Cheat Sheets/SCS-C03
SpecialtySCS-C03

AWS Certified Security – Specialty Cheat Sheet (SCS-C03)

Every in-scope security service, detection pattern, IAM and data-protection decision the SCS-C03 exam actually tests — organised by the six exam domains with policy patterns and runbooks

Free PDF — no signup required

15 pages1.1 MBUpdated April 24, 2026

About This Cheat Sheet

A 15-page specialty-tier reference covering every in-scope service from the official SCS-C03 exam guide, organised around the six exam domains: Detection (16%), Incident Response (14%), Infrastructure Security (18%), Identity & Access Management (20%), Data Protection (18%), Security Foundations & Governance (14%). Structured for candidates with 5+ years of IT security and 2+ years of AWS — sections move from shared-responsibility foundations (Artifact, Well-Architected Tool, Trusted Advisor) through Organizations / Control Tower / SCPs / RCPs / permission boundaries / session policies with explicit evaluation order, IAM (principals, condition keys, ABAC, Access Analyzer, credentials report, access advisor), IAM Identity Center (workforce SSO with external IdP via SAML + SCIM), STS (external ID, session tags, Regional endpoints), Directory Service + Cognito + Verified Permissions, AWS KMS (key types, algorithms, multi-Region keys, key policy anatomy, grants, kms:ViaService, envelope encryption, rotation) and CloudHSM (custom key store), ACM + Private CA, Secrets Manager vs Parameter Store decision, Detection services (GuardDuty with all protection plans including Runtime Monitoring + Malware Protection, Inspector for EC2 + ECR + Lambda, Macie for S3 PII, Detective for graph-based investigation, Security Hub with FSBP / CIS / PCI / NIST standards, Config + Conformance Packs, CloudTrail + CloudTrail Lake, CloudWatch, OpenSearch, Athena, Managed Grafana, User Notifications, Amazon Security Lake with OCSF), Incident Response (the event-driven auto-remediation pattern, Automated Forensics Orchestrator for EC2, Incident Manager, FIS, AWS Backup restore testing, Resilience Hub, Application Recovery Controller), Infrastructure Security (VPC + Network Access Analyzer + Network Firewall + Firewall Manager + WAF + Shield + PrivateLink + Verified Access + Route 53 Resolver DNS Firewall + CloudFront), Compute workload security (EC2 IMDSv2 + Instance Connect + Session Manager + Image Builder + Nitro Enclaves, EKS IRSA/Pod Identity + SG-for-Pods + GuardDuty EKS Runtime, Lambda signing + Inspector, API Gateway auth + mTLS, EMR security configurations, IoT Core with Device Defender, Data Lifecycle Manager), Data Protection (S3 Block Public Access + KMS + Object Lock + Access Points + Macie, RDS / Aurora / DynamoDB / OpenSearch / Athena encryption + IAM DB auth, SageMaker AI + Bedrock Guardrails + Q Business + Q Developer + CodeGuru Security, EFS + FSx for Lustre, Backup + DataSync), the security & compliance services matrix (Artifact, Audit Manager, Service Catalog, CloudFormation, Systems Manager), 7 canonical policy patterns, 22-scenario Answer Patterns, 13 common pitfalls, deep IAM evaluation logic + condition operators, KMS key policy anatomy, logging reference architecture (org-wide CloudTrail + Security Lake), specialised workload security for Lambda / EKS / SageMaker / Bedrock / IoT, compliance framework mapping (PCI DSS v4, HIPAA, SOC 2, FedRAMP, ISO 27001, NIST 800-53 Rev 5, GDPR), and four step-by-step runbooks (compromised IAM key, public S3 with sensitive data, root account misuse, suspicious STS assumptions). Every service on the SCS-C03 in-scope list is audited present.

