Free SCS-C03: AWS Certified Security - Specialty Exam Questions and Answers
AWS Certified Security - Specialty is exam SCS-C03, part of AWS Certification from Amazon Web Services. AWS codes take the form ROLE-Cnn, where the letters name the role and tier and the C-number is the syllabus revision — so SAA-C03 is the third revision of Solutions Architect Associate. Exams are multiple choice and multiple response through Pearson VUE, scored on a 100 to 1000 scale, with the pass mark set by tier: 700 Foundational, 720 Associate, 750 Professional and Specialty.
Candidates comparing SCS-C03 exam dumps, ExamTopics and other SCS-C03 practice tests use this page for the answers and explanations behind each question. Download the free SCS-C03 PDF, then sit the timed SCS-C03 exam simulation before booking with Amazon.
Last updated: October 3, 2026
- Exam code
- SCS-C03
- Provider
- Amazon
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Official page
- Official Exam website
- Our test mode duration & pass mark
- 130 mins · 70%
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #1
A security team manages a company's AWS Key Management Service (AWS KMS) customer managed keys. Only members of the security team can administer the KMS keys. The company's application team has a software process that needs temporary access to the keys occasionally. The security team needs to provide the application team's software process with access to the keys. Which solution will meet these requirements with the LEAST operational overhead?
Correct answer: C
Explanation
Grants provide temporary, granular permissions to use a KMS key and can be revoked when no longer needed, without editing the key policy or moving key material.
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #2
A company stores sensitive data in an Amazon S3 bucket. The company encrypts the data at rest by using server-side encryption with Amazon S3 managed keys (SSE-S3). A security engineer must prevent any modifications to the data in the S3 bucket. Which solution will meet this requirement?
Correct answer: B
Explanation
S3 Object Lock in compliance mode with versioning makes objects immutable for the retention period; no user, including the root user, can overwrite or delete them. Bucket policies and MFA delete can be changed by privileged users.
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #3
A company's security team wants to receive near-real-time email notifications about AWS abuse reports related to DoS attacks. An Amazon SNS topic already exists and is subscribed to by the security team. What should the security engineer do next?
Correct answer: B
Explanation
AWS Health delivers abuse notifications as events, so an EventBridge rule matching the AWS_ABUSE_DOS_REPORT event type can publish to the existing SNS topic for near-real-time email alerts without polling.
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #4
A security engineer wants to forward custom application-security logs from an Amazon EC2 instance to Amazon CloudWatch. The security engineer installs the CloudWatch agent on the EC2 instance and adds the path of the logs to the CloudWatch configuration file. However, CloudWatch does not receive the logs. The security engineer verifies that the awslogs service is running on the EC2 instance. What should the security engineer do next to resolve the issue?
Correct answer: D
Explanation
The correct answer is D. Attach the CloudWatchAgentServerPolicy AWS managed policy to the EC2 instance role. According to the AWS documentation1, the CloudWatch agent is a software agent that you can install on your EC2 instances to collect system-level metrics and logs. To use the CloudWatch agent, you need to attach an IAM role or user to the EC2 instance that grants permissions for the agent to perform actions on your behalf. The CloudWatchAgentServerPolicy is an AWS managed policy that provides the necessary permissions for the agent to write metrics and logs to CloudWatch2. By attaching this policy to the EC2 instance role, the security engineer can resolve the issue of CloudWatch not receiving the custom application- security logs. The other options are incorrect for the following reasons: A. Adding AWS CloudTrail to the trust policy of the EC2 instance is not relevant, because CloudTrail is a service that records API activity in your AWS account, not custom application logs3. Sending the custom logs to CloudTrail instead of CloudWatch would not meet the requirement of forwarding them to CloudWatch. B. Adding Amazon S3 to the trust policy of the EC2 instance is not necessary, because S3 is a storage service that does not require any trust relationship with EC2 instances4. Configuring the application to write the custom logs to an S3 bucket that CloudWatch can use to ingest the logs would be an alternative solution, but it would be more complex and costly than using the CloudWatch agent directly. C. Adding Amazon Inspector to the trust policy of the EC2 instance is not helpful, because Inspector is a service that scans EC2 instances for software vulnerabilities and unintended network exposure, not custom application logs5. Using Amazon Inspector instead of the CloudWatch agent would not meet the requirement of forwarding them to CloudWatch. References: 1: Collect metrics, logs, and traces with the CloudWatch agent - Amazon CloudWatch 2: CloudWatchAgentServerPolicy - AWS Managed Policy 3: What Is AWS CloudTrail? - AWS CloudTrail 4: Amazon S3 FAQs - Amazon Web Services 5: Automated Software Vulnerability Management - Amazon Inspector - AWS
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #5
A company needs to identify the root cause of security findings and investigate IAM roles involved in those findings. The company has enabled VPC Flow Logs, Amazon GuardDuty, and AWS CloudTrail. Which solution will meet these requirements?
