All certifications / Security Specialty / Lessons
Security Specialty SCS-C03 lessons
Study Security Specialty for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security Specialty study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Detection
- Security monitoring strategy: deciding what to monitor per workload, CloudWatch metrics and alarms, and Route 53 health checks
- AWS CloudTrail: management vs data events, organization trails, CloudTrail Lake and log file integrity validation
- Amazon GuardDuty: foundational data sources, protection plans, finding types and a delegated administrator for the organization
- AWS Security Hub: aggregating findings, security standards checks and cross-Region aggregation
- Log sources for detection: VPC Flow Logs, Route 53 Resolver query logs, S3 server access logs, and ELB and CloudFront access logs
- Centralizing and analyzing logs: CloudWatch Logs Insights, Athena on S3, Amazon Security Lake and OpenSearch
- Alerting with Amazon EventBridge rules, SNS notifications and CloudWatch Logs metric filters
- Troubleshooting monitoring and logging: missing log delivery, bucket policies for log delivery and KMS key policies for encrypted logs
Domain 2: Incident Response
- Incident response plans and runbooks on AWS: response phases, Systems Manager Automation runbooks and OpsCenter
- Preparing for incidents: break-glass access, a dedicated forensics account, and game days to test the plan
- Responding to compromised IAM credentials: deactivating access keys, revoking role sessions and reviewing CloudTrail activity
- Containing a compromised EC2 instance: isolation, EBS snapshots, memory capture and preserving evidence
- Investigating and scoping with Amazon Detective and CloudTrail Lake queries
- Automated response: EventBridge with Lambda or Step Functions, Security Hub automation rules and AWS Config remediation
- Forensic evidence handling: S3 Object Lock, chain of custody and tagging evidence
- Recovering after an incident: restoring from AWS Backup, rotating secrets and applying lessons learned
Domain 3: Infrastructure Security
- Edge protection with AWS WAF: web ACLs, managed rule groups, rate-based rules and OWASP Top 10 threats
- DDoS resilience: AWS Shield Standard vs Shield Advanced, CloudFront, Route 53 and AWS Firewall Manager
- CloudFront security: origin access control, signed URLs and signed cookies, security headers and field-level encryption
- VPC traffic controls: security groups vs network ACLs, AWS Network Firewall and Route 53 Resolver DNS Firewall
- Private connectivity: gateway and interface VPC endpoints, endpoint policies, PrivateLink and Transit Gateway segmentation
- Hybrid and remote access: Site-to-Site VPN, Direct Connect with MACsec, Client VPN and Verified Access
- Securing compute: Session Manager instead of SSH, IMDSv2, patching with Patch Manager and hardened images
- Vulnerability management with Amazon Inspector for EC2 instances, ECR container images and Lambda functions
- Network troubleshooting and analysis: VPC Reachability Analyzer, Network Access Analyzer and Traffic Mirroring
Domain 4: Identity and Access Management
- IAM policy types and evaluation logic: identity-based, resource-based, permissions boundaries, session policies and explicit deny
- Writing least-privilege policies: condition keys, attribute-based access control with tags, and policy variables
- Temporary credentials: IAM roles, STS AssumeRole, trust policies, external IDs and the confused deputy problem
- Workforce identity: IAM Identity Center, permission sets, SAML 2.0 federation, SCIM provisioning and MFA
- Application and customer identity: Amazon Cognito user pools vs identity pools, and Amazon Verified Permissions
- Workload identity outside AWS: IAM Roles Anywhere, OIDC federation for CI/CD pipelines, and EKS Pod Identity
- Root user and credential hygiene: protecting the root user, centralized root access, removing long-term keys and credential reports
- Finding and removing excess access: IAM Access Analyzer external and unused access findings, policy generation and last-accessed data
- Troubleshooting access denied errors: reading the error message, CloudTrail, the IAM policy simulator and cross-account checks
Domain 5: Data Protection
- Encryption in transit: TLS certificates from ACM, ELB security policies, enforcing aws:SecureTransport and inter-node encryption
- AWS KMS fundamentals: key types, key policies, grants, envelope encryption, encryption context and key rotation
- Advanced KMS: cross-account key use, multi-Region keys, imported key material and CloudHSM key stores
- S3 encryption and access: SSE-S3, SSE-KMS, DSSE-KMS and SSE-C, S3 Bucket Keys, Block Public Access and Object Ownership
- Data integrity and retention: S3 Object Lock governance vs compliance mode, versioning, MFA Delete and AWS Backup Vault Lock
- Secrets and certificates: Secrets Manager rotation, Parameter Store SecureString and AWS Private CA
- Sensitive data discovery and masking: Amazon Macie and CloudWatch Logs data protection policies
- Encrypting data stores: EBS encryption by default, RDS, Aurora and DynamoDB encryption, and encrypting existing unencrypted resources
- Securing generative AI data: Amazon Bedrock guardrails, private model access with VPC endpoints and invocation logging
Domain 6: Security Foundations and Governance
- Multi-account strategy: AWS Organizations, organizational units, AWS Control Tower landing zones and dedicated security accounts
- Organization guardrails: service control policies, resource control policies and declarative policies
- Delegated administration for GuardDuty, Security Hub, Config and other security services
- Secure and consistent deployment: CloudFormation StackSets, Service Catalog and scanning infrastructure as code
- Evaluating compliance: AWS Config rules, conformance packs and aggregators
- Audit evidence and reports: AWS Audit Manager and AWS Artifact
- Tagging for security and governance: tag policies, requiring tags with conditions, and backup policies
- Shared responsibility and security reviews: the Well-Architected security pillar, Trusted Advisor and threat modeling