AWS Cloud Practitioner Certification Guide
·10 min read
Everything you need for the CLF-C02 exam — format, cost, what it tests, booking, renewal and a step-by-step preparation plan for first-time candidates.
Continue readingHow experienced cloud engineers should prepare for the AWS Security Specialty — IAM and KMS depth, incident-response drills and the SCS-C02 to SCS-C03 change.

The AWS Certified Security – Specialty is a depth exam: it assumes you already work with Amazon Web Services (AWS) and asks whether you can secure it under pressure — dissecting identity policies, reasoning about encryption key management, and deciding what to do in the first hour of an incident. Preparation therefore looks different from Associate-level study. You aren't surveying a platform; you're sharpening judgement in a handful of areas until it holds up against deliberately ambiguous scenarios.
One version note before anything else, because it affects every study resource you'll evaluate: if your search history says "SCS-C02", update it. That version of the exam was available until 1 December 2025; as of 2026 the current version is SCS-C03, which added generative AI and machine-learning security coverage and restructured the domains, with dedicated sections for detection and incident response. Materials that predate the change are not worthless, but they must be checked against the SCS-C03 exam guide on the official AWS Security Specialty page before you rely on them.
For the exam's complete blueprint and booking logistics, our AWS Security Specialty certification guide is the reference; this article is about how a practitioner actually gets ready. And if you're still weighing this credential against a vendor-neutral one, that decision has its own home in AWS Security Specialty vs Security+.
There are no formal prerequisites — AWS certifications never have them — but specialty-level depth is expected, and the exam's difficulty comes from nuance rather than obscurity. A quick self-assessment:
If most of these describe you, prepare for the exam directly. If not, the honest path is six months to a year of security-adjacent work — or an Associate-level exam first to consolidate platform breadth. Nothing stops you booking SCS-C03 tomorrow, but at $300 USD (as of 2026; local pricing varies by country, so confirm on AWS's pricing page), guessing is expensive.
Format facts to anchor your planning: 65 questions in 170 minutes, multiple choice and multiple response only — no labs — with a passing score of 750 on AWS's 100–1000 scaled range, which is not a percentage-correct figure. The certification is valid for three years, and note the specialty-specific renewal rule: unlike Associate certs, which a Professional exam can renew, specialties renew only by retaking the current specialty exam.
Rather than marching through a course start to finish, structure your prep as deep passes over the themes below, always cross-referencing the official SCS-C03 exam guide for the authoritative domain names and weightings. For each theme: read, build a small proof in a sandbox account, then interrogate yourself with scenario questions.
AWS Identity and Access Management (IAM) reasoning is the spine of this exam. Go beyond writing policies into evaluating them: how identity-based and resource-based permissions combine, how organisational guardrails constrain accounts, how temporary credentials and cross-account roles actually flow, and how federation changes the picture. A strong exercise is adversarial: write a policy, then try to explain every way a request could still be denied — or worse, unexpectedly allowed. If you can narrate the full evaluation of a single denied request, you're thinking at the level the scenarios demand.
The AWS Key Management Service (KMS) questions separate people who have enabled encryption from people who have operated it. Work through key policies versus grants, cross-account encryption, rotation behaviour, and the choice between AWS-managed and customer-managed keys — always framed as "who can do what to this data, and who could change that?". Extend the same custody thinking to data in transit and certificate handling. In your sandbox, build one cross-account encrypted pipeline end to end; the misunderstandings it surfaces are exactly the ones the exam probes.
SCS-C03's restructure gave detection and incident response dedicated domain treatment, which tells you where AWS wants candidates to be strong. Prepare in two modes. Instrumentation mode: know which service answers which question — where API activity is recorded, where findings are aggregated, how alerting is wired — and prove it by tracing one of your own sandbox actions through the audit trail. Response mode: rehearse first-hour decisions as runbooks. For a leaked access key, a crypto-mining alarm and a publicly exposed data store, write down: contain how, investigate with what, recover in which order. Exam questions about incidents are sequencing questions in disguise; candidates fail them by knowing all the actions but not the priority.