Correct answer: A
Explanation
Amazon Detective automatically ingests VPC Flow Logs, GuardDuty findings and CloudTrail events into a behavior graph, giving visualizations and role-level context needed for root cause analysis.
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #6
A company has decided to move its fleet of Linux-based web server instances to an Amazon EC2 Auto Scaling group. Currently, the instances are static and are launched manually. When an administrator needs to view log files, the administrator uses SSH to establish a connection to the instances and retrieves the logs manually. The company often needs to query the logs to produce results about application sessions and user issues. The company does not want its new automatically scaling architecture to result in the loss of any log files when instances are scaled in. Which combination of steps should a security engineer take to meet these requirements MOST cost-effectively? (Select TWO.)
Select 2 answers.
Correct answer: C, D
Explanation
The CloudWatch agent streams logs off the instances before they are terminated during scale-in, and CloudWatch Logs Insights queries those logs directly, avoiding the extra cost of Glue, Athena or an EFS volume.
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #7
A company runs an application on an Amazon EC2 instance. The application generates invoices and stores them in an Amazon S3 bucket. The instance profile that is attached to the instance has appropriate access to the S3 bucket. The company needs to share each invoice with multiple clients that do not have AWS credentials. Each client must be able to download only the client's own invoices. Clients must download their invoices within 1 hour of invoice creation. Clients must use only temporary credentials to access the company's AWS resources. Which additional step will meet these requirements?
Correct answer: C
Explanation
Generating the pre-signed URLs with STS-assumed role credentials (C) gives each client short-lived temporary access scoped to its own invoice object. Embedding long-lived IAM user access keys (D) violates the requirement, and bucket policy or tag conditions do not govern callers of a pre-signed URL.
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #8
A company uses AWS IAM Identity Center to manage access to its AWS accounts. The accounts are in an organization in AWS Organizations. A security engineer needs to set up delegated administration of IAM Identity Center in the organization's management account. Which combination of steps should the security engineer perform in IAM Identity Center before configuring delegated administration? (Select THREE.)
Select 3 answers.
Correct answer: B, D, F
Explanation
Delegated administration cannot manage the management account itself, so the directory, permission sets and user assignments that apply to the management account must be created there beforehand and remain management-account only.
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #9
A company is running its application on AWS. The company has a multi-environment setup, and each environment is isolated in a separate AWS account. The company has an organization in AWS Organizations to manage the accounts. There is a single dedicated security account for the organization. The company must create an inventory of all sensitive data that is stored in Amazon S3 buckets across the organization's accounts. The findings must be visible from a single location. Which solution will meet these requirements?
Correct answer: A
Explanation
Macie is the service that discovers sensitive data in S3, and designating the security account as delegated administrator for Macie and Security Hub, with Macie publishing findings to Security Hub, gives one organization-wide view.
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #10
A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company wants to centrally give users the ability to access Amazon Q Developer. Which solution will meet this requirement?
Correct answer: A
Explanation
Amazon Q Developer integrates with IAM Identity Center as an AWS managed application, letting workforce identities be assigned access centrally across the organization. Cognito is for application end users, not workforce access.
