AWS Security Specialty

Amazon Web Services

Complete guide to passing the AWS Security Specialty exam on your first attempt.

HardHigh Search Volume
Key Information at a Glance
Cost

$300

Pass Rate

~45%

Validity

3 years

Region

Global

Provider

Amazon Web Services

Salary Impact

$140k-$190k

Are you ready for AWS Security Specialty?

Loading quiz...

Complete Overview

AWS Certified Security - Specialty, exam code SCS-C02, is a specialty-level certification from Amazon Web Services that validates the ability to secure workloads and architectures running on AWS. The exam costs 300 USD per attempt, runs 170 minutes, contains 65 questions, and is delivered either at a Pearson VUE test center or through online proctoring. It is taken mostly by security engineers, cloud architects and DevSecOps staff who already run production AWS environments.

Amazon describes the target candidate in the SCS-C02 exam guide as someone with three to five years of experience designing and implementing security solutions, plus a minimum of two years of hands-on experience securing AWS workloads. That second requirement is the one candidates underestimate. The questions are written as scenarios in which several AWS services could plausibly solve the problem, and the correct answer usually depends on a detail such as whether a KMS key policy or an IAM policy is the binding constraint, or whether a finding should be routed through EventBridge or handled inside Security Hub.

Of the 65 questions, only 50 affect your score. The other 15 are unscored pretest items that AWS uses to evaluate new questions, and they are not identified during the exam. Results are reported as a scaled score from 100 to 1,000 with a minimum passing score of 750. The exam uses a compensatory scoring model, so a weak section can be offset by a strong one; you only need to clear the overall bar.

The blueprint splits into six domains. Infrastructure Security carries the largest share at 20 percent, followed by Security Logging and Monitoring and Data Protection at 18 percent each, Identity and Access Management at 16 percent, and Threat Detection and Incident Response and Management and Security Governance at 14 percent each. Identity and Access Management is smaller than most candidates expect, but IAM reasoning bleeds into every other domain, because resource policies, KMS key policies and service control policies show up inside data protection and governance questions too.

AWS states on the certification page that job listings requiring this certification rose 73 percent between October 2021 and September 2022, citing Lightcast data from October 2022, and that the credential ranked among the top highest-paying technical certifications in the United States in Skillsoft's October 2024 IT Skills and Salary survey. The certification is valid for three years, and AWS renews it only by passing the current version of the exam again. There are no prerequisites, and AWS does not publish a pass rate for any of its exams.

Why Get AWS Security Specialty Certified?

The exam sits at the 300 USD specialty price tier, the same as AWS professional-level exams, and the credential covers a security scope that no associate-level AWS certification touches in depth.

AWS reports on the certification page that job postings requiring AWS Certified Security - Specialty grew 73 percent between October 2021 and September 2022, based on Lightcast data published in October 2022.

AWS names this certification among the top highest-paying technical certifications in the United States, citing findings from Skillsoft's October 2024 IT Skills and Salary survey.

The 20 percent Infrastructure Security domain and the 18 percent Data Protection domain map directly onto the work of a cloud security engineer, so the study effort produces skills that transfer to the job rather than trivia.

Passing any AWS certification earns a 50 percent discount voucher toward your next AWS exam, which takes a follow-on specialty or professional exam from 300 USD to 150 USD.

The certification lasts three years, longer than the annual renewal cycle Microsoft applies to its Azure associate certifications, so the recertification overhead is one exam every 36 months.

AWS lists the AWS Certified DevOps Engineer - Professional and AWS Certified Advanced Networking - Specialty as the natural follow-on credentials, giving a defined route toward DevSecOps and network security roles.