What's Inside

1

Shared Responsibility & Governance

AWS responsibility (security of the cloud) vs customer responsibility (security in the cloud), degree-of-responsibility slider by service type (IaaS → SaaS). AWS Artifact for compliance reports (SOC, PCI, ISO, FedRAMP, HIPAA), AWS Well-Architected Tool Security pillar + lenses, AWS Trusted Advisor security checks, AWS Audit Manager for automated evidence collection mapped to frameworks.

2

Organizations, SCPs, RCPs & Landing Zone

Canonical secure multi-account layout (Management + Log Archive + Audit/Security Tooling + Networking + Identity + Workloads OU). Policy ceilings: SCPs (principals), RCPs (resources), permission boundaries (max identity-based grant), session policies. Full evaluation order with explicit deny winning always. AWS Control Tower landing zone with preventive (SCP) and detective (Config) guardrails, Account Factory + AFT for IaC-driven provisioning.

3

Identity & Access Management

IAM principals, policy elements, condition keys (aws:PrincipalOrgID, aws:PrincipalTag, aws:SourceIp, aws:SourceVpce, aws:SecureTransport, aws:MultiFactorAuthPresent, kms:ViaService), ABAC vs RBAC, IAM Access Analyzer (external + unused + custom policy checks + policy generation), Access Advisor, Credentials Report. IAM Identity Center with SAML + SCIM + external IdP (Okta, Entra, Ping), Permission Sets as auto-provisioned IAM roles. STS AssumeRole chains with ExternalId to prevent confused deputy, session tags for downstream ABAC.

4

Encryption & Key Management

AWS KMS key types (AWS-owned, AWS-managed, customer-managed), key material sources (KMS-generated, imported BYOK, CloudHSM-backed custom key store), symmetric + asymmetric + HMAC + SM2 algorithms, multi-Region keys, key policy anatomy (root account grant is mandatory, key users vs administrators, service use via grants), kms:ViaService condition, envelope encryption with DEKs, annual auto-rotation. AWS CloudHSM FIPS 140-2 Level 3 (PKCS#11, JCE, CNG/KSP). AWS Certificate Manager (free public TLS) + AWS Private CA (internal X.509 hierarchy, CRL + OCSP). AWS Secrets Manager (automatic rotation + cross-Region replication) vs Parameter Store (free SecureString with KMS).

5

Detection Services

Amazon GuardDuty across CloudTrail / VPC Flow / DNS / EKS audit / S3 / RDS / Lambda + Runtime Monitoring + Malware Protection. Amazon Inspector continuous CVE + network reachability scanning on EC2 / ECR / Lambda. Amazon Macie for S3 PII / credentials / regulatory data. Amazon Detective for graph-based incident investigation. AWS Security Hub aggregator with AWS FSBP / CIS v1.4 + v3.0 / PCI DSS v3.2.1 + v4.0.1 / NIST SP 800-53 Rev 5 standards. AWS Config + Conformance Packs. AWS CloudTrail + CloudTrail Lake (SQL over up-to-10-year event history, federated queries). Amazon Security Lake normalising OCSF Parquet in S3 for SIEM / Athena / OpenSearch subscribers.

6

Incident Response & Forensics

The event-driven auto-remediation pattern (GuardDuty / Config / CloudWatch Alarm / CloudTrail → EventBridge → SSM Automation / Lambda / Step Functions / Incident Manager). Automated Forensics Orchestrator for Amazon EC2 (isolate SG, snapshot EBS, capture memory via SSM, preserve evidence in forensic account with chain-of-custody). AWS Systems Manager Incident Manager (on-call rotas, response plans, chat channel auto-populated). AWS Fault Injection Service for controlled chaos with CloudWatch stop conditions. AWS Backup restore testing + vault lock for ransomware-proof retention. AWS Resilience Hub RTO/RPO scoring. Amazon Application Recovery Controller for deterministic Region failover.