Continue with SCS-C03: AWS Certified Security - Specialty
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SCS-C03: AWS Certified Security - Specialty, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Discussion
Explain your reasoning, not just the letterOther Amazon certifications
- AWS Certified Solutions Architect - Associate SAA-C03 (opens in a new tab)
- AWS Certified Cloud Practitioner CLF-C02 (opens in a new tab)
- AWS Certified Developer - Associate DVA-C02 (opens in a new tab)
- SOA-C03: AWS Certified CloudOps Engineer - Associate (opens in a new tab)
- AWS Certified Solutions Architect - Professional SAP-C02: AWS Certified Solutions Architect -Professional SAP-C02 (opens in a new tab)
- AWS Certified DevOps Engineer - Professional DOP-C02: AWS Certified DevOps Engineer -Professional DOP-C02 (opens in a new tab)
- AWS Certified Database - Specialty (opens in a new tab)
- AWS Certified Advanced Networking - Specialty ANS-C01 (opens in a new tab)
- AWS Certified Machine Learning - Specialty (MLS-C01) (opens in a new tab)
- AWS Certified Data Analytics - Specialty (DAS-C01) (opens in a new tab)
- AWS Certified Data Engineer - Associate DEA-C01 (opens in a new tab)
- ANS-C00: AWS Certified Advanced Networking - Specialty (opens in a new tab)
Reviews
Write a review★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit SharmaVerified buyer
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar NyströmVerified buyer
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah SmithVerified buyer
FAQ
Learn More: https://aws.amazon.com/certification/
- Q1: How much does the AWS Security Specialty (SCS-C03) exam cost?
- A: The exam costs 300 USD as of October 2026, and the full fee applies to every attempt.
- Q2: How many questions are on the SCS-C03 exam and how long is it?
- A: The real exam has 65 questions and you get 170 minutes. Fifteen of the questions are unscored items that AWS is evaluating for future use, so 50 questions determine your result, and the unscored ones are not identified.
- Q3: What question types are on the SCS-C03 exam?
- A: Besides multiple choice and multiple response questions, SCS-C03 introduced ordering questions, where you place three to five responses in the correct sequence, and matching questions, where you pair responses with three to seven prompts. You must get every part of an ordering or matching question right to receive credit for it.
- Q4: What is the passing score for the AWS Security Specialty exam?
- A: You need a scaled score of at least 750 on a 100 to 1,000 scale, which is higher than the 720 required for AWS Associate exams. Scoring is compensatory, so you do not need to pass each domain individually.
- Q5: What are the SCS-C03 exam domains and weightings?
- A: The SCS-C03 exam guide weights the scored content as Detection 16%, Incident Response 14%, Infrastructure Security 18%, Identity and Access Management 20%, Data Protection 18% and Security Foundations and Governance 14%.
- Q6: What experience do I need for the AWS Security Specialty exam?
- A: There are no required prerequisites or prior certifications. AWS's exam guide targets candidates with the equivalent of three to five years of experience securing cloud solutions, and the certification page describes five years of IT security experience including at least two years of hands-on experience securing AWS workloads.
- Q7: When did SCS-C03 replace SCS-C02?
- A: The last day to take SCS-C02 was December 1, 2025, and SCS-C03 has been the only version available since December 2, 2025. The new version expanded coverage of generative AI and machine learning security. As of October 2026 AWS has not announced a further update.
- Q8: How is the SCS-C03 exam delivered, how long is it valid, and what if I fail?
- A: You can sit the exam at a Pearson VUE test centre or online with a proctor, in English, Japanese, Korean, Portuguese (Brazil), Simplified Chinese or Spanish (Latin America), although the Simplified Chinese, Spanish (Latin America) and Portuguese (Brazil) versions will be retired after December 31, 2026. The certification is valid for 3 years and is renewed by passing the latest version of the exam, and if you fail you must wait 14 calendar days before retaking it at the full fee.