Exam Format & Structure

Duration

170 minutes

Questions

65 questions, of which 50 are scored and 15 are unscored pretest items that are not identified during the exam

Passing Score

750 on a scaled range of 100 to 1,000, using a compensatory model that does not require a passing score in each domain

Question Types

  • Multiple choice with one correct response and three distractors
  • Multiple response with two or more correct responses out of five or more options

Delivery Method

Pearson VUE test center or online proctored exam through Pearson VUE OnVUE

Exam Domains & Topics

Threat detection and incident response
14%

Covers designing an incident response plan for AWS, detecting threats and anomalies using AWS managed security services, and responding to compromised resources. Tasks include credential invalidation and rotation, isolating resources, building playbooks and runbooks, and preserving forensic artifacts so that evidence survives the response itself.

Key Topics to Master:

  • AWS Security Finding Format and centralising findings in Security Hub
  • Amazon GuardDuty finding types and Amazon Detective investigation workflows
  • Isolating a compromised EC2 instance without destroying volatile evidence
  • Capturing EBS volume snapshots and memory dumps for forensics
  • Protecting artifacts with S3 Object Lock, isolated forensic accounts and S3 replication
  • Automated remediation with Lambda, Step Functions, EventBridge and Systems Manager runbooks
  • Querying CloudTrail and VPC Flow Logs in Amazon S3 with Amazon Athena
  • IAM Access Analyzer and Amazon Macie findings
Security logging and monitoring
18%

Covers designing monitoring and alerting for security events, troubleshooting monitoring that fails to fire, designing a logging solution across accounts, troubleshooting missing logs, and designing log analysis. Much of this domain is diagnostic: given an event that produced no alert, work out which permission, configuration or data source was absent.

Key Topics to Master:

  • AWS CloudTrail organization trails, data events and CloudTrail Insights
  • VPC Flow Logs, Route 53 Resolver query logs and AWS WAF logs
  • CloudWatch metric filters, alarms and CloudWatch Logs Insights queries
  • S3 bucket policies and KMS key permissions required for log delivery
  • Log retention, lifecycle management and immutable storage
  • Custom insights in AWS Security Hub and automated audit scripting
  • Diagnosing a custom application that stops reporting statistics
  • Normalising, parsing and correlating logs from multiple sources
Infrastructure security
20%

The largest domain. Covers edge security controls, network security controls inside and between VPCs, security controls for compute workloads, and troubleshooting network security. Expect questions that require choosing between security groups, network ACLs and AWS Network Firewall for the same requirement, and layering CloudFront, AWS WAF and AWS Shield correctly.

Key Topics to Master:

  • AWS WAF rule groups, rate-based rules and geographic restrictions
  • AWS Shield Advanced compared with Shield Standard for DDoS protection
  • Security groups, network ACLs and AWS Network Firewall selection
  • VPC endpoints, AWS Transit Gateway and keeping traffic off the public internet
  • AWS VPN, AWS Direct Connect, VPN over Direct Connect and MACsec
  • Hardened AMIs, EC2 Image Builder and patching fleets with Systems Manager
  • Amazon Inspector findings for EC2 instances and Amazon ECR container images
  • VPC Reachability Analyzer, Network Access Analyzer and Traffic Mirroring
  • AWS Firewall Manager for policy enforcement across accounts
Identity and access management
16%

Covers designing, implementing and troubleshooting authentication and authorization for AWS resources. Authentication topics include federation, AWS IAM Identity Center, Amazon Cognito, MFA and temporary credentials from AWS STS. Authorization topics centre on how identity-based policies, resource-based policies, permissions boundaries and session policies combine to allow or deny a request.

Key Topics to Master:

  • Policy evaluation logic across identity-based, resource-based and session policies
  • Principal, Action, Resource and Condition elements and condition keys
  • Attribute-based access control compared with role-based access control
  • AWS IAM Identity Center and external identity provider federation
  • Amazon Cognito user pools and identity pools
  • AWS STS AssumeRole, external IDs and cross-account trust policies
  • IAM policy simulator, IAM Access Advisor and CloudTrail for authorization failures
  • Least privilege and separation of duties in a multi-account setup
Data protection
18%

Covers confidentiality and integrity for data in transit and at rest, lifecycle management for stored data, and protection of credentials, secrets and key material. AWS KMS appears throughout: key policies, grants, symmetric and asymmetric keys, imported key material, and the interaction between a key policy and an IAM policy in the same account.