7

Infrastructure Security

VPC segmentation (public / private / isolated subnets, NACLs stateless, Security Groups stateful with SG-to-SG references, VPC endpoints), Network Access Analyzer for org-wide policy checks, AWS Network Firewall (managed Suricata + TLS inspection), AWS Firewall Manager for org-wide policies, AWS WAF (Bot Control, ATP/ACFP, Fraud Control), AWS Shield Standard + Advanced, AWS PrivateLink, AWS Verified Access (zero-trust with identity + device posture, no VPN), Route 53 Resolver DNS Firewall with AWS-managed threat domain feeds, Amazon CloudFront edge TLS + signed URLs + field-level encryption + OAC.

8

Compute Workload Security

Amazon EC2 IMDSv2 required (token-based, blocks SSRF), EC2 Instance Connect (temporary SSH keys), Session Manager (shell without SSH / bastion / open ports), EC2 Image Builder pipeline with Inspector scanning, Nitro Enclaves (isolated CPU/RAM with KMS attestation for key handling), Amazon Data Lifecycle Manager for snapshot policies. Containers: ECR Enhanced scanning via Inspector + Signer signing, EKS IAM Roles for Service Accounts / EKS Pod Identity, Security Groups for Pods, GuardDuty EKS Runtime Monitoring (eBPF). AWS Lambda with least-privilege execution role + KMS env vars + Code Signing. Amazon API Gateway auth + mTLS. Amazon EMR security configurations. AWS IoT Core with X.509 cert + Device Defender.

9

Data Protection

Amazon S3: Block Public Access (account + bucket default), SSE-S3 / SSE-KMS / SSE-C / DSSE-KMS with Bucket Keys, bucket policies (prefer over ACLs — BucketOwnerEnforced), Object Lock (Governance / Compliance), Access Points, Multi-Region Access Points, Presigned URLs, Replication with RTC, Versioning + MFA Delete. Databases: RDS / Aurora KMS + TLS + IAM DB auth + Database Activity Streams, DynamoDB KMS + fine-grained IAM. OpenSearch at-rest + node-to-node + in-transit. Athena workgroup encryption. EFS + FSx for Lustre with KMS. AWS Backup vault lock. AWS DataSync with TLS + PrivateLink. Amazon SageMaker AI + Bedrock Guardrails + Amazon Q Business + Amazon Q Developer + CodeGuru Security — customer data remains private and is not used for training.

10

Policy Patterns

Seven canonical patterns you must recognise at a glance: deny non-TLS S3 (aws:SecureTransport=false), enforce CMK encryption on PutObject, restrict by aws:PrincipalOrgID, restrict API to VPC endpoint via aws:SourceVpce, MFA-required action with aws:MultiFactorAuthPresent / MultiFactorAuthAge, confused-deputy prevention with sts:ExternalId + aws:SourceAccount / aws:SourceArn, log integrity via CloudTrail log-file validation, and the SCP that denies disabling security services (guardduty:DeleteDetector / config:DeleteConfigurationRecorder / cloudtrail:StopLogging / securityhub:DisableSecurityHub).

11

Scenario → Answer Patterns

22 SCS-C03 scenarios mapped to the AWS default answer: centralised tamper-proof logs, public S3 remediation, anomalous console logins, EC2 compromise forensics, enforced KMS encryption, RDS credential rotation, cross-account secret sharing, preventing CloudTrail deletion, blocking root in members, preventing S3 exfiltration, PCI DSS evidence automation, central WAF across accounts, zero-trust internal apps, exposed IAM keys, S3 ransomware defence, Private CA for mTLS, IMDSv1 enforcement, immutable log chain, DNS tunnelling detection, MFA for admin, root-login audit, HSM-boundary keys.

12

Compliance Frameworks

AWS primary controls for PCI DSS v4 (Security Hub PCI, Audit Manager PCI framework, KMS + CloudHSM), HIPAA (BAA via Artifact, HIPAA-eligible services, Macie for PHI), SOC 2 (Audit Manager, FSBP, Change Manager), FedRAMP Moderate/High (GovCloud High or commercial), ISO 27001 (Audit Manager ISO), NIST 800-53 Rev 5 (Security Hub standard + Conformance Pack), GDPR (Region data residency, DPA, Macie + Lake Formation for data-subject requests).

