AWS Certified Security - Specialty (SCS-C03) Cert Prep
11hIntermediate2026-02-12
Authors

Digital Cloud Training
Course details
Get ready for the AWS Certified Security - Specialty (SCS-C03) exam with this comprehensive course. Learn how to use identity and access management to establish robust security frameworks. Discover infrastructure security techniques to safeguard networks and data, ensuring compliance and integrity. Apply data protection strategies, including encryption and key management, to secure sensitive information in transit and at rest. Explore detection and incident response methods to effectively manage security events and maintain operational readiness. This course is designed for individuals with three to five years of experience in securing cloud solutions. Build on your existing knowledge, prepare for the certification exam, enhance your skills in AWS security, and make a significant impact in your organization.
Concepts
Let's Get Started
- Welcome and How to Use this Course
- The SCS-C03 Exam
- Hands-On Practice - Free Tier vs Sandbox
Getting Started - AWS Accounts
- Section 2 - Introduction
- AWS Account Overview
- HOL Create your AWS Account
- HOL Configure Account and Create a Budget
- HOL Install Tools
AWS IAM Fundamentals
- Section 3 - Introduction
- AWS Identity and Access Management (IAM)
- IAM Roles and Policies
- HOL Create an IAM User and Group
- IAM Authentication and MFA
- HOL Enable Multi-Factor Authentication (MFA)
- AWS Security Token Service (STS)
IAM Access Control
- Section 4 - Introduction
- Identity-Based Policies and Resource-Based Policies
- IAM Policy Evaluation
- IAM Policy Structure
- HOL Using Role-Based Access Control (RBAC)
- HOL Using Attribute-Based Access Control (ABAC)
- HOL Apply Permissions Boundary
- HOL AWS Policy Generator
- HOL IAM Policy Simulator
- IAM Best Practices
- AWS IAM Exam Cram
AWS Organizations and Control Tower
- Section 5 - Introduction
- Centralized Governance with AWS Organizations
- HOL Create Organization and Add Account
- Authorization Policies (SCP RCP)
- Management Policies
- SCP Strategies and Inheritance
- HOL Create Service Control Policy (SCP)
- Use Cases for IAM Roles
- HOL Cross-Account Access to S3
- AWS Control Tower
- AWS Organizations and Control Tower Exam Cram
Infrastructure Security
- Section 6 - Introduction
- Secure VPC Design
- HOL Create a Custom VPC
- Stateful and Stateless Firewalls
- Security Groups and Network ACLs
- HOL Using Security Groups and NACLs
- VPC Peering
- HOL Configure VPC Peering
- VPC Endpoints
- HOL Create VPC Endpoint
- AWS Site-to-Site VPN
- Securing AWS Direct Connect
- HOL VPC Flow Logs
- Accessing Services Access Keys and IAM Roles
- HOL Access Keys and IAM Roles
- Managing Amazon EC2 Security
- HOL Connect to EC2 with Instance Connect
- HOL Connect to EC2 with Session Manager
- AWS Services in Amazon VPC
- Automating Infrastructure as Code
- HOL Create Amazon VPC with CloudFormation
- Compliance with AWS Config
- HOL SSM Automation and Config Rules
- AWS Transit Gateway
- VPC Sharing
- AWS Service Catalog
- Network Reachability and Security Tools
- Network Access Analyzer
- HOL Reviewing Findings with Network Access Analyzer
- Automating Security in CI CD
- AWS Systems Manager
- Systems Manager Parameter Store
- Infrastructure Security Exam Cram
Edge Security
- Section 7 - Introduction
- DNS Name Resolution and Routing
- CloudFront Signed URLs and OAI OAC
- HOL Configure CloudFront Distribution Settings
- CloudFront SSL TLS and SNI
- Lambda@Edge
- AWS Web Application Firewall (WAF)
- AWS Shield
- Network Firewall and DNS Firewall
- HOL AWS Firewall Manager
- Edge Security Exam Cram
Data and Application Protection
- Section 8 - Introduction
- Encryption at Rest and in-Transit
- AWS Certificate Manager (ACM)
- HOL SSL TLS Certificate in ACM
- AWS Key Management Service (KMS)
- HOL Create Custom KMS Keys
- AWS CloudHSM
- Protecting Data on S3, EBS, and EFS
- HOL Enforce KMS Encryption for S3 Bucket
- HOL Copy Encrypted Snapshot Across Accounts
- Database Protection - DynamoDB and RDS
- HOL Encryption Options for AWS Databases
- HOL Schedule Key Deletion
- Storing Secrets
- Security for Lambda Functions
- AWS Step Functions
- AWS Data Lifecycle Management Features
- AWS Data Integrity Features
- HOL Amazon Verified Permissions
- Data and Application Protection Exam Cram
Logging, Monitoring, and Auditing
- Section 9 - Introduction
- Amazon CloudWatch & EventBridge
- HOL Create a Custom Metric
- Logging for Other AWS Services
- AWS CloudTrail Deep Dive
- HOL Create EventBridge rule for API calls
- Normalizing and Analyzing Logs
- Logging, Monitoring, and Auditing Exam Cram
Directory Services and Federation
- Section 10 - Introduction
- AWS Directory Services
- Identity Providers and Federation
- HOL IAM Identity Center in Action
- Amazon Cognito
- Directory Services and Federation Exam Cram
Data Analysis and Incident Response
- Section 11 - Introduction
- AWS Incident Response Overview
- Root Cause and Threat Detection
- Automated Incident Remediation in AWS
- Security Management and Support
- Penetration Testing
- Compliance Services
- Incident Response Plans
- Detect and Respond
- Data Analysis and Incident Response Exam Cram
- Amazon Athena and AWS Glue
- Automating Security Runbooks with Amazon SageMaker AI