- Q9: What is the SCS-C03: AWS Certified Security - Specialty exam?
- A: SCS-C03: AWS Certified Security - Specialty is a Amazon certification exam. Judging by the questions in our bank, it concentrates on amazon, engineer, bucket, instance and instances.
- Q10: What topics does the SCS-C03: AWS Certified Security - Specialty exam cover?
- A: Questions in our SCS-C03: AWS Certified Security - Specialty bank cluster around amazon, engineer, bucket, instance, instances, lambda, accounts and cloudwatch. Working through the full set is the quickest way to find which of these you are weakest on.
- Q11: How should I prepare for SCS-C03: AWS Certified Security - Specialty?
- A: Work through the SCS-C03: AWS Certified Security - Specialty practice questions here, checking your answer on each one, then sit the practice test to rehearse the exam under timed conditions before the real thing.
- Q12: Are these real SCS-C03: AWS Certified Security - Specialty exam questions?
- A: They are drawn from officially released past questions and from community members who have sat SCS-C03: AWS Certified Security - Specialty. Answers are verified and updated weekly.
- Q13: Where do I register for the SCS-C03: AWS Certified Security - Specialty exam?
- A: Register through Amazon directly. Exampractice is not affiliated with Amazon and does not administer the exam.
- Q14: Is there a free SCS-C03: AWS Certified Security - Specialty sample?
- A: Yes. Every SCS-C03: AWS Certified Security - Specialty page shows a free sample of real questions. Upgrading opens the full bank and the practice test.
- Q15: What are Amazon Certification Exams?
- A: Amazon Certification Exams validate your expertise in Amazon Web Services (AWS), covering a range of cloud computing skills, including architecture, development, operations, and data analytics. These certifications demonstrate your proficiency in designing, deploying, and managing applications on the AWS platform.
- Q16: Why should I pursue Amazon Certification?
- A: Amazon Certification enhances your professional credibility, showcasing your skills and knowledge in AWS services. This can lead to better job opportunities, higher salaries, and career advancement in the cloud computing and IT industry.
- Q17: What are the benefits of Amazon Certification?
- A: Benefits include recognition as a certified cloud professional, improved job performance, access to exclusive resources, continuing education opportunities, and staying current with the latest AWS technologies and best practices.
- Q18: Who should take Amazon Certification Exams?
- A: IT professionals, cloud architects, developers, system administrators, data analysts, and anyone involved in designing, implementing, and managing cloud solutions on AWS should consider these certifications to validate their expertise and advance their careers.
- Q19: What types of Amazon Certification Exams are available?
- A: Amazon offers various certification paths, including Foundational Level (AWS Certified Cloud Practitioner), Associate Level (AWS Certified Solutions Architect, AWS Certified Developer, AWS Certified SysOps Administrator), Professional Level (AWS Certified Solutions Architect – Professional, AWS Certified DevOps Engineer – Professional), and Specialty Certifications (Security, Big Data, Advanced Networking, and more).
- Q20: How do I prepare for Amazon Certification Exams?
- A: Preparation can include official AWS training courses, study guides, practice exams, online tutorials, and hands-on experience with AWS services and solutions.
- Q21: Where can I take Amazon Certification Exams?
- A: Amazon Certification Exams can be taken online or at authorized testing centers worldwide, providing flexibility to fit your schedule and location.
- Q22: How do Amazon Certifications impact my career?
- A: Amazon Certifications significantly boost your career by demonstrating your expertise to employers, making you a more competitive candidate for advanced roles and promotions in the cloud computing and IT industry.
- Q23: Are there any prerequisites for Amazon Certification Exams?
- A: Some exams may have prerequisites, such as foundational knowledge or prior certifications. Check the specific requirements for each certification path on the AWS Certification website.
- Q24: How often do I need to recertify for Amazon Certifications?
- A: AWS Certifications typically require recertification every three years to ensure that certified professionals stay updated with the latest AWS technologies and industry practices.



