Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Amazon
Exam Format
170 min
65
750
Specialty
Registration
$300 USD
Pearson VUE or online proctoring
English, Japanese, Korean, Portuguese (Brazil) +2 more
Validity
3 years
Pass the current version of the exam; Pass a higher-level exam in the same track; Earn continuing education credits through AWS re:Invent, AWS Summit, or AWS Training
Exam Guide
SCS-C02 Exam Topics and Domains
SCS-C02 is organized into 6 weighted domains. Expect to work with AWS Config, AWS Security Hub, VPC Flow Logs, Amazon Athena, and more.
1
Threat Detection and Incident Response
14%
Design and implement an incident response plan
AWS incident response best practicesSecurity service deployment
- Implement credential invalidation and rotation strategies in response to compromises
- Isolate AWS resources during security incidents
- Design and implement playbooks and runbooks for security incident responses
- Deploy and configure security services for incident detection
- Configure integrations with native AWS services and third-party services
Detect security threats and anomalies
Threat detection using AWS servicesSecurity monitoring and analysis
- Evaluate findings from security services
- Search and correlate security threats across AWS services
- Perform queries to validate security events
- Create metric filters and dashboards to detect anomalous activity
Respond to compromised resources and workloads
Incident response automationForensics and evidence collection
- Automate remediation using AWS services
- Respond to compromised resources
- Investigate and conduct root cause analysis
- Capture relevant forensics data from compromised resources
- Query logs in Amazon S3 for contextual information
- Protect and preserve forensic artifacts
- Prepare services for incidents and recover after incidents
2
Security Logging and Monitoring
18%
Design and implement monitoring and alerting
Monitoring architecture design
- Analyze architectures to identify monitoring requirements
- Design environment and workload monitoring based on business requirements
- Set up automated tools and scripts for regular audits
- Define metrics and thresholds for alerts
Troubleshoot security monitoring and alerting
Monitoring service configuration
- Analyze service functionality and permissions after security events
- Remediate configuration of custom applications
- Evaluate logging and monitoring services for security requirements
Design and implement a logging solution
Logging architecture
- Configure logging for services and applications
- Identify logging requirements and sources
- Implement log storage and lifecycle management
Troubleshoot logging solutions
Logging troubleshooting
- Identify misconfiguration and determine remediation steps
- Determine causes of missing logs and perform remediation
Design a log analysis solution
Log analysis and correlation
- Identify patterns in logs to indicate anomalies and threats
- Normalize, parse, and correlate logs
3
Infrastructure Security
20%
Design and implement security controls for edge services
Edge security architecture
- Define edge security strategies for common use cases
- Select appropriate edge services based on threats
- Define layers of defense by combining edge services
- Apply restrictions at the edge based on various criteria
- Activate logs and monitoring for edge services
Design and implement network security controls
VPC securityHybrid connectivity
- Implement network segmentation based on security requirements
- Design network controls to permit or prevent traffic
- Design network flows to keep data off public internet
- Determine telemetry sources to monitor
- Determine redundancy and security for hybrid connectivity
- Identify and remove unnecessary network access
Design and implement security controls for compute workloads
Compute security
- Create hardened EC2 AMIs
- Apply instance and service roles appropriately
- Scan EC2 instances and container images for vulnerabilities
- Apply patches across fleets
- Activate host-based security mechanisms
- Analyze Inspector findings and determine mitigation
- Pass secrets and credentials securely to workloads
Troubleshoot network security
Network troubleshooting
- Identify and prioritize network connectivity problems
- Determine solutions for desired network behavior
- Analyze log sources to identify problems
- Capture traffic samples for analysis
4
Identity and Access Management
16%
Design, implement, and troubleshoot authentication
Authentication mechanisms
- Establish identity through authentication systems
- Set up multi-factor authentication
- Determine when to use AWS STS for temporary credentials
- Troubleshoot authentication issues
Design, implement, and troubleshoot authorization
IAM policies and authorization
- Construct ABAC and RBAC strategies
- Evaluate IAM policy types for requirements
- Interpret IAM policy effects
- Apply principle of least privilege
- Enforce separation of duties
- Analyze authorization errors
- Investigate unintended permissions
5
Data Protection
18%
Design and implement controls for data in transit
Encryption in transit
- Design secure connectivity between AWS and on-premises
- Design mechanisms to require encryption when connecting
- Require TLS for AWS API calls
- Design mechanisms to forward traffic over secure connections
- Design cross-Region networking using VIFs
Design and implement controls for data at rest
Encryption at rest
- Design resource policies to restrict access
- Design mechanisms to prevent unauthorized public access
- Configure services for encryption at rest
- Design mechanisms to protect data integrity
- Design encryption using CloudHSM for databases
- Choose encryption techniques based on requirements
Design and implement lifecycle management for data
Data lifecycle
- Design S3 Lifecycle mechanisms for retention
- Design automatic lifecycle management
- Establish schedules and retention for AWS Backup
Design and implement controls for credentials and keys
Secrets management
- Design management and rotation of secrets
- Design KMS key policies to limit usage
- Establish mechanisms for customer-provided keys
6
Management and Security Governance
14%
Develop strategy for centralized AWS account management
Multi-account management
- Deploy and configure AWS Organizations
- Determine when to deploy AWS Control Tower
- Implement SCPs as technical solutions
- Centrally manage security services
- Secure AWS account root user credentials
Implement secure deployment strategy
Infrastructure as Code security
- Use CloudFormation for consistent deployment
- Implement multi-account tagging strategies
- Configure and deploy approved service portfolios
- Deploy Firewall Manager policies
- Securely share resources across accounts
Evaluate compliance of AWS resources
Compliance assessment
- Identify sensitive data using Macie
- Create AWS Config rules for compliance
- Collect and organize evidence
Identify security gaps through reviews
Security assessment
- Identify anomalies based on resource utilization
- Identify unused resources
- Use Well-Architected Tool for security gaps
Who should take this exam?
This exam is typically taken by Security Engineers and Security Architects.
- 3-5 years of experience designing and implementing security solutions
- Minimum 2 years of hands-on experience securing AWS workloads
- Working knowledge of AWS security services and features
- Understanding of AWS shared responsibility model
- Experience with logging and monitoring strategies
- Knowledge of threat detection and incident response
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.