Key Topics to Master:

  • AWS KMS key policies, grants, key rotation and imported key material
  • AWS CloudHSM for relational databases including RDS Custom
  • Client-side compared with server-side encryption, symmetric compared with asymmetric
  • TLS enforcement with aws:SecureTransport conditions on S3 bucket policies
  • AWS Certificate Manager with CloudFront, load balancers and API Gateway
  • S3 Block Public Access, S3 Object Lock, S3 Glacier Vault Lock and AWS Backup Vault Lock
  • AWS Secrets Manager rotation compared with Systems Manager Parameter Store
  • Systems Manager Session Manager and EC2 Instance Connect for secure remote access
Management and security governance
14%

Covers centrally deploying and managing AWS accounts, consistent and secure deployment of cloud resources, evaluating compliance of AWS resources, and identifying security gaps through architectural review and cost analysis. Service control policies and AWS Organizations delegated administration appear repeatedly in questions about enforcing a rule across many accounts.

Key Topics to Master:

  • AWS Organizations structure, service control policies and delegated administration
  • AWS Control Tower deployment and services that must be deactivated first
  • CloudFormation template hardening and drift detection
  • AWS Config rules, conformance packs and Config aggregators
  • AWS Service Catalog portfolios and multi-account tagging strategies
  • AWS Resource Access Manager for secure cross-account resource sharing
  • Amazon Macie for sensitive data classification and AWS Audit Manager for evidence
  • Cost Explorer and Trusted Advisor for spotting anomalous resource usage

