as OpsItems with related resources and runbooks.
Break-glass access
Emergency credentials, tightly protected and monitored, used only when normal access paths fail.
Forensics account
An isolated AWS account used to store evidence and run analysis away from production.
Game day
A practice event that simulates an incident to test people, processes and tools.
Tabletop exercise
A discussion-based walkthrough of an incident scenario to test roles and decisions.
Deactivate access key
Setting an IAM access key to Inactive so it stops working but still exists for investigation.
Revoke active sessions
An IAM role action that denies all requests from sessions issued before a chosen time.
aws:TokenIssueTime
A condition key holding the time temporary credentials were issued.
Persistence
Changes an attacker makes to keep access, such as creating new users, keys or roles.
Isolation security group
A security group with no or minimal rules used to cut a compromised instance off from the network.
Tracked connection
A flow a stateful security group remembers, which stays open even after the rules that allowed it are removed.
Memory capture
Acquiring a copy of a running system's RAM to preserve volatile evidence.
Termination protection
An EC2 setting that prevents an instance from being terminated through the API or console until turned off.
Behavior graph
Detective's linked model of entities and their activity built from logs and findings.
Finding group
A Detective grouping of related findings and entities that likely belong to one security event.
Event data store
A CloudTrail Lake store of events that can be queried with SQL.
Scoping
Determining the extent of an incident: affected accounts, resources, data and time frame.
Step Functions
A workflow service that coordinates multiple steps with retries, branching and waits, useful for multi-step response.
Automatic remediation
An AWS Config feature that runs a Systems Manager Automation document when a rule finds a noncompliant resource.
Custom action
A Security Hub feature that sends chosen findings to EventBridge when an analyst selects them.
Human approval step
A pause in an automated workflow that waits for a person to confirm a risky action.
Chain of custody
A record of who collected, transferred, stored and accessed each piece of evidence, and when.
Legal hold
An S3 Object Lock setting that prevents deletion of an object version until the hold is removed, with no fixed end date.
Hash
A fixed-length fingerprint of a file, such as SHA-256, used to prove it has not changed.
WORM
Write once, read many: storage that cannot be modified or deleted after writing.
AWS Backup
A service that centrally manages backup plans and recovery points across AWS services and accounts.
Backup Vault Lock
A setting that enforces write-once retention on a backup vault, preventing deletion of recovery points.
Root cause
The underlying weakness that allowed an incident, as opposed to its symptoms.
Post-incident review
A blameless meeting after an incident to document the timeline, causes and improvements.

Domain 3: Infrastructure Security (18%)

Exam tips

Key terms

Web ACL
A set of AWS WAF rules and a default action attached to a protected web resource.
Managed rule group
A maintained set of WAF rules from AWS or a Marketplace seller, such as the core rule set.
Rate-based rule
A WAF rule that blocks or challenges sources whose request count exceeds a limit in a time window.
Count action
A WAF action that records matches without blocking, used to test rules safely.
Shield Standard
Free, automatic protection against common network and transport layer DDoS attacks.
Shield Advanced
A paid service adding enhanced detection, the Shield Response Team, cost protection and automatic layer 7 mitigation.
Shield Response Team
AWS DDoS experts available 24/7 to Shield Advanced customers during attacks.
Firewall Manager
A service that applies WAF, Shield Advanced, security group and firewall policies across an organization.
Origin access control
A CloudFront feature that signs requests to an S3 origin so the bucket can allow only that distribution.
Signed URL
A URL with an expiry and signature that grants access to one CloudFront object.
Signed cookie
A set of cookies that grants access to multiple CloudFront objects without changing their URLs.
Field-level encryption
CloudFront encryption of chosen request fields at the edge with a public key.
Security group
A stateful, allow-only firewall attached to network interfaces.
Network ACL
A stateless subnet firewall with numbered allow and deny rules evaluated in order.
AWS Network Firewall
A managed stateful firewall and intrusion prevention service deployed in VPC subnets.
DNS Firewall
A Route 53 Resolver feature that blocks or alerts on DNS queries for listed domains.
Gateway endpoint
A free route-table-based endpoint for private access to S3 or DynamoDB.
Interface endpoint
An elastic network interface with a private IP that provides PrivateLink access to a service.
Endpoint policy
A policy on a VPC endpoint that limits which actions and resources can be reached through it.
aws:SourceVpce
A condition key holding the ID of the VPC endpoint a request came through.
Site-to-Site VPN
An IPsec VPN with two tunnels between an on-premises gateway and AWS.
Direct Connect
A private, dedicated network connection to AWS that is not encrypted by default.
MACsec
IEEE 802.1AE layer-2 encryption available on supported Direct Connect dedicated connections.
Verified Access
A zero trust service that grants access to applications per request based on identity and device posture.
Session Manager
A Systems Manager capability that provides audited shell access without open inbound ports or SSH keys.
IMDSv2
The token-based version of the instance metadata service that protects instance credentials from SSRF.
Patch baseline
A Patch Manager rule set defining which patches are approved for installation.
EC2 Image Builder
A service that automates building, hardening and testing machine images.
CVE
Common Vulnerabilities and Exposures, a public identifier for a known software vulnerability.
Network reachability finding
An Inspector finding showing that a port on an instance can be reached from outside.
Inspector score
A risk score based on CVSS and adjusted using details of your environment.
SBOM
Software bill of materials, a list of the packages and versions in a workload.
Reachability Analyzer
A tool that analyzes configuration to show whether a network path exists between two resources and what blocks it.
Network Access Analyzer
A tool that finds network paths that violate a defined Network Access Scope.
Network Access Scope
A definition of which network access is or is not allowed, used by Network Access Analyzer.
Mirror filter
Rules that choose which traffic Traffic Mirroring copies.

