Study Plan · Cybersecurity

AWS Security Specialty (SCS-C03): An 8-Week Study Plan

expert

A free, realistic 8-week study plan for AWS Certified Security - Specialty (SCS-C03): weekly goals, hands-on labs, checkpoints and final review tactics.

By The Exam Atlas Editorial Team · Verified 2026-08-05

A realistic eight-week plan for SCS-C03, assuming roughly 8 to 10 hours a week and an existing AWS background. Every week pairs reading with hands-on work in a sandbox account, because this exam tests operational judgement, not definitions. Weights in brackets show each domain’s share of scored content.

Week 1 - Baseline, exam guide, and IAM fundamentals

Read the official SCS-C03 exam guide end to end and set up a sandbox AWS account (or an isolated account in your Organization). Start IAM (20%): policy structure, identity-based vs resource-based policies, and the evaluation logic - explicit deny, then allow. Checkpoint: given a simple policy pair, you can predict whether a request is allowed or denied, and say why.

Week 2 - IAM at depth: roles, federation, multi-account

Cover IAM roles and STS, cross-account role assumption and external IDs, permissions boundaries, SCPs, and IAM Identity Center for workforce access. Practise diagnosing “access denied” scenarios in your sandbox. Checkpoint: you can explain how an SCP, a permissions boundary and an identity policy combine, and where an explicit deny can come from.

Week 3 - Data Protection: KMS and encryption at rest

Work through KMS (18% domain): AWS managed vs customer managed keys, key policies vs IAM policies, grants, envelope encryption, multi-Region keys and imported key material. Then storage: S3 encryption options and their audit trails, EBS and RDS encryption. Checkpoint: you can choose a key type and policy design for a scenario and justify the trade-offs.

Week 4 - Data Protection: transit, secrets and discovery

Finish the domain: TLS with ACM, AWS Private CA for internal PKI, Secrets Manager vs Parameter Store and rotation, Amazon Macie for sensitive-data discovery, and data masking in CloudWatch Logs and SNS. Note the C03 additions around node-to-node encryption (EMR, EKS). Checkpoint: you can map “protect this data” requirements to specific services without looking anything up.

Week 5 - Infrastructure Security

Cover the 18% infrastructure domain: security groups vs NACLs, VPC design and endpoints, AWS Network Firewall, WAF, Shield, CloudFront at the edge, Session Manager instead of SSH, and vulnerability management with Inspector. Checkpoint: you can layer edge, network and host controls for a three-tier workload and say what each layer stops.

Week 6 - Detection

Cover the 16% detection domain: GuardDuty, Security Hub, Detective, Config, CloudTrail (management vs data events, integrity validation), VPC Flow Logs, CloudWatch alarms and EventBridge routing. Understand which tool answers which question - that distinction is exam gold. Checkpoint: for any “we need to know when X happens” requirement, you can name the right service and the log source it depends on.

Week 7 - Incident Response and Governance

Two lighter domains (14% each). IR: preparation and playbooks, containment that preserves evidence, snapshot-based forensics, credential-compromise response, and automated response via EventBridge. Governance: shared responsibility, Organizations and Control Tower, Artifact, Trusted Advisor, and the C03 additions on generative-AI application security. Checkpoint: you can order the response steps for a compromised-instance scenario, and explain who secures what under shared responsibility.

Week 8 - Full review and timed practice

Take the official practice question set on Skill Builder and any full-length timed reviews you have. Drill your weak domains, re-read the exam guide’s out-of-scope list so you stop over-studying, and rehearse pacing: 170 minutes for 65 questions is generous if you keep moving. Confirm booking logistics. Checkpoint: you consistently reason to correct answers on fresh scenario questions - and can explain why the wrong options fail.

A note on practice

Use original practice material and the official question set - not sites claiming to sell real questions, which violate AWS’s exam policies and teach outdated C02 content anyway. Everything on this site is original and concept-based. Cross-check anything surprising against AWS documentation: the exam rewards people who know how the services actually behave.

FAQ

How many weeks do I need for the AWS Security Specialty?
AWS publishes no official figure. With the recommended background (several years of cloud security work), 6 to 10 weeks at 8-10 hours per week is a common pattern. This plan uses eight; compress or stretch it to fit your experience.
Can I follow this plan without AWS experience?
Not realistically. The exam assumes deep hands-on familiarity - AWS recommends the equivalent of 3-5 years securing cloud solutions. If you are new to AWS, build Associate-level skills first, then come back.
What if I fall behind?
Protect the two heaviest areas: IAM (20%) and the Infrastructure Security + Data Protection pair (18% each). Understanding policy evaluation and KMS deeply is worth more than skimming every service.

Sources