Recommended Study Plan

Week 1: Blueprint, baseline and IAM policy evaluation
8-10 hours
  • 1Download the SCS-C02 exam guide from the AWS Certified Security - Specialty page and copy the six domain weightings into a tracking sheet
  • 2Take the free AWS Certification Official Practice Question Set for SCS-C02 on AWS Skill Builder to establish a baseline
  • 3Read the AWS documentation page on IAM policy evaluation logic end to end, including the deny, organizations SCP, resource policy and permissions boundary ordering
  • 4Build a two-account AWS Organizations sandbox and write a cross-account role with an external ID
  • 5Work through ten questions in the IAM policy simulator against policies you wrote yourself
Week 2: Identity and access management depth
8-10 hours
  • 1Configure AWS IAM Identity Center with an external identity provider and assign permission sets
  • 2Set up an Amazon Cognito user pool and identity pool and trace the token exchange with AWS STS
  • 3Write and test attribute-based access control policies using aws:PrincipalTag and resource tags
  • 4Practise deliberately breaking a policy, then diagnosing it with CloudTrail and IAM Access Advisor
  • 5Review the AWS Skill Builder Exam Prep Plan module covering domain 4
Week 3: Data protection and AWS KMS
9-11 hours
  • 1Read the AWS Key Management Service Developer Guide sections on key policies, grants and key rotation
  • 2Create a customer managed key and deny access to it from an IAM administrator using only the key policy
  • 3Import key material into KMS and observe expiry behaviour, then test cross-account key usage
  • 4Enable S3 Object Lock in governance and compliance modes on separate buckets and try to delete objects
  • 5Configure Secrets Manager rotation for an RDS credential using the provided Lambda rotation function
Week 4: Data in transit and secure remote access
8-10 hours
  • 1Issue an ACM certificate and attach it to an Application Load Balancer and a CloudFront distribution
  • 2Write an S3 bucket policy that denies requests where aws:SecureTransport is false and test it
  • 3Configure Systems Manager Session Manager with session logging to S3 and CloudWatch Logs
  • 4Build a site-to-site VPN to a simulated on-premises endpoint and review the IPsec parameters
  • 5Review the AWS Well-Architected Framework Security Pillar whitepaper sections on data protection
Week 5: Infrastructure security part one, edge and network
9-11 hours
  • 1Deploy AWS WAF in front of CloudFront with a rate-based rule and a geographic match rule, then generate traffic to trigger them
  • 2Compare AWS Shield Standard and Shield Advanced features in the AWS Shield documentation
  • 3Build a VPC with public and private subnets, then replace a NAT route with VPC endpoints for S3 and DynamoDB
  • 4Deploy AWS Network Firewall with a stateful rule group and compare its behaviour with a network ACL
  • 5Practise reading VPC Flow Log records field by field until you can identify a rejected flow at a glance
Week 6: Infrastructure security part two, compute
8-10 hours
  • 1Build a hardened AMI with EC2 Image Builder including a CIS-style hardening component
  • 2Enable Amazon Inspector for EC2 and Amazon ECR and review the finding severity model
  • 3Patch a fleet of EC2 instances with Systems Manager Patch Manager and a maintenance window
  • 4Attach an instance profile and demonstrate how a workload retrieves credentials from IMDSv2
  • 5Run VPC Reachability Analyzer against a deliberately broken path and interpret the output
Week 7: Logging and monitoring
8-10 hours
  • 1Create a CloudTrail organization trail with data events for a specific S3 bucket and Lambda function
  • 2Break log delivery on purpose by removing the required S3 bucket policy statement, then diagnose the failure
  • 3Write three CloudWatch Logs Insights queries against CloudTrail data, including one for failed console logins
  • 4Query CloudTrail logs in Athena using the AWS-provided table definition
  • 5Create a CloudWatch metric filter and alarm for root account usage and confirm it fires
Week 8: Threat detection and incident response
9-11 hours
  • 1Enable GuardDuty across the organization and generate sample findings, then review each finding type
  • 2Enable Amazon Detective and follow a finding through to a behaviour graph
  • 3Read the AWS Security Incident Response Guide whitepaper, focusing on the containment and eradication sections
  • 4Build an EventBridge rule that routes a GuardDuty finding to a Lambda function that isolates an EC2 instance
  • 5Enable Security Hub, turn on the AWS Foundational Security Best Practices standard and review failing controls
Week 9: Governance and multi-account controls
8-10 hours
  • 1Write service control policies that deny root user actions and restrict regions, then test them on a member account
  • 2Deploy AWS Control Tower in the sandbox organization and review the preventive and detective controls it installs
  • 3Create a custom AWS Config rule backed by Lambda and an AWS Config aggregator across two accounts
  • 4Share a resource across accounts with AWS Resource Access Manager and inspect the resulting permissions
  • 5Run Amazon Macie on a bucket seeded with synthetic PII and review the sensitive data discovery results
Week 10: Full-length practice and weak domain repair
10-12 hours
  • 1Take the AWS Certification Official Pretest for SCS-C02 on AWS Skill Builder under timed conditions
  • 2Rebuild every question you missed into a one-line rule stating why the correct service was correct
  • 3Review the list of AWS service short names available through the Help button in the exam so the abbreviations do not slow you down
  • 4Re-read the exam guide appendix listing in-scope and out-of-scope services and drop revision on out-of-scope topics
  • 5Sit one more timed set of 65 questions with a strict 170-minute clock to rehearse pacing at 2.6 minutes per question

Ready to pass AWS Security Specialty?

Get 500+ practice questions, video walkthroughs, and a pass guarantee.

94% pass rate on first attempt
$150$75

Best Study Resources

AWS Certified Security - Specialty (SCS-C02) Exam Guide

Official exam blueprint

The authoritative document for domain weightings, task statements, scoring, and the appendix listing in-scope and out-of-scope AWS services. Version 1.1 is the current SCS-C02 guide.

Free

AWS Certification Official Practice Question Set: Security - Specialty

Practice questions

A short set of exam-style questions written by AWS with explanations for both correct and incorrect responses. Useful for calibrating how AWS phrases distractors before you buy anything else.

