AWS Certified Security Specialty (SCS-C02)

Master AWS cloud security. This 32-hour instructor-led masterclass covers threat detection & incident response, security logging & monitoring, infrastructure security, identity & access management, data protection, and security governance — preparing you to safeguard sensitive data, ensure compliance, and defend against evolving threats while mastering the skills needed to pass the SCS-C02 exam.

AWS Certified Security Specialty (SCS-C02)

Security is a foundational aspect of cloud computing, and mastering it is essential for every AWS customer. Whether you’re safeguarding sensitive data, ensuring compliance, or protecting against evolving threats, the knowledge covered in this certification is indispensable. This course provides a structured, comprehensive study path aligned with the SCS-C02 exam objectives, combined with practical, real-world insights — including text explanations, video demos, hands-on live labs, self-assessment questions, and a full practice exam by MeasureUp.

Key Learning Specs

Level

Intermediate

Duration

32 Hours

Experience

2+ Yrs AWS Security Experience

Labs

Hands-on Live Labs (6 Modules)

Goal

SCS-C02 Exam Mastery

Training Details

Security is a foundational aspect of cloud computing, and mastering it is essential for every AWS customer. This course has been carefully designed to help you succeed in earning the AWS Certified Security Speciality certification, targeting the SCS-C02 exam with a structured study path aligned to the exam objectives and real-world practical insights.

The course includes text explanations, video demos, lab activities, self-assessment questions, and a practice exam helping learners at any current skill level improve their chances of passing on the first attempt.

Upon successful completion of this course, students will be able to:

  • Describe how to detect threats and the appropriate incident response
  • Explain security logging and monitoring
  • Design and implement infrastructure security concepts
  • Troubleshoot identity and access management issues
  • Describe how to protect data
  • Explain management and security governance

Required course materials:

  • Pearson Skilling Suite AWS Certified Security-Specialty Courseware
  • Design and Implement an Incident Response Plan (48 min)
    • Incident Response in AWS
    • Preparation in Incident Response
    • Deployment of Security Services in AWS
    • Centralizing Security Management in AWS
  • Detect and Respond to Security Incidents (1 hr 36 min)
    • Operations – Detection and Analysis
    • Categorizing Security Alerts
    • Alerting Types
    • Containment, Eradication, and Recovery
    • Containment Strategies
    • Eradication Strategies
    • Recovery Strategies
    • Post-Incident Activities
  • Lab
  • Knowledge Check
  • Security Monitoring and Troubleshooting (36 min) 
    • Implementing Monitoring and Alerting with AWS CloudWatch Alarms
    • Implementing EventBridge Rules for Event-Driven Pipelines in AWS
    • Automating Security Alerts in AWS
  • Security Logging and Log Analysis (1 hr) 
    • Understanding Security Logging in AWS
    • Building an Effective Security Event and Log-Driven Pipeline in AWS
    • Configuring Permissions for Security Log Delivery in AWS
    • Troubleshooting CloudTrail Log Delivery in Multi-Account AWS Environments
    • Analyzing Security Logs in AWS
  • Lab
  • Knowledge Check
  • Design and Implement Edge and Network Security (48 min)
    • Network Security at the Edge in AWS
    • VPC Security in AWS
    • Encrypting Data in Transit in AWS
    • Protecting Network Traffic in AWS with AWS Network Firewall
  • Compute Security and Security Troubleshooting (36 min)
    • Managing Vulnerabilities on an EC2-Based Platform in AWS
    • Securing Secrets and Credentials for Compute Resources in AWS
    • Troubleshooting Connectivity in AWS: Methodologies and Tools
  • Knowledge Check
  • Design, Implement, and Troubleshoot Authentication (1 hr 36 min)
    • Implementing Authentication in AWS: Identity Management Principles
    • AWS Identity Management Principle: Using Temporary Credentials
    • Federating External Identities with Amazon Cognito
    • Machine Identities
    • Store and Use Secrets Securely
    • Rely on a Centralized Identity Provider
    • Audit and Rotate Credentials Periodically
    • Leverage User Groups and Attributes
  • Design, Implement, and Troubleshoot Authorization (2 hr 12 min)
    • AWS Policies
    • AWS Well-Architected Framework: Security Pillar and Permissions Management
    • The Principle of Least Privilege in AWS Permissions Management
    • How AWS Determines Access: An In-Depth Look
    • Establishing Emergency Access Processes in AWS
    • Continuously Reducing Permissions
    • Defining Permission Guardrails for Your Organization
    • Managing Access Based on Lifecycle
    • Analyzing Public and Cross-Account Access
    • Sharing Resources Securely Within Your Organization
    • Sharing Resources Securely with a Third Party
  • Labs
  • Knowledge Check
  • In-Transit Data Protection (1 hr 12 min)
    • The Three Goals of Data Encryption
    • Implementing Network Encryption in AWS
    • Cross-Region Protection
    • AWS Certificate Manager (ACM)
    • AWS Private CA Service
    • Enforcing Data Encryption in Transit on AWS
  • At-Rest Data Protection (1 hr 36 min)
    • Protecting Data at Rest in AWS
    • Protecting Data at Rest Using Encryption in AWS
    • Symmetric Data Encryption in AWS
    • AWS KMS
    • Understanding KMS Key Types
    • Managing Permissions for AWS KMS
    • Encrypting Data at Rest in AWS: S3 Encryption and Cloud HSM
    • Protecting Data at Rest in AWS: Beyond Encryption
  • Data Lifecycle, Credential, and Secret Management (1 hr)
    • Data Retention Strategies
    • AWS Backup
    • Asymmetric Key Encryption
    • Managing and Rotating Credentials and Secrets in AWS
    • Secrets Manager vs. SSM Parameter Store
  • Labs
  • Knowledge Check
  • AWS Resource Governance (1 hr 12 min)
    • AWS Organizations
    • AWS Control Tower
    • AWS Control Tower Account Factory
    • AWS Resource Groups
    • AWS Organizations’ Tag Policies
    • AWS Firewall Manager
  • AWS Security Compliance (1 hr)
    • Amazon Macie
    • AWS Config, CloudWatch Logs, and Security Hub
    • AWS Audit Manager
    • AWS Well-Architected Framework
    • Cost Analysis and Anomalies
  • Knowledge Check
  • This course is ideal for:

    • IT professionals interested in cloud computing who want to increase their security skills
    • IT professionals in charge of securing data and workloads in the AWS cloud
  • To get the most out of this course, we recommend you have:

    • Approximately 5 years of IT security experience in designing and implementing security solutions
    • At least 2 years of hands-on experience securing AWS workloads
    • Working knowledge of AWS security services and best practices

    Target certification exam: SCS-C02