Cert Notes/ Commute Study Notes
Roadmap
KOEN
CLF-C02 · FoundationalCloud Practitioner - Foundational
DVA-C02 · AssociateDeveloper - Associate
SAA-C03 · AssociateSolutions Architect - Associate
SOA-C02 · AssociateCloudOps Engineer - Associate
SAP-C02 · ProfessionalSolutions Architect - Professional
DOP-C02 · ProfessionalDevOps Engineer - Professional
SCS-C03 · SpecialtySecurity - Specialty
  • Week 1
    • 1.Shared Responsibility Model and SCS-C03's 6 Domains: The Big Picture for Security Engineers
    • 2.IAM Core: Users, Groups, Roles, Policies, and Policy Evaluation Flow
    • 3.Advanced IAM Policies: Identity vs Resource, Condition Keys, and Least-Privilege Design
    • 4.STS and Temporary Credentials: AssumeRole, Federation, Role Chaining, Confused Deputy Prevention
    • 5.Week 1 Synthesis: Integrating IAM and Credentials Through Scenarios
  • Week 2
    • 1.Master IAM Policy Evaluation Logic: Explicit Deny Beats Everything
    • 2.Permission Boundary and Delegation: The Safe Way to Grant Permissions to Developers
    • 3.AWS Organizations and SCP: Account-Level Guardrail Design
    • 4.Day 4
    • 5.Day 5
  • Week 3
    • 1.Enable VPC Flow Logs (detailed in Day 3)
    • 2.Scenario: Web server (443) receiving Internet connection
    • 3.1. CloudWatch Logs — suits real-time alarms (Metric Filter)
    • 4.Gateway Endpoint (S3) — add route to table, free
    • 5.Day 5
  • Week 4
    • 1.Day 1
    • 2.AWS Shield (Standard/Advanced) and DDoS Protection: Layered Defense, CloudFront/Route 53 Integration
    • 3.AWS Network Firewall and DNS Firewall: Stateful Inspection, Domain Filtering, Centralized Inspection VPC
    • 4.Edge Security Integration: CloudFront (OAC, Signed URLs), ACM Certificates, Perimeter Security Architecture
    • 5.Week 4 Synthesis: Integrated Review of Edge and Perimeter Defense Scenarios
  • Week 5
    • 1.AWS KMS Fundamentals: CMK Types, Key Policy vs IAM, Symmetric/Asymmetric Keys
    • 2.Envelope Encryption and Data Keys: GenerateDataKey, Encryption Context
    • 3.Key Policies, Grants, and Cross-Account Sharing: ViaService Condition and Key Governance
    • 4.Encryption at Rest/in Transit: TLS, Service-Specific Encryption, Key Rotation
    • 5.Week 5 Synthesis: Integrated Review of Encryption and Key Management Scenarios
  • Week 6
    • 1.Secrets Manager: Automatic Rotation (Lambda), Parameter Store Comparison, Cross-Account Secrets
    • 2.S3 Data Protection: SSE-S3/SSE-KMS/DSSE, Bucket Keys, Object Lock, Versioning, Block Public Access
    • 3.S3 Access Control Deep Dive: Bucket Policies, ACLs, Access Points, Encryption Enforcement, Exfiltration Prevention
    • 4.ACM and Macie: Certificate Lifecycle and Integration, Macie Sensitive Data (PII) Detection and Classification
    • 5.Week 6 Integration: Secrets, Storage, and Sensitive Data Scenario Review
  • Week 7
    • 1.CloudTrail: Management/Data Events, Organization Trail, Log File Integrity Validation, CloudTrail Lake
    • 2.AWS Config: Configuration Items and Records, Rules (Managed/Custom Lambda), Conformance Pack, Auto-Remediation
    • 3.VPC Flow Logs and Network Logging: Detecting Breaches/Misconfig via Traffic, Route 53 Resolver Query Logs
    • 4.Log Integrity, Retention, and Centralization: S3 Object Lock, Cross-Account Log Aggregation, KMS Encryption of Logs
    • 5.Week 7 Integration: Audit Trail Scenario Review
  • Week 8
    • 1.CloudWatch: Log Groups, Metric Filters, Alarms, Anomaly Detection, Security Event Notifications
    • 2.Security Hub: Security Standards (CIS/FSBP), Consolidated Score, Finding Aggregation and Normalization (ASFF), Automated Response
    • 3.Log Analysis: Query CloudTrail/VPC Flow with Athena, OpenSearch, CloudWatch Logs Insights
    • 4.EventBridge Security Automation: Finding Routing, Alert Pipelines, Security Data Lake Concept
    • 5.Week 8 Integration: Monitoring, Aggregation, Analysis Scenario Comprehensive Review
  • Week 9
    • 1.Amazon GuardDuty: Threat Detection Principles, Finding Types, Threat Intelligence, Multi-Account Delegated Administrator
    • 2.Amazon Detective: Finding Investigation and Root Cause, Behavior Graph, GuardDuty Integration
    • 3.Amazon Inspector: EC2/ECR/Lambda Vulnerability Scanning, CVE, Automated Assessment
    • 4.Detection Integration: GuardDuty + Security Hub + Detective + Inspector One Picture, Multi-Account Detection Baseline
    • 5.Week 9 Synthesis: Integrated Review of Threat Detection Scenarios
  • Week 10
    • 1.Automated Response Pipeline: EventBridge + SSM Automation + Lambda for Auto-Remediation of Findings
    • 2.Incident Response for Compromised EC2: Isolation, Snapshots, Forensics, Credential Revocation
    • 3.Credential Exposure Response: Access Key Exposure, Root Compromise, IAM Neutralization and Rotation Playbook
    • 4.Incident Response Framework: NIST Phases, Runbooks, Automation vs Human Judgment Boundary
    • 5.Week 10 Synthesis: Integrated Incident Response Scenario Review
  • Week 11
    • 1.AWS Organizations Security Governance: SCP Design, Delegated Administrators, Central Security Account Model
    • 2.Control Tower and Landing Zone: Guardrails (Preventive/Detective), Account Factory, Compliance Baseline
    • 3.Audit Manager and Compliance: Automated Evidence Collection, Frameworks (CIS/PCI), Config Integration
    • 4.Multi-Account Security Operations: Firewall Manager, Central Policy Distribution, Cost/Tag Governance, Security Baseline Automation
    • 5.Week 11 Comprehensive Review: Integrated Governance Scenarios
  • Week 12
    • 1.Integrated Review Domains 1 & 2: Threat Detection and Incident Response ↔ Security Logging and Monitoring
    • 2.Integrated Review Domains 3 & 4: Infrastructure Security ↔ Identity and Access Management
    • 3.Integrated Review Domains 5 & 6: Data Protection ↔ Management and Governance
    • 4.Full Practice Exam Pace: Six-Domain Synthesis Scenario Review
    • 5.D-Day Final: Exam Strategy, Keyword Translation, Trap Summary
MLA-C01 · AssociateMachine Learning Engineer - Associate
AIF-C01 · FoundationalAI Practitioner - Foundational
DEA-C01 · AssociateData Engineer - Associate
MLS-C01 · SpecialtyMachine Learning - Specialty
← All certifications/SCS-C03

