
Discover the AWS certified security – specialty course overview with module-based exam prep, console demos, and practice questions, while clarifying target audiences and prerequisites in cloud security and CompTIA fundamentals.
Explore the AWS certified security specialty exam prerequisites, Bloom's taxonomy apply analyze evaluate, and the six pillars of the well-architected framework, with scaffolding and practice questions.
Explore host security in AWS by examining how to protect EC2 instances, containers, and serverless resources across data in transit, data at rest, and access controls.
Explore host security configurations for AWS EC2, including hardening instances with IAM roles, patch management, memory and EBS encryption, and secure access via SSM agent, key pairs, and security groups.
Explore host security services with security groups and Amazon Inspector, including stateful filtering, design and reuse of groups, and vulnerability scanning across EC2, Lambda, and ECR.
Learn to troubleshoot host security for EC2 by using auto-scaling, elastic load balancing, cross-zone failover, automated backups with EBS snapshots and Data Lifecycle Manager, and CloudWatch monitoring.
Explore how AWS network security uses VPCs and IAM-based identity controls to protect networks, edge spaces, and APIs, including ALB and NLB load balancers.
Design secure AWS networks with private link and VPC endpoints, comparing interface and gateway endpoints, gateway load balancer endpoints, and Route 53 split-horizon DNS to keep traffic private.
Explore VPC security mechanisms for network segmentation, compare security groups and network ACLs, and learn firewall manager usage for centralized and distributed protection with strict inbound rules.
Explore how AWS traffic monitoring uses VPC flow logs, traffic mirroring, and reachability and network access analyzers to diagnose issues and route logs to CloudWatch, S3, or Kinesis for analysis.
Explore securing network connections in hybrid deployments, including client and site-to-site VPNs, Direct Connect with encryption options, and VPC peering to keep on-prem and cloud traffic secure and efficient.
Learn to troubleshoot network security with reachability and network access analyzers in AWS, understanding connectivity versus isolation and their limitations. Build security posture with firewall manager and shield features.
Explore edge security in AWS by examining edge locations, edge devices, and CloudFront, and learn how to reduce attack surfaces with Origin Access Control and encrypted data.
Explore edge security services in AWS, learning how to build layered defenses with TLS, DDoS protection, WAF, DNS health checks, and data residency for edge and hybrid deployments.
Learn how AWS WAF protects web apps via web ACLs, managed and custom rules, and edge security for CloudFront and related services, plus rule components and WCUs.
Troubleshoot edge security with DDoS protection, Shield Advanced, CloudFront, ELB, and WAF, then apply private subnets and explicit allow rules to reduce the attack surface.
Explore data encryption across the data lifecycle, from encryption at rest and in transit to key management with KMS, IAM, and ACM, while designing S3 lifecycle and AWS backup policies.
Master data classification and tagging in AWS, applying best practices and multi-account tagging strategies to protect sensitive data. Inventory data, assign nuanced classifications, and monitor access with automated controls.
Explore how to protect data at rest by encrypting storage across AWS services, including EBS volumes, S3 objects, and RDS data, using KMS keys and default encryption. Apply best practices for key management, least privilege access, and tokenization, and follow practical steps for encrypting data at rest across EC2, S3, databases, and archives.
Explore how to protect data in transit across AWS with TLS concepts, VPN concepts, and certificate management. Apply CloudFront options with ACM, OAC, and SSL termination across ALB and origins.
Explore key management design with AWS KMS and CloudHSM, learning envelope encryption, data keys, symmetric and asymmetric keys, rotation, policies, and when to use each service for encryption at rest.
Explore evaluating AWS KMS key management, comparing key policies, IAM policies, and grants, including customer-provided key material, encryption, rotation, ABAC, encryption context, and monitoring.
Learn to troubleshoot data encryption by selecting encryption techniques based on business requirements and identifying sensitive data with Macie, while managing KMS keys and S3 encryption settings.
Explore the fundamentals of logging in the cloud, including why logs matter for compliance, troubleshooting, and incident response, and learn key AWS logging services like CloudTrail, CloudWatch, and GuardDuty.
Design a robust logging system with CloudTrail capturing API calls, configure trails and encryption, and integrate with CloudWatch, EventBridge, and SNS for end-to-end monitoring.
Master log storage and lifecycle management using CloudTrail and S3, encryption options, log validation, best practices, and centralized logging with CloudWatch Logs.
Master log analysis for security events by querying CloudWatch logs, correlating data with OpenSearch, Athena, and Glue, and automating responses with EventBridge.
Troubleshoot logs by identifying misconfigurations and remediation steps for absent permissions, verify log capture and delivery, and implement IAM roles and KMS access for CloudTrail and CloudWatch.