Domain 4: Identity and Access Management (20%)

Exam tips

Key terms

Implicit deny
The default result for any request that no policy allows.
Explicit deny
A Deny statement that matches a request and overrides every Allow.
Permissions boundary
A managed policy that sets the maximum permissions for one IAM user or role.
Session policy
A policy passed when creating a temporary session that further limits that session's permissions.
Condition key
A named value in the request context, such as aws:SourceIp, that a policy condition can test.
ABAC
Attribute-based access control: granting access by comparing tags on principals and resources.
Policy variable
A placeholder such as ${aws:username} that IAM replaces with a value from the request.
Session tags
Tags passed when assuming a role or federating, used as principal tags for that session.
Trust policy
The resource-based policy on a role that specifies who can assume it.
AWS STS
The Security Token Service, which issues temporary credentials for roles and federated users.
External ID
A unique value required in a role's trust policy to prevent confused deputy attacks by third parties.
Confused deputy
A situation where a trusted entity is tricked into using its permissions on behalf of an unauthorized party.
IAM Identity Center
The AWS service for central workforce sign-in and access to multiple accounts and applications.
Permission set
A template of policies that Identity Center turns into roles in assigned accounts.
SCIM
A standard for automatically provisioning and deprovisioning users and groups between systems.
SAML 2.0
An XML-based standard for exchanging authentication assertions between an identity provider and a service.
User pool
A Cognito user directory that authenticates users and issues JWT tokens.
Identity pool
A Cognito feature that exchanges identity tokens for temporary AWS credentials through IAM roles.
JWT
JSON Web Token, a signed token that carries claims about a user.
Cedar
The open policy language used by Amazon Verified Permissions for application authorization.
IAM Roles Anywhere
A service that lets workloads outside AWS exchange X.509 certificates for temporary role credentials.
Trust anchor
The CA certificate that Roles Anywhere uses to verify workload certificates.
OIDC federation
Trusting tokens from an OpenID Connect provider to assume an IAM role with AssumeRoleWithWebIdentity.
EKS Pod Identity
An EKS feature that maps an IAM role to a Kubernetes service account for pod credentials.
Root user
The identity created with an AWS account, with complete access that IAM policies cannot limit in a standalone account.
Centralized root access
An Organizations feature to remove member account root credentials and perform root tasks through short-term sessions.
sts:AssumeRoot
The STS action used to get a task-scoped root session for a member account.
Credential report
An IAM CSV report of all users' passwords, access keys, their ages and MFA status.
Zone of trust
The account or organization that Access Analyzer treats as trusted when reporting external access.
External access finding
A report that a resource policy allows access from outside the zone of trust.
Unused access finding
A report of unused roles, credentials or permissions over a tracking period.
Archive rule
A rule that automatically archives Access Analyzer findings that match expected patterns.
AccessDenied
The error code returned when an authorization check fails for a request.
Policy simulator
An IAM tool that evaluates policies for a principal, action and resource and explains the result.
decode-authorization-message
An STS command that decodes the detailed reason in some encoded access denied errors.
get-caller-identity
An STS call that returns the account, ARN and user ID of the credentials in use.

Domain 5: Data Protection (18%)

