AWSSpecialty

AWS Certified Security – Specialty

SCS-C03

Advanced skills in securing workloads and architectures on AWS.

This exam replaces AWS Certified Security – Specialty (SCS-C02), retired 1 December 2025.
Duration
170 min
Exam questions
65
Passing score
750 / 1000
Exam fee
$300
Question formats:Multiple choiceMultiple responseOrderingMatching
Free plan
3 free papers
Free account
Mocks locked
Pro only
Upgrade to Pro
Every paper and mock exam.
See Pro

Start with free papers Free

You get 3 free practice papers with your plan.

Free
Mixed paper 1
Domain 1 · 25 questions
Free
Mixed paper 2
Domain 1 · 25 questions
Free
Mixed paper 3
Domain 1 · 25 questions

Domain papers 502 questions

Free
Mixed paper 1
25 questions · 60 min
Free
Mixed paper 2
25 questions · 60 min
Free
Mixed paper 3
25 questions · 60 min
Pro
Mixed paper 4
18 questions · 44 min

Mock exams Pro

Full-length, exam-like practice tests. Available with Pro.

Mock exam 1
65 questions · 170 min
Mock exam 2
65 questions · 170 min
Mock exam 3
65 questions · 170 min

Try a sample question

All 10 sample questions →
Question 1Detection

An authorized vulnerability scanner runs weekly from a fixed set of internal addresses and generates a large volume of GuardDuty reconnaissance findings. The security team wants those findings to stop reaching Security Hub and the team's EventBridge pipeline, but it must still be able to show an auditor that GuardDuty detected and recorded the scanning activity. What should the engineer configure?

  1. A.

    A GuardDuty trusted IP list containing the scanner's addresses, uploaded to the detector in the administrator account.

  2. B.

    An EventBridge rule with an event pattern that excludes the scanner's addresses so that matching findings are dropped before delivery.

  3. C.

    A GuardDuty suppression rule matching the finding type and the scanner's addresses.

  4. D.

    A Security Hub automation rule that sets the workflow status of matching findings to SUPPRESSED after they are imported.

Show answer

Answer: C

A suppression rule still generates the finding and archives it automatically, and archived findings are not exported to Security Hub, S3, Detective, or EventBridge.

  • A. A trusted IP list prevents the findings from being generated at all, so there is no record for the auditor.
  • B. Filtering in EventBridge only cleans one consumer; Security Hub still receives the findings and the noise remains.
  • C. Suppressed findings are generated and auto-archived, so they remain visible in GuardDuty for audit but are not exported to Security Hub, S3, Detective, or EventBridge.
  • D. An automation rule acts after import, so the findings have already reached Security Hub and the EventBridge pipeline.

What's on the exam

6 domains · 16 task statements, straight from the official exam guide (as of 2026-09-29).

  1. 1.1Design and implement monitoring and alerting solutions for an AWS account or organization
    • Skill 1.1.1: Analyze workloads to determine monitoring requirements.
    • Skill 1.1.2: Design and implement workload monitoring strategies (for example, by configuring resource health checks).
    • Skill 1.1.3: Aggregate security and monitoring events.
    • Skill 1.1.4: Create metrics, alerts, and dashboards to detect anomalous data and events (for example, Amazon GuardDuty, Amazon Security Lake, AWS Security Hub, Amazon Macie).
    • Skill 1.1.5: Create and manage automations to perform regular assessments and investigations (for example, by deploying AWS Config conformance packs, Security Hub, AWS Systems Manager State Manager).
  2. 1.2Design and implement logging solutions
    • Skill 1.2.1: Identify sources for log ingestion and storage based on requirements.
    • Skill 1.2.2: Configure logging for AWS services and applications (for example, by configuring an AWS CloudTrail trail for an organization, by creating a dedicated Amazon CloudWatch logging account, by configuring the Amazon CloudWatch Logs agent).
    • Skill 1.2.3: Implement log storage and log data lakes (for example, Security Lake) and integrate with third-party security tools.
    • Skill 1.2.4: Use AWS services to analyze logs (for example, CloudWatch Logs Insights, Amazon Athena, Security Hub findings).
    • Skill 1.2.5: Use AWS services to normalize, parse, and correlate logs (for example, Amazon OpenSearch Service, AWS Lambda, Amazon Managed Grafana).
    • Skill 1.2.6: Determine and configure appropriate log sources based on network design, threats, and attacks (for example, VPC Flow Logs, transit gateway flow logs, Amazon Route 53 Resolver logs).
  3. 1.3Troubleshoot security monitoring, logging, and alerting solutions
    • Skill 1.3.1: Analyze the functionality, permissions, and configuration of resources (for example, Lambda function logging, Amazon API Gateway logging, health checks, Amazon CloudFront logging).
    • Skill 1.3.2: Remediate misconfiguration of resources (for example, by troubleshooting CloudWatch Agent configurations, troubleshooting missing logs).

Outline reproduced from the vendor's public exam guide for study reference.Official guide

SCS-C03 practice — frequently asked questions

Are these real SCS-C03 exam questions?

No. Every question on CertifyCloudx is original, written by us against Amazon Web Services's publicly available SCS-C03 exam guide to rehearse the skills it lists. None are actual exam questions, and CertifyCloudx is not affiliated with or endorsed by Amazon Web Services.

How many SCS-C03 practice questions are there?

502 practice questions, including 3 full-length timed mock exams and 51 domain papers of up to 25 questions (mixed and by topic). Every question has a detailed explanation of why the right answer wins and why each distractor loses.

Is the content up to date with the current SCS-C03 exam guide?

The questions are written against the SCS-C03 exam guide dated 2026-09-29, and we revise them when Amazon Web Services updates the guide.

What question formats are covered?

The same formats the real SCS-C03 uses: Multiple choice, Multiple response, Ordering, Matching. Each is rendered and graded the way the exam does it.

How long is the SCS-C03 exam and how many questions does it have?

According to Amazon Web Services's published exam details: 65 questions, 170 minutes, passing score 750 / 1000. Our mock exams use the same time limit and question count. Always confirm current details with Amazon Web Services before booking.

Can I practise SCS-C03 for free?

Yes. 3 papers are free, with up to 10 questions a day on the free plan and no card needed. Pro unlocks every paper and mock exam with no daily limit.

Does CertifyCloudx guarantee that I will pass?

No practice material can guarantee a result. CertifyCloudx helps you find and close your weak areas — accuracy by exam-guide domain and topic shows what to study next.