Network-layer security — segmenting environments, filtering traffic at different layers, protecting public endpoints — features in scenarios that mix security with connectivity troubleshooting. If your background is more governance than networking, budget extra time here; if you're an ex-network engineer, spend the saved time on identity instead. Tailoring effort this way is the main advantage practitioners have over course-followers.
The addition of generative AI and machine-learning security coverage is the most visible SCS-C03 change. Approach it as an extension of principles you already hold — least privilege for model access, data protection for training and inference data, monitoring for novel services — rather than an alien topic. Check the exam guide for how AWS scopes it, and don't let older courses' silence on the subject lull you into skipping it.
Experienced practitioners fail this exam in characteristic ways. Three habits counteract them.
Habit one: answer as AWS, not as your employer. Your organisation's conventions ("we never use that service", "we route everything through the proxy team") are invisible to the exam. Ground every answer in AWS's documented mechanisms and the scenario's stated constraints only.
Habit two: practise eliminating, not recognising. At specialty level, distractors are plausible. Train on questions by ruling out three answers with explicit reasons rather than spotting one that looks right. When you review a practice question, write the reason each wrong option is wrong; if you can't, that's the gap — not the topic you missed, but the discrimination you couldn't make. This is also why memorising answers is self-sabotage: the exam paraphrases freely, and recognition without reasoning collapses under paraphrase.
Habit three: rehearse the clock. 170 minutes for 65 questions is generous on paper and tight in practice, because specialty scenarios are long. In your final fortnight, sit at least two full-length timed simulations, flagging slow questions and returning to them, so pacing is automatic on the day. ExamPractice's AWS Certified Security – Specialty practice questions include free samples, with fuller question sets and a timed simulation mode for subscribers — use the untimed sets for the elimination drills above and the timed mode for these final rehearsals. AWS's own Skill Builder platform offers free official practice question sets as a further calibration source.
A note on breadth: this specialty assumes comfortable familiarity with core platform operations. If monitoring and operational tooling feel shaky rather than second nature, skim our SysOps Administrator exam preparation guide first — its observability groundwork shores up the operational layer this exam builds on.
Not useless, but unreliable on its own. The identity, encryption and infrastructure fundamentals carry over; the domain structure, the dedicated detection and incident-response emphasis, and the generative AI security coverage are SCS-C03 developments. Audit any older course against the current exam guide and fill its gaps deliberately.
No — AWS sets no prerequisites for any exam. Plenty of candidates come straight from security roles. The self-assessment earlier in this article is a better readiness gauge than your certificate count.
There's no honest universal number: a cloud security engineer refreshing depth areas and a generalist building them from scratch face very different timelines. Let evidence set your date — when full-length timed practice is consistently strong across every domain, you're ready; until then, you're not.
No. That renewal shortcut applies to Associate-level certifications; specialties renew only by retaking the current specialty exam. Passing SCS-C03 again resets your three-year window.
Specialty exams reward candidates who prepare like practitioners: deep passes over identity, keys, detection and response; adversarial self-testing instead of passive review; runbooks rehearsed until sequencing is instinct; and timed simulation to make the 170 minutes a known quantity. Verify everything against the official SCS-C03 exam guide, treat pre-2026 materials with polite suspicion, and book the exam when your evidence — not your optimism — says the gaps are closed. The wider AWS portfolio, and where a security specialist goes next within it, is mapped in the amazon exams hub and our AWS certification guides.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·10 min read
Everything you need for the CLF-C02 exam — format, cost, what it tests, booking, renewal and a step-by-step preparation plan for first-time candidates.
Continue reading·9 min read
A complete SAA-C03 reference: exam format, cost, what the questions look like, a structured prep sequence and exam-day tactics for the AWS architect exam.
Continue reading·9 min read
The DVA-C02 exam explained for working developers: format, cost, syllabus territory, registration steps, renewal rules and a study approach that fits around code.
Continue reading