Free on AWS Skill Builder

AWS Certification Official Pretest: Security - Specialty

Full-length practice exam

A full-length pretest that mirrors the real exam structure and reports performance by domain. The Individual subscription is 29 USD per month or 449 USD per year.

Included with an AWS Skill Builder Individual subscription

AWS Skill Builder Exam Prep Plan for Security - Specialty

Structured course

AWS-authored four-step plan covering exam-style questions, digital courses, domain review with flashcards, and readiness assessment. Includes AWS Builder Labs and AWS SimuLearn exercises for hands-on practice.

Free tier plus paid tier

AWS Security Incident Response Guide

Official whitepaper

Named directly in task statement 1.3 of the exam guide. It defines the incident response lifecycle AWS expects you to apply, including forensic account isolation and evidence preservation.

Free

AWS Well-Architected Framework Security Pillar

Official whitepaper

Referenced in task statement 6.4. It supplies the design principles behind many correct answers, particularly for detective controls, data classification and incident response readiness.

Free

AWS Key Management Service Developer Guide

Official documentation

The single densest source for the Data Protection domain. The sections on key policies, grants, cross-account key access and imported key material map directly onto exam scenarios.

Free

AWS Exam Demo tool at Pearson VUE

Interface familiarisation

Lets you practise the actual exam interface, including colour contrast options, the mark-for-review function, and the English-language toggle used on translated exams.

Free

AWS Builder Labs

Hands-on labs

Provisioned AWS environments for practising GuardDuty, Security Hub, KMS and network security tasks without spending on your own account. Labs typically cost up to 15 credits when bought individually.

Included with AWS Skill Builder Individual subscription, or paid with credits at 1 USD per credit

AWS Security Blog

Reference reading

AWS engineers publish walkthroughs of the exact patterns the exam tests, such as cross-account KMS access, SCP design and centralised logging architectures.

Free

Common Mistakes to Avoid

Treating an IAM policy as sufficient to grant access to a KMS-encrypted resource, and ignoring the key policy.

Learn the rule that a KMS key policy must explicitly allow access before an IAM policy can grant it, including the standard statement that delegates to IAM in the key's own account. Practise revoking access to a key purely through the key policy while leaving the IAM administrator policy untouched.

Choosing network ACLs when the scenario calls for security groups, or the reverse, because the stateful and stateless distinction was memorised as a phrase rather than tested.

Build a subnet where the network ACL allows inbound traffic but blocks the ephemeral return port range, then observe the connection failing. Once you have seen a stateless rule break a working connection, the exam scenarios become mechanical.

Assuming CloudTrail records everything, then choosing it as the answer for S3 object-level or Lambda invocation visibility without enabling data events.

Enable CloudTrail data events for a specific S3 bucket prefix and a Lambda function and look at the cost and volume difference. Remember that management events are logged by default and data events are not.

Spending the bulk of study time on IAM because it feels like the core of AWS security, when it is only 16 percent of scored content.

Weight study hours to the published blueprint: Infrastructure Security at 20 percent, Logging and Monitoring and Data Protection at 18 percent each. IAM knowledge still pays off because policy reasoning appears inside the other domains, but dedicated IAM revision should not dominate the schedule.

Isolating a compromised EC2 instance by terminating it or detaching its volumes before capturing evidence.

Follow the sequence in the AWS Security Incident Response Guide: snapshot the EBS volumes, capture a memory dump if required, replace the security group with a deny-all group, and move the instance into an isolated forensic account. Termination destroys the evidence the exam scenario usually wants preserved.

Confusing AWS Shield Advanced, AWS WAF and Amazon CloudFront responsibilities when a DDoS question appears.

Fix the layers in your head: Shield handles volumetric and protocol attacks at layers three and four with Shield Advanced adding cost protection and the AWS Shield Response Team, WAF handles layer seven rules, and CloudFront absorbs traffic at the edge. Exam answers usually combine two of the three.

