A realistic eight-week plan for SCS-C03, assuming roughly 8 to 10 hours a week and an existing AWS background. Every week pairs reading with hands-on work in a sandbox account, because this exam tests operational judgement, not definitions. Weights in brackets show each domain’s share of scored content.
Week 1 - Baseline, exam guide, and IAM fundamentals
Read the official SCS-C03 exam guide end to end and set up a sandbox AWS account (or an isolated account in your Organization). Start IAM (20%): policy structure, identity-based vs resource-based policies, and the evaluation logic - explicit deny, then allow. Checkpoint: given a simple policy pair, you can predict whether a request is allowed or denied, and say why.
Week 2 - IAM at depth: roles, federation, multi-account
Cover IAM roles and STS, cross-account role assumption and external IDs, permissions boundaries, SCPs, and IAM Identity Center for workforce access. Practise diagnosing “access denied” scenarios in your sandbox. Checkpoint: you can explain how an SCP, a permissions boundary and an identity policy combine, and where an explicit deny can come from.
Week 3 - Data Protection: KMS and encryption at rest
Work through KMS (18% domain): AWS managed vs customer managed keys, key policies vs IAM policies, grants, envelope encryption, multi-Region keys and imported key material. Then storage: S3 encryption options and their audit trails, EBS and RDS encryption. Checkpoint: you can choose a key type and policy design for a scenario and justify the trade-offs.
Week 4 - Data Protection: transit, secrets and discovery
Finish the domain: TLS with ACM, AWS Private CA for internal PKI, Secrets Manager vs Parameter Store and rotation, Amazon Macie for sensitive-data discovery, and data masking in CloudWatch Logs and SNS. Note the C03 additions around node-to-node encryption (EMR, EKS). Checkpoint: you can map “protect this data” requirements to specific services without looking anything up.
Week 5 - Infrastructure Security
Cover the 18% infrastructure domain: security groups vs NACLs, VPC design and endpoints, AWS Network Firewall, WAF, Shield, CloudFront at the edge, Session Manager instead of SSH, and vulnerability management with Inspector. Checkpoint: you can layer edge, network and host controls for a three-tier workload and say what each layer stops.
Week 6 - Detection
Cover the 16% detection domain: GuardDuty, Security Hub, Detective, Config, CloudTrail (management vs data events, integrity validation), VPC Flow Logs, CloudWatch alarms and EventBridge routing. Understand which tool answers which question - that distinction is exam gold. Checkpoint: for any “we need to know when X happens” requirement, you can name the right service and the log source it depends on.
Week 7 - Incident Response and Governance
Two lighter domains (14% each). IR: preparation and playbooks, containment that preserves evidence, snapshot-based forensics, credential-compromise response, and automated response via EventBridge. Governance: shared responsibility, Organizations and Control Tower, Artifact, Trusted Advisor, and the C03 additions on generative-AI application security. Checkpoint: you can order the response steps for a compromised-instance scenario, and explain who secures what under shared responsibility.
Week 8 - Full review and timed practice
Take the official practice question set on Skill Builder and any full-length timed reviews you have. Drill your weak domains, re-read the exam guide’s out-of-scope list so you stop over-studying, and rehearse pacing: 170 minutes for 65 questions is generous if you keep moving. Confirm booking logistics. Checkpoint: you consistently reason to correct answers on fresh scenario questions - and can explain why the wrong options fail.
A note on practice
Use original practice material and the official question set - not sites claiming to sell real questions, which violate AWS’s exam policies and teach outdated C02 content anyway. Everything on this site is original and concept-based. Cross-check anything surprising against AWS documentation: the exam rewards people who know how the services actually behave.