How Long to Study for AWS Security Specialty
A complete week-by-week study plan for the AWS Security Specialty (Hard difficulty, ~45% pass rate).
10
Weeks
10
Hrs/Week
95
Total Hours
~45%
Pass Rate
8-10 hours this week
- Download the SCS-C02 exam guide from the AWS Certified Security - Specialty page and copy the six domain weightings into a tracking sheet
- Take the free AWS Certification Official Practice Question Set for SCS-C02 on AWS Skill Builder to establish a baseline
- Read the AWS documentation page on IAM policy evaluation logic end to end, including the deny, organizations SCP, resource policy and permissions boundary ordering
- Build a two-account AWS Organizations sandbox and write a cross-account role with an external ID
- Work through ten questions in the IAM policy simulator against policies you wrote yourself
8-10 hours this week
- Configure AWS IAM Identity Center with an external identity provider and assign permission sets
- Set up an Amazon Cognito user pool and identity pool and trace the token exchange with AWS STS
- Write and test attribute-based access control policies using aws:PrincipalTag and resource tags
- Practise deliberately breaking a policy, then diagnosing it with CloudTrail and IAM Access Advisor
- Review the AWS Skill Builder Exam Prep Plan module covering domain 4
9-11 hours this week
- Read the AWS Key Management Service Developer Guide sections on key policies, grants and key rotation
- Create a customer managed key and deny access to it from an IAM administrator using only the key policy
- Import key material into KMS and observe expiry behaviour, then test cross-account key usage
- Enable S3 Object Lock in governance and compliance modes on separate buckets and try to delete objects
- Configure Secrets Manager rotation for an RDS credential using the provided Lambda rotation function
8-10 hours this week
- Issue an ACM certificate and attach it to an Application Load Balancer and a CloudFront distribution
- Write an S3 bucket policy that denies requests where aws:SecureTransport is false and test it
- Configure Systems Manager Session Manager with session logging to S3 and CloudWatch Logs
- Build a site-to-site VPN to a simulated on-premises endpoint and review the IPsec parameters
- Review the AWS Well-Architected Framework Security Pillar whitepaper sections on data protection
9-11 hours this week
- Deploy AWS WAF in front of CloudFront with a rate-based rule and a geographic match rule, then generate traffic to trigger them
- Compare AWS Shield Standard and Shield Advanced features in the AWS Shield documentation
- Build a VPC with public and private subnets, then replace a NAT route with VPC endpoints for S3 and DynamoDB
- Deploy AWS Network Firewall with a stateful rule group and compare its behaviour with a network ACL
- Practise reading VPC Flow Log records field by field until you can identify a rejected flow at a glance
8-10 hours this week
- Build a hardened AMI with EC2 Image Builder including a CIS-style hardening component
- Enable Amazon Inspector for EC2 and Amazon ECR and review the finding severity model
- Patch a fleet of EC2 instances with Systems Manager Patch Manager and a maintenance window
- Attach an instance profile and demonstrate how a workload retrieves credentials from IMDSv2
- Run VPC Reachability Analyzer against a deliberately broken path and interpret the output
8-10 hours this week
- Create a CloudTrail organization trail with data events for a specific S3 bucket and Lambda function
- Break log delivery on purpose by removing the required S3 bucket policy statement, then diagnose the failure
- Write three CloudWatch Logs Insights queries against CloudTrail data, including one for failed console logins
- Query CloudTrail logs in Athena using the AWS-provided table definition
- Create a CloudWatch metric filter and alarm for root account usage and confirm it fires
9-11 hours this week
- Enable GuardDuty across the organization and generate sample findings, then review each finding type
- Enable Amazon Detective and follow a finding through to a behaviour graph
- Read the AWS Security Incident Response Guide whitepaper, focusing on the containment and eradication sections
- Build an EventBridge rule that routes a GuardDuty finding to a Lambda function that isolates an EC2 instance
- Enable Security Hub, turn on the AWS Foundational Security Best Practices standard and review failing controls
8-10 hours this week
- Write service control policies that deny root user actions and restrict regions, then test them on a member account
- Deploy AWS Control Tower in the sandbox organization and review the preventive and detective controls it installs
- Create a custom AWS Config rule backed by Lambda and an AWS Config aggregator across two accounts
- Share a resource across accounts with AWS Resource Access Manager and inspect the resulting permissions
- Run Amazon Macie on a bucket seeded with synthetic PII and review the sensitive data discovery results
10-12 hours this week
- Take the AWS Certification Official Pretest for SCS-C02 on AWS Skill Builder under timed conditions
- Rebuild every question you missed into a one-line rule stating why the correct service was correct
- Review the list of AWS service short names available through the Help button in the exam so the abbreviations do not slow you down
- Re-read the exam guide appendix listing in-scope and out-of-scope services and drop revision on out-of-scope topics
- Sit one more timed set of 65 questions with a strict 170-minute clock to rehearse pacing at 2.6 minutes per question
Duration: 15 weeks
Hours/week: 7 hours
Daily: ~1 hours on weeknights
Weekends: 3-4 hours Saturday + Sunday
Study during lunch breaks and commute time. Use weekends for deeper study sessions and practice tests.
Duration: 20 weeks
Hours/week: 5 hours
Saturday: 4-5 hours of focused study
Sunday: 3-4 hours of practice tests
Longer timeline but sustainable. Review flashcards on weeknights for 15-20 minutes to maintain retention.
How long does it take to study for the AWS Security Specialty?
Plan for 10 weeks of dedicated study at 10 hours per week (95 total hours). If studying while working full-time, extend to 15 weeks.
Can I pass the AWS Security Specialty in 2 weeks?
It's unlikely for most candidates. The AWS Security Specialty is rated "Hard" difficulty and typically requires 10 weeks of preparation. Rushing increases your risk of failing and paying the exam fee again.
How many hours a day should I study for AWS Security Specialty?
Aim for 2-3 hours per day on weekdays. Quality matters more than quantity, use active recall and practice tests rather than passive reading.
Is AWS Security Specialty hard to pass?
The AWS Security Specialty is rated "Hard" difficulty with a pass rate of ~45%. Solid preparation over several months is recommended.
Ready to start your AWS Security Specialty journey?
Get the complete exam guide with tips, resources, and practice questions.
View AWS Security Specialty Guide