Answering multi-account governance questions with IAM policies applied account by account instead of service control policies.

Whenever a scenario says the control must apply across an organization, across all future accounts, or must not be removable by an account administrator, reach for a service control policy or an AWS Control Tower control. Practise writing an SCP that denies a region and confirm an account admin cannot override it.

Running out of time because the 65 questions include long multi-paragraph scenarios and candidates re-read them from the start.

At 170 minutes for 65 questions the budget is roughly 2.6 minutes each. Read the final sentence of the scenario first to find the actual requirement, then read the body once with that requirement in mind. Flag anything over four minutes and return to it.

Studying services listed as out of scope in the exam guide appendix, such as AWS Database Migration Service or the AWS Elemental media services.

Read the appendix of the SCS-C02 exam guide before week one and delete out-of-scope services from your revision list. The in-scope list is short enough to cover properly, and it names Amazon Detective, AWS Audit Manager and AWS Firewall Manager, which many candidates skip.

Exam Day Tips

  • 1

    Identification requirements differ by delivery method. A test centre appointment needs two primary IDs, or one primary and one secondary; an online proctored appointment needs a single primary ID. A primary ID must be an original, unexpired, government-issued document carrying your photo, your signature and your name in Roman characters, and that name must match your AWS Certification Account exactly.

  • 2

    If you do not hold a qualifying government-issued ID from the country where you are testing, an international travel passport from your country of citizenship must be your primary ID, with a secondary ID still required. European Union IDs are the stated exception.

  • 3

    Nothing is permitted on your desk. There is no calculator, no scratch paper and no reference sheet, because SCS-C02 requires no arithmetic; every answer is a design judgement.

  • 4

    Use the Help button during the exam to open the list of AWS service short names and their full names. AWS added this so abbreviations such as ACM, ASFF and ASG do not cost you time.

  • 5

    If English is not your first language and you are sitting the English version, request the ESL +30 accommodation before you register. It adds 30 minutes and only needs to be requested once for all future AWS exams.

  • 6

    For an online proctored appointment through OnVUE, clear your desk completely, run the system test in advance, and be ready to show all four walls of the room on camera. Communication with the proctor is required to start.

  • 7

    Plan for 2.6 minutes per question. Use the mark-for-review function on any question where two answers both look defensible, and finish the whole paper before returning to flagged items.

  • 8

    There is no penalty for guessing, and unanswered questions are scored as incorrect, so never leave anything blank even if the clock is nearly out.

  • 9

    Your score does not appear at the test centre in final form. AWS posts final results to your AWS Certification Account within five business days, with a downloadable PDF score report under Exam History.

Career Paths & Salary Ranges

Cloud security engineer

Builds and operates preventive and detective controls across AWS accounts. Day to day this means writing service control policies, tuning GuardDuty and Security Hub, managing KMS key hierarchies and reviewing IAM permissions before they reach production.

$140k-$190k

DevSecOps engineer

Embeds security checks into CI/CD pipelines, hardens CloudFormation and Terraform templates, runs container image scanning through Amazon ECR and Amazon Inspector, and automates remediation with Lambda and EventBridge. AWS names DevOps Engineer - Professional as the usual next certification for this track.

$140k-$190k

Security operations analyst on AWS

Owns detection and response. Triages GuardDuty and Security Hub findings, investigates in Amazon Detective, queries CloudTrail in Athena, and runs the incident response playbooks defined in the AWS Security Incident Response Guide.

$140k-$190k

Cloud security architect

Designs multi-account landing zones, defines the AWS Organizations structure and guardrails, sets the encryption and key management standard, and reviews workload designs against the Well-Architected Security Pillar before they are built.

$140k-$190k

Compliance and cloud governance specialist

Maps regulatory requirements onto AWS Config rules and conformance packs, collects evidence through AWS Audit Manager and Security Hub, runs Amazon Macie for data classification, and reports posture to auditors and risk committees.