Security - Specialty

12 weeks · 60 days · Specialty

Week 1 is available in English as a free preview. The full course is currently Korean-only — view the Korean track.

Start with Week 1

Read SCS-C03 pass reviews →

Exam Information

전문 · 해당 도메인 실무 경험 권장
Questions
65
Duration
170min
Passing
750 / 1000
Cost
$300
Validity
3y

Domain Weights

위협 탐지 및 인시던트 대응14%
보안 로깅 및 모니터링18%
인프라 보안20%
자격 증명 및 액세스 관리16%
데이터 보호18%
관리 및 보안 거버넌스14%
Format객관식·복수응답
Prerequisites없음(권장: IT 보안 5년 + AWS 워크로드 보안 2년 경험)
Languages영어, 한국어, 일본어, 포르투갈어(브라질), 중국어 간체, 스페인어(중남미)

Benefits & Tips

  • 합격하면 다음 시험 50% 할인 바우처가 생깁니다. AWS Certification 계정의 "Benefits"에서 확인하고 재인증·다른 자격증 응시에 쓸 수 있어요(만료일이 있으니 그 전에 사용).
  • 인증은 3년간 유효하며 만료 전 재인증이 필요합니다. 재인증 때도 이 50% 바우처를 쓸 수 있어요.
  • 무료 재응시는 없습니다(매 응시 전액 결제). 첫 시도에 붙는 게 가장 저렴하니, 모의고사로 합격선을 넘긴 뒤 응시하세요.
  • 합격하면 Credly 디지털 배지가 발급돼 링크드인·이메일 서명에 붙일 수 있습니다.

FAQ

SCS-C03 시험은 몇 문항이고 시험 시간은 얼마나 되나요?+

SCS-C03은 총 65문항이며, 시험 시간은 170분입니다. 문항은 객관식과 복수응답형으로 출제됩니다.

합격 점수는 몇 점인가요?+

1000점 만점에 750점 이상이면 합격입니다. 점수는 문항 난이도를 보정한 스케일 점수라 단순 정답률과는 다릅니다.

