StudyToCert

All certifications / Security Specialty / Lessons

AWS Certified Security – Specialty SCS-C03 · Domain 1: Detection

Security monitoring strategy: deciding what to monitor per workload, CloudWatch metrics and alarms, and Route 53 health checks

▶ Watch the overview video

Last reviewed September 29, 2026 · Leer en español

Detection starts with a plan, not a tool. For each workload you ask: what could go wrong, what would it look like in logs or metrics, and who needs to know? A public web application cares about spikes in 4xx and 5xx errors, failed logins and unusual traffic sources. A data platform cares about who reads which buckets and whether encryption settings change. Writing these answers down turns into a monitoring requirement list: which log sources to turn on, which metrics to watch and which alerts to send where.

Amazon CloudWatch is the core metrics and alarm service. AWS services publish metrics automatically, such as CPUUtilization for EC2 or HTTPCode_ELB_5XX_Count for a load balancer, and you can publish custom metrics from applications. A CloudWatch alarm watches one metric (or a math expression over several) against a threshold for a number of periods and changes state to ALARM, which can notify an Amazon SNS topic, trigger Auto Scaling or run an EC2 action. Composite alarms combine several alarms to cut noise, so an on-call engineer is paged only when, for example, errors and latency are both high.

Health checks tell you whether something is reachable and working from the outside. Route 53 health checks probe an endpoint over HTTP, HTTPS or TCP from locations around the world and can also watch a CloudWatch alarm. They drive DNS failover, and Shield Advanced can use them for health-based DDoS detection, which makes attack detection faster and more accurate. Load balancer health checks do a similar job inside a Region, taking unhealthy targets out of service.

For the exam, match the requirement to the right layer. Resource health and performance: CloudWatch metrics and alarms. Reachability from the internet: Route 53 health checks. API activity: CloudTrail. Threats: GuardDuty. Aggregated findings: Security Hub. A good monitoring strategy uses several of these together and routes each signal to someone who can act on it, instead of collecting data nobody reads.

Key terms

CloudWatch alarm
A rule that watches a metric against a threshold over time and changes state to ALARM, which can trigger notifications or actions.
Composite alarm
An alarm whose state depends on a logical combination of other alarms, used to reduce noisy alerts.
Route 53 health check
A probe from AWS locations that tests whether an endpoint responds, or follows a CloudWatch alarm, and can drive DNS failover.
Monitoring requirement
A written statement of what must be observed for a workload, where the data comes from and who is alerted.
Real-world example

A payments API team lists its risks: credential stuffing, a failing database and accidental policy changes. They add a CloudWatch alarm on the WAF blocked-request metric, a Route 53 health check on the public endpoint that Shield Advanced also uses, and an EventBridge rule for IAM policy changes, each sending to the team's SNS topic.

Exam tip: When a question asks how to detect that an application is down or slow, think CloudWatch alarms and health checks; when it asks who did something, think CloudTrail. Do not pick a threat detection service for a pure availability problem.

Check yourself

What does a Route 53 health check add that a CloudWatch CPU alarm does not?

It tests whether the endpoint actually answers from outside, so it catches failures such as a broken listener or network path even when CPU looks normal.

Why use a composite alarm?

To alert only when several conditions are true together, which reduces false alarms and alert fatigue.

Study Security Specialty for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security Specialty study plan