Exam tips

Key terms

ACM
AWS Certificate Manager, which provisions, deploys and renews TLS certificates for AWS services.
ELB security policy
A predefined set of TLS protocol versions and ciphers a load balancer listener accepts.
aws:SecureTransport
A condition key that is true when a request arrives over TLS.
Mutual TLS
TLS in which both the client and server present certificates to authenticate each other.
Customer managed key
A KMS key you create and fully control, including its policy, rotation and deletion.
Key policy
The resource-based policy on a KMS key; it must allow access before IAM policies can grant it.
Grant
A KMS mechanism that delegates specific key operations to a principal and can be retired or revoked.
Encryption context
Non-secret key-value data bound to ciphertext that must match on decrypt and is logged in CloudTrail.
Multi-Region key
One of a set of KMS keys in different Regions sharing the same key ID and key material.
Imported key material
Key material you generate outside AWS and import into a KMS key.
CloudHSM key store
A KMS custom key store backed by a single-tenant CloudHSM cluster you control.
External key store
A KMS custom key store that uses keys held in an HSM outside AWS.
SSE-KMS
S3 server-side encryption using an AWS KMS key, with key policy control and CloudTrail logging.
DSSE-KMS
Dual-layer server-side encryption with KMS keys, applying two layers of encryption to objects.
S3 Bucket Key
A bucket-level key that reduces KMS requests and costs for SSE-KMS.
Bucket owner enforced
An Object Ownership setting that disables ACLs so the bucket owner owns all objects.
Object Lock governance mode
Retention that most users cannot override, but that principals with a bypass permission can.
Object Lock compliance mode
Retention that no one, including root, can shorten or remove until it expires.
Legal hold
An Object Lock flag that prevents deletion until it is removed, with no expiry date.
Backup Vault Lock
An AWS Backup feature that enforces WORM retention on recovery points in a vault.
Secrets Manager rotation
Automatic replacement of a secret's value on a schedule using managed or Lambda-based rotation.
SecureString
A Parameter Store parameter type encrypted with a KMS key.
AWS Private CA
A managed private certificate authority service for issuing internal certificates.
Certificate revocation list
A signed list of certificates a CA has revoked before their expiry.
Managed data identifier
A built-in Macie detection pattern for a type of sensitive data.
Custom data identifier
A user-defined pattern, such as a regular expression with keywords, for Macie to detect.
Automated sensitive data discovery
Macie sampling of objects across buckets to estimate where sensitive data lives.
logs:Unmask
The permission that lets a principal see values masked by a CloudWatch Logs data protection policy.
EBS encryption by default
An account and Region setting that encrypts all new EBS volumes and snapshot copies.
Snapshot copy with encryption
The method for creating an encrypted copy of unencrypted EBS or RDS data.
Transparent Data Encryption
Database-engine encryption for Oracle and SQL Server that encrypts data files.
S3 Batch Operations
A feature that runs an action, such as copy with new encryption, across many S3 objects.
Bedrock Guardrails
Configurable filters for prompts and responses, including content, topic, word and sensitive information filters.
Model invocation logging
A Bedrock setting that records prompts, responses and metadata to CloudWatch Logs or S3.
Prompt injection
An attack that hides instructions in input to make a model ignore its intended rules.
Retrieval-augmented generation
A pattern where a model answers using documents retrieved from a knowledge base.

Domain 6: Security Foundations and Governance (14%)

Exam tips

Key terms

Organizational unit
A group of accounts in AWS Organizations to which policies can be attached.
Landing zone
A well-architected multi-account baseline with shared accounts, logging, identity and guardrails.
Log archive account
A dedicated account that stores logs from all accounts with strict protections.
Control Tower control
A preventive, detective or proactive guardrail managed by Control Tower.
Service control policy
An Organizations policy that limits the maximum permissions of principals in member accounts.
Resource control policy
An Organizations policy that limits the maximum permissions on resources in member accounts.
Declarative policy
An Organizations policy that enforces a baseline configuration of a service, such as EC2 settings.
Data perimeter
A set of guardrails ensuring only trusted identities access trusted resources from expected networks.
Trusted access
An Organizations setting that allows an AWS service to work across the organization's accounts.
Delegated administrator
A member account registered to manage a specific service for the whole organization.
Auto-enable
A setting that turns on a security service automatically for new organization member accounts.
Central configuration
A Security Hub feature to set standards and controls for many accounts and Regions from one place.
StackSet
A CloudFormation feature that deploys one template to multiple accounts and Regions.
Service-managed permissions
A StackSets mode using Organizations that can auto-deploy to new accounts in target OUs.
Launch constraint
A Service Catalog setting that assigns the IAM role used to launch a product.
CloudFormation Guard
A policy-as-code tool that validates templates against rules.
Configuration item
A point-in-time record of a resource's configuration captured by AWS Config.
Config rule
A check that evaluates whether resources meet a desired configuration.
Conformance pack
A collection of Config rules and remediation actions deployed and reported as one unit.
Aggregator
A Config resource that gathers configuration and compliance data from multiple accounts and Regions.
AWS Artifact
A portal for downloading AWS compliance reports and accepting agreements such as the BAA.
AWS Audit Manager
A service that continuously collects evidence from your AWS usage and maps it to audit frameworks.
Assessment report
An Audit Manager output bundling selected evidence for auditors.
Business Associate Addendum
An agreement with AWS required before storing protected health information under HIPAA.
Tag policy
An Organizations policy that standardizes tag keys and allowed values across accounts.
aws:RequestTag
A condition key for tags included in a create or tag request.
aws:TagKeys
A condition key listing the tag keys in a request, used to limit which keys can be set.
Backup policy
An Organizations policy that deploys AWS Backup plans across accounts, often selecting resources by tag.
Shared responsibility model
The division of security duties between AWS (of the cloud) and the customer (in the cloud).
Security pillar
The Well-Architected Framework section with principles and best practices for security.
Trusted Advisor
An AWS service that checks accounts and recommends improvements, including security checks.
STRIDE
A threat modeling mnemonic: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
Study Security Specialty for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Security Specialty study plan