AWS Certified Security Specialty (SCS-C02)
Master AWS cloud security. This 32-hour instructor-led masterclass covers threat detection & incident response, security logging & monitoring, infrastructure security, identity & access management, data protection, and security governance — preparing you to safeguard sensitive data, ensure compliance, and defend against evolving threats while mastering the skills needed to pass the SCS-C02 exam.


AWS Certified Security Specialty (SCS-C02)
Security is a foundational aspect of cloud computing, and mastering it is essential for every AWS customer. Whether you’re safeguarding sensitive data, ensuring compliance, or protecting against evolving threats, the knowledge covered in this certification is indispensable. This course provides a structured, comprehensive study path aligned with the SCS-C02 exam objectives, combined with practical, real-world insights — including text explanations, video demos, hands-on live labs, self-assessment questions, and a full practice exam by MeasureUp.
Key Learning Specs
Level
Intermediate
Duration
32 Hours
Experience
2+ Yrs AWS Security Experience
Labs
Hands-on Live Labs (6 Modules)
Goal
SCS-C02 Exam Mastery
Training Details
Course Overview
Security is a foundational aspect of cloud computing, and mastering it is essential for every AWS customer. This course has been carefully designed to help you succeed in earning the AWS Certified Security Speciality certification, targeting the SCS-C02 exam with a structured study path aligned to the exam objectives and real-world practical insights.
The course includes text explanations, video demos, lab activities, self-assessment questions, and a practice exam helping learners at any current skill level improve their chances of passing on the first attempt.
Upon successful completion of this course, students will be able to:
- Describe how to detect threats and the appropriate incident response
- Explain security logging and monitoring
- Design and implement infrastructure security concepts
- Troubleshoot identity and access management issues
- Describe how to protect data
- Explain management and security governance
Required course materials:
- Pearson Skilling Suite AWS Certified Security-Specialty Courseware
Course Outline
Threat Detection and Incident Response
- Design and Implement an Incident Response Plan (48 min)
- Incident Response in AWS
- Preparation in Incident Response
- Deployment of Security Services in AWS
- Centralizing Security Management in AWS
- Detect and Respond to Security Incidents (1 hr 36 min)
- Operations – Detection and Analysis
- Categorizing Security Alerts
- Alerting Types
- Containment, Eradication, and Recovery
- Containment Strategies
- Eradication Strategies
- Recovery Strategies
- Post-Incident Activities
- Lab
- Knowledge Check
Security Logging and Monitoring
Security Monitoring and Troubleshooting (36 min)
Implementing Monitoring and Alerting with AWS CloudWatch AlarmsImplementing EventBridge Rules for Event-Driven Pipelines in AWSAutomating Security Alerts in AWS
Security Logging and Log Analysis (1 hr)
Understanding Security Logging in AWSBuilding an Effective Security Event and Log-Driven Pipeline in AWSConfiguring Permissions for Security Log Delivery in AWSTroubleshooting CloudTrail Log Delivery in Multi-Account AWS EnvironmentsAnalyzing Security Logs in AWS
LabKnowledge Check
Infrastructure Security
- Design and Implement Edge and Network Security (48 min)
- Network Security at the Edge in AWS
- VPC Security in AWS
- Encrypting Data in Transit in AWS
- Protecting Network Traffic in AWS with AWS Network Firewall
- Compute Security and Security Troubleshooting (36 min)
- Managing Vulnerabilities on an EC2-Based Platform in AWS
- Securing Secrets and Credentials for Compute Resources in AWS
- Troubleshooting Connectivity in AWS: Methodologies and Tools
- Knowledge Check
Identity and Access Management
- Design, Implement, and Troubleshoot Authentication (1 hr 36 min)
- Implementing Authentication in AWS: Identity Management Principles
- AWS Identity Management Principle: Using Temporary Credentials
- Federating External Identities with Amazon Cognito
- Machine Identities
- Store and Use Secrets Securely
- Rely on a Centralized Identity Provider
- Audit and Rotate Credentials Periodically
- Leverage User Groups and Attributes
- Design, Implement, and Troubleshoot Authorization (2 hr 12 min)
- AWS Policies
- AWS Well-Architected Framework: Security Pillar and Permissions Management
- The Principle of Least Privilege in AWS Permissions Management
- How AWS Determines Access: An In-Depth Look
- Establishing Emergency Access Processes in AWS
- Continuously Reducing Permissions
- Defining Permission Guardrails for Your Organization
- Managing Access Based on Lifecycle
- Analyzing Public and Cross-Account Access
- Sharing Resources Securely Within Your Organization
- Sharing Resources Securely with a Third Party
- Labs
- Knowledge Check
Data Protection
- In-Transit Data Protection (1 hr 12 min)
- The Three Goals of Data Encryption
- Implementing Network Encryption in AWS
- Cross-Region Protection
- AWS Certificate Manager (ACM)
- AWS Private CA Service
- Enforcing Data Encryption in Transit on AWS
- At-Rest Data Protection (1 hr 36 min)
- Protecting Data at Rest in AWS
- Protecting Data at Rest Using Encryption in AWS
- Symmetric Data Encryption in AWS
- AWS KMS
- Understanding KMS Key Types
- Managing Permissions for AWS KMS
- Encrypting Data at Rest in AWS: S3 Encryption and Cloud HSM
- Protecting Data at Rest in AWS: Beyond Encryption
- Data Lifecycle, Credential, and Secret Management (1 hr)
- Data Retention Strategies
- AWS Backup
- Asymmetric Key Encryption
- Managing and Rotating Credentials and Secrets in AWS
- Secrets Manager vs. SSM Parameter Store
- Labs
- Knowledge Check
Management and Security Governance
- AWS Resource Governance (1 hr 12 min)
- AWS Organizations
- AWS Control Tower
- AWS Control Tower Account Factory
- AWS Resource Groups
- AWS Organizations’ Tag Policies
- AWS Firewall Manager
- AWS Security Compliance (1 hr)
- Amazon Macie
- AWS Config, CloudWatch Logs, and Security Hub
- AWS Audit Manager
- AWS Well-Architected Framework
- Cost Analysis and Anomalies
- Knowledge Check
Audience profile
This course is ideal for:
- IT professionals interested in cloud computing who want to increase their security skills
- IT professionals in charge of securing data and workloads in the AWS cloud
Certification Pre-requisites
To get the most out of this course, we recommend you have:
- Approximately 5 years of IT security experience in designing and implementing security solutions
- At least 2 years of hands-on experience securing AWS workloads
- Working knowledge of AWS security services and best practices
Target certification exam: SCS-C02