Why This Cheat Sheet Helps

SCS-C03 tests how to build and run secure multi-account AWS with the exact AWS-prescribed pattern for each scenario. Questions reliably distinguish services with overlapping surface (Macie vs Inspector vs GuardDuty, CloudTrail Lake vs Athena vs OpenSearch, Security Hub vs Security Lake, Secrets Manager vs Parameter Store, KMS CMK vs CloudHSM), the precise IAM / KMS / resource policy combination for a given access path, and the event-driven auto-remediation fabric (EventBridge + SSM Automation) that AWS wants you to use. This cheat sheet puts those decisions side by side with the ASFF / CIS / FSBP vocabulary examiners use.

It assumes you already know security fundamentals and AWS shared-responsibility. Use it in the final weeks to reinforce the policy evaluation order (explicit deny, SCP, RCP, identity, resource, permission boundary, session, VPC endpoint), the KMS key policy anatomy, and the canonical detection → response → forensics pipeline AWS expects in real incidents.

How to Use It

Skim the whole sheet once to see how the six domains map to sections. Then hammer practice exams — for each wrong answer, find the relevant section and study the tables and policy patterns. Pay extra attention to sections 2–3 (Orgs + IAM), 4 (KMS), 5 (Detection), 6 (Incident Response), 9 (Data Protection), 11 (policy patterns), 12 (Scenario → Answer Patterns), 13 (Pitfalls), and 14–15 (IAM + KMS deep dives).

In the final week, walk through the six domain weights against your confidence: Detection (16%) → section 5; Incident Response (14%) → sections 6, 19; Infrastructure Security (18%) → section 7; IAM (20%) → sections 3, 11, 14; Data Protection (18%) → sections 4, 9; Foundations & Governance (14%) → sections 1, 2, 10, 18. Pair with CloudNinja's free SCS-C03 practice exam to surface gaps.

Frequently Asked Questions

Is this AWS Security Specialty cheat sheet free?

Yes, completely free with no signup required. Download the PDF directly from CloudNinja and use it as a study reference for the SCS-C03 exam.

How much experience do I need before SCS-C03?

AWS recommends five or more years of IT security experience plus two or more years of AWS. The exam is policy-dense and assumes fluent reading of IAM / KMS / resource policies with condition keys. If you do not already work in security or have hands-on experience with IAM Identity Center, KMS CMKs, GuardDuty / Security Hub, and incident response runbooks, build that foundation first — ideally via Solutions Architect Associate + a security-focused role.

How is SCS-C03 different from general security on AWS?

SCS-C03 tests the AWS-prescribed pattern for each scenario, not just "a secure answer." It cares which service owns each layer: Macie for S3 PII, Inspector for CVEs, GuardDuty for behavioural threats, Security Hub as the aggregator, Security Lake as the OCSF data lake, Audit Manager for compliance evidence, CloudTrail Lake for forensic SQL, CloudHSM only when FIPS 140-2 Level 3 is a hard requirement. Expect IAM / resource / KMS policy questions where one condition key is the difference between pass and fail.

Is this cheat sheet updated for the current SCS-C03 exam?

Yes, it is built directly from the current SCS-C03 exam guide (security-specialty-03) and audited against the full in-scope services list. It reflects current services — AWS CloudTrail Lake, Amazon Security Lake, AWS Verified Access, Amazon Verified Permissions, GuardDuty Runtime Monitoring + Malware Protection + RDS + Lambda + EKS, Inspector for Lambda, AWS User Notifications, Amazon Application Recovery Controller, Automated Forensics Orchestrator for Amazon EC2, Amazon Q Business / Q Developer, Amazon Bedrock Guardrails, Amazon CodeGuru Security, and Resource Control Policies alongside SCPs.

Keep Studying

Affiliate links — if you enrol through them, CloudNinja may earn a commission at no extra cost to you.

We use cookies to improve your experience. This site uses YouTube embeds and Google Analytics to understand how visitors use our site. Learn more