Explore how logging and monitoring work together to detect security events, set metrics and thresholds, and automate alerts using AWS services like CloudTrail, CloudWatch, and GuardDuty.
Design robust monitoring systems for AWS security by mastering anomaly and correlation techniques, centralized security findings, and monitoring requirements across environments and workloads using CloudWatch and related services.
Explore how AWS monitoring and security services like Security Hub, GuardDuty, Inspector, Detective, Config, Audit Manager, and CloudFormation centralize findings, automate responses with EventBridge and Lambda, and ensure secure environments.
Learn to implement custom monitoring in AWS by generating metrics with the CloudWatch agent and SSM State Manager, then visualize anomalies with dashboards and metric filters to detect activity.
Explore auditing in AWS by setting up automated tools and scripts for regular audits, and collecting evidence with AWS Audit Manager and Security Hub to support compliance frameworks.
Explore troubleshooting, monitoring, and alerting practices to diagnose failed events. Analyze permissions and configurations, and use logs, metrics, traces, and X-ray service maps to improve performance and security.
Explore AWS compliance and incident response fundamentals. Learn shared responsibility, artifact reports, abuse complaints, and planning for cloud incidents and compromised resources.
Plan AWS incident response with playbooks and runbooks, guided by the security incident response guide, and perform root cause analysis and forensics to recover services.
Explore automated alerts in AWS using Security Hub, GuardDuty, Macie, Config, and CloudWatch to monitor findings and events, then trigger responses with Lambda, Step Functions, and Systems Manager.
Apply incident response actions by isolating AWS resources, automating remediation with AWS services, and using GuardDuty findings and IOCs to drive containment and recovery.
Master identity and access management in AWS with cross-account roles and boundaries. Explore identity-based and resource-based policies, service control policies, and external ID for secure third-party access.
Design organizational accounts with AWS organizations, using management accounts, OUs, and SCPs for centralized control and consolidated billing. Secure root and route users with MFA and guardrails via control tower.
Explore how resource-based and identity-based policies interact, apply permissions boundaries and SCPs, and master policy evaluation and explicit denial in AWS IAM.
Explore workload access control, including IAM roles, ABAC and RBAC strategies, federated and temporary access, cross-account sharing with RAM, and Cognito for authentication and authorization.
Explore federation and SSO, leveraging STS to issue temporary credentials for IAM roles, while comparing Secrets Manager and parameter store for securely storing credentials and configuration with identity provider options.
Diagnose authentication and authorization issues in IAM, implement least privilege, and rotate compromised credentials. Use Access Analyzer and policy simulator to validate permissions, and revoke active sessions for compromised roles.
Discover how the AWS well-architected framework and its security tool identify security gaps, apply zero-trust principles, and guide secure design across compute, storage, and other services.
Explore securing compute services across instances, containers, and functions, including host-based security, instance metadata, container image scanning, and network controls.
Explore secure storage in AWS by controlling data access with S3 access points and VPC endpoints, protect data with object lock and versioning, and use pre-signed URLs for time-limited access.
Learn to secure database services with encryption at rest using Cloud HSM, and leverage RDS proxy to improve security and scalability for relational and serverless databases.
Learn how to secure code development services by standardizing AWS portfolios with Service Catalog and Proton, and enforce configurations with AWS Config rules to detect noncompliant resources.
Explore the AWS certified security specialty exam objectives (SCS-C02), the six domains, new governance content, Bloom's taxonomy levels, and how to use the objectives to study and fill gaps.
Master study and exam strategies for the AWS certified security specialty exam. Explore exam format, question types, time management, and ai-assisted prep.
The AWS Certified Security - Specialty (SCS-C02) certification is a designation offered by Amazon Web Services (AWS) that validates a candidate's expertise in designing and implementing secure applications and infrastructures on the AWS platform. This certification is intended for individuals who work with AWS services and have a strong focus on security aspects.
The main objective of this certification is to validate your skills and knowledge in building and deploying security solutions in the AWS Cloud. Furthermore, this certification also confirms that you understand the specialized data classifications and AWS data protection mechanisms, data-encryption techniques and how to implement them using AWS mechanisms, as well as secure internet protocols and how to implement them using AWS mechanisms. Overall, taking this exam will help you demonstrate your expertise in the field of AWS security, which is essential for any IT professional working on AWS infrastructure.
The AWS Certified Security - Specialty course is designed to equip IT professionals and security specialists with the knowledge and skills needed to design and implement secure applications and infrastructures on the Amazon Web Services (AWS) platform.
This certification is intended for individuals who want to demonstrate their expertise in securing AWS environments and applying best practices for maintaining a secure cloud infrastructure.