$140k-$190k

Prerequisites & Requirements

  • There are no formal prerequisites. AWS states that all its certifications can be earned without completing any specific prior certification.
  • AWS recommends three to five years of experience designing and implementing security solutions, as stated in the SCS-C02 exam guide.
  • AWS also recommends a minimum of two years of hands-on experience securing AWS workloads in production.
  • AWS notes that candidates commonly hold AWS Certified Solutions Architect - Associate or AWS Certified Solutions Architect - Professional first, although neither is required.
  • Candidates aged 13 to 17 may take AWS Certification exams with the consent of a parent or legal guardian.
  • You need an AWS Certification Account, which is separate from your AWS account and is created with an AWS Builder ID.

Frequently Asked Questions

How much does the AWS Certified Security - Specialty exam cost?

The exam costs 300 USD, the standard AWS specialty and professional price tier. AWS publishes local currency prices of 256 EUR, 449 AUD, 40,000 JPY, 394,575 KRW and 2,113 CNY, with 25,659 INR available only through the Pearson VUE Mindhub voucher store. AWS updates these foreign exchange prices at least annually in May, with a minimum of 30 days notice for any change.

What is the passing score for SCS-C02?

The minimum passing score is 750 on a scaled range of 100 to 1,000. AWS sets that standard using the modified Angoff technique, in which a panel of subject matter experts rates the difficulty of each question for a minimally qualified candidate, and then equates later exam forms statistically so that different question sets hold candidates to the same standard. Scaled scoring means there is no fixed number of questions you must answer correctly.

What happens if I fail the exam?

You must wait 14 calendar days before you can retake it. AWS places no limit on the number of attempts, but you pay the full 300 USD registration fee each time. Your score report, available in your AWS Certification Account under Exam History, includes a table of classifications showing your relative performance in each domain, which tells you where to concentrate before the retake.

How long does it take to get results?

AWS posts final results to your AWS Certification Account within five business days of the exam closing. The only stated exception is when results are held for security or technical review. Once available, you can view, download or print a PDF score report from the Exam History table.

How long is the certification valid and how do I recertify?

AWS Certified Security - Specialty is valid for three years. AWS does not use continuing education credits for this certification. You recertify by passing the current version of the exam before your credential expires, and holding an active AWS certification entitles you to a 50 percent discount voucher toward your next AWS exam, which halves the cost of that recertification attempt.

What identification do I need to bring?

A test centre appointment needs two primary IDs, or one primary and one secondary; an online proctored appointment needs a single primary ID. A primary ID is an original, unexpired, government-issued document showing your photo, your signature and your name in Roman characters. If you do not hold a qualifying government-issued ID from the country you are testing in, an international travel passport from your country of citizenship is required as your primary ID, with European Union IDs as the stated exception. ID requirements differ between test centre and online appointments, so review Pearson VUE's guidelines for the format you booked.

Can I take SCS-C02 online, and what are the rules?

Yes. Online proctoring through Pearson VUE OnVUE is available for all AWS Certification exams. English proctoring runs 24 hours a day, seven days a week. Japanese proctoring runs Monday to Saturday, 9 a.m. to 4 p.m. local Japan time; Spanish (Latin America) proctoring runs Monday to Friday, 10:00 a.m. to 5:45 p.m. Eastern; Mandarin proctoring for customers in mainland China runs Monday to Friday, 8:00 a.m. to 5:00 p.m. local China time. Communication with the proctor is required to complete the appointment.

Are calculators, notes or reference materials allowed?

No external materials are permitted. The exam includes no calculations that need a calculator, and no scratch paper or notes are allowed. The only in-exam reference is the list of AWS service short names and their full names, which you open through the Help button during the exam.

What accommodations are available?

AWS grants reasonable accommodations for documented disabilities, arranged in advance through Pearson VUE, and accommodations must be requested before you schedule each exam. Separately, non-native English speakers sitting the English version can request the ESL +30 accommodation for an extra 30 minutes; that request is made once through your AWS Certification Account and applies to all future AWS exam registrations. Certain comfort aids such as medicines and medical devices need no prior approval.

How many questions actually count toward my score?

Fifty of the 65 questions are scored. The remaining 15 are unscored pretest items that AWS uses to evaluate questions for future use, and they are not marked or identifiable during the exam. Because you cannot tell which is which, treat every question as scored. Unanswered questions count as incorrect and there is no guessing penalty.

Can I reschedule or cancel my exam appointment?

You can reschedule up to 24 hours before your appointment, and each appointment can only be rescheduled twice; a third change requires cancelling and rebooking. Cancelling more than 24 hours ahead refunds the fee you paid. Cancelling within 24 hours or failing to appear forfeits the fee, although Pearson VUE will waive it for documented illness or an unforeseen emergency.

How does this compare with AWS Certified Solutions Architect - Professional?

Both sit at the 300 USD price tier and both use scaled scoring with a 750 pass mark, but they test different things. Solutions Architect - Professional covers architecture breadth across compute, storage, networking, migration and cost, in 180 minutes with 75 questions. Security - Specialty goes deeper on a narrower surface: KMS key policies, GuardDuty finding handling, VPC traffic control and multi-account guardrails, in 170 minutes with 65 questions. AWS lists Solutions Architect - Associate or Professional as certifications candidates commonly earn first.

How does it compare with the retired SCS-C01 version?

SCS-C02 replaced SCS-C01 and reorganised the blueprint into six domains, adding Threat Detection and Incident Response and Management and Security Governance as named domains. Study material written for SCS-C01 misses services that carry weight in SCS-C02, including Amazon Detective, AWS Audit Manager, AWS Network Firewall and AWS Control Tower. Check that any course or question bank you buy names SCS-C02 explicitly.

Do I need to know how to write code?

No. The exam guide lists software development in a specific language such as Python or Java as out of scope for the target candidate. You do need to read policy documents in JSON fluently, understand what a Lambda function or Step Functions state machine accomplishes in a remediation workflow, and interpret CloudFormation templates, but you are never asked to author application code.

Which AWS services are out of scope?

The exam guide appendix names entire categories as out of scope, including Amazon Managed Blockchain and Amazon QLDB, the AWS Elemental media services and Kinesis Video Streams, Amazon AppStream 2.0, Amazon Braket, AWS RoboMaker, AWS Ground Station, and the migration services AWS DMS, AWS Application Migration Service and AWS Transfer Family. Reading that list before you start saves several study hours.

Can I retake the exam after passing it?

Not for two years. Once you pass, AWS blocks you from retaking the same exam for two years, with one exception: if AWS updates the exam with a new exam guide and a new series code, you become eligible to sit the new version immediately.

Is there a published pass rate?

AWS does not publish pass rates for any of its certification exams, so any figure you see quoted comes from third parties rather than Amazon. What AWS does publish is the standard-setting method: a modified Angoff panel establishes the raw passing standard on the initial form, and statistical equating adjusts it on subsequent forms so that difficulty differences between forms do not change the bar.

How long should I study for SCS-C02?

AWS gives no official study-hour figure. The exam guide's recommendation of two or more years of hands-on AWS security experience is the meaningful signal; candidates who already run AWS security in production typically need a shorter revision cycle focused on the domains they do not touch daily, while those coming from on-premises security need to build lab time for KMS, GuardDuty, Security Hub and AWS Organizations before any question practice becomes useful.

50% OFF

Pass AWS Security Specialty, Guaranteed

94% pass rate on first attempt

500+ Real QuestionsUpdated weekly
Video Walkthroughs20+ hours
Pass or Full RefundGuaranteed
Lifetime AccessFree updates
SAVE $75
$75
$15050% OFF

One-time • Lifetime access

Secure Instant
4.9/5 (2,847 reviews)
30-Day Guarantee, Pass or get 100% refund