응시료는 얼마이고 어떻게 접수하나요?+

응시료는 미화 $300이며, Pearson VUE를 통해 시험 센터 또는 온라인 감독(프록터드) 시험으로 응시할 수 있습니다. 무료 재응시는 없어 매 응시마다 전액을 결제합니다.

자격증은 얼마나 유효한가요? 재인증은 어떻게 하나요?+

합격 후 3년간 유효하며, 만료 전 재인증이 필요합니다. 합격 시 다음 시험 50% 할인 바우처가 제공되어 재인증이나 다른 AWS 자격증 응시에 사용할 수 있습니다.

한국어로 응시할 수 있나요?+

네, 한국어를 포함해 총 6개 언어로 제공됩니다. 시험 등록 시 언어를 선택할 수 있습니다.

Official Exam Guide Register for Exam

Week 1

  • Day 1Shared Responsibility Model and SCS-C03's 6 Domains: The Big Picture for Security Engineers
  • Day 2IAM Core: Users, Groups, Roles, Policies, and Policy Evaluation Flow
  • Day 3Advanced IAM Policies: Identity vs Resource, Condition Keys, and Least-Privilege Design
  • Day 4STS and Temporary Credentials: AssumeRole, Federation, Role Chaining, Confused Deputy Prevention
  • Day 5Week 1 Synthesis: Integrating IAM and Credentials Through Scenarios

Week 2

  • Day 1Master IAM Policy Evaluation Logic: Explicit Deny Beats Everything
  • Day 2Permission Boundary and Delegation: The Safe Way to Grant Permissions to Developers
  • Day 3AWS Organizations and SCP: Account-Level Guardrail Design
  • Day 4Day 4
  • Day 5Day 5

Week 3

  • Day 1Enable VPC Flow Logs (detailed in Day 3)
  • Day 2Scenario: Web server (443) receiving Internet connection
  • Day 31. CloudWatch Logs — suits real-time alarms (Metric Filter)
  • Day 4Gateway Endpoint (S3) — add route to table, free
  • Day 5Day 5

Week 4

  • Day 1Day 1
  • Day 2AWS Shield (Standard/Advanced) and DDoS Protection: Layered Defense, CloudFront/Route 53 Integration
  • Day 3AWS Network Firewall and DNS Firewall: Stateful Inspection, Domain Filtering, Centralized Inspection VPC
  • Day 4Edge Security Integration: CloudFront (OAC, Signed URLs), ACM Certificates, Perimeter Security Architecture
  • Day 5Week 4 Synthesis: Integrated Review of Edge and Perimeter Defense Scenarios

Week 5

  • Day 1AWS KMS Fundamentals: CMK Types, Key Policy vs IAM, Symmetric/Asymmetric Keys
  • Day 2Envelope Encryption and Data Keys: GenerateDataKey, Encryption Context
  • Day 3Key Policies, Grants, and Cross-Account Sharing: ViaService Condition and Key Governance
  • Day 4Encryption at Rest/in Transit: TLS, Service-Specific Encryption, Key Rotation
  • Day 5Week 5 Synthesis: Integrated Review of Encryption and Key Management Scenarios

Week 6

  • Day 1Secrets Manager: Automatic Rotation (Lambda), Parameter Store Comparison, Cross-Account Secrets
  • Day 2S3 Data Protection: SSE-S3/SSE-KMS/DSSE, Bucket Keys, Object Lock, Versioning, Block Public Access
  • Day 3S3 Access Control Deep Dive: Bucket Policies, ACLs, Access Points, Encryption Enforcement, Exfiltration Prevention
  • Day 4ACM and Macie: Certificate Lifecycle and Integration, Macie Sensitive Data (PII) Detection and Classification
  • Day 5Week 6 Integration: Secrets, Storage, and Sensitive Data Scenario Review

Week 7

  • Day 1CloudTrail: Management/Data Events, Organization Trail, Log File Integrity Validation, CloudTrail Lake
  • Day 2AWS Config: Configuration Items and Records, Rules (Managed/Custom Lambda), Conformance Pack, Auto-Remediation
  • Day 3VPC Flow Logs and Network Logging: Detecting Breaches/Misconfig via Traffic, Route 53 Resolver Query Logs
  • Day 4Log Integrity, Retention, and Centralization: S3 Object Lock, Cross-Account Log Aggregation, KMS Encryption of Logs
  • Day 5Week 7 Integration: Audit Trail Scenario Review

Week 8

  • Day 1CloudWatch: Log Groups, Metric Filters, Alarms, Anomaly Detection, Security Event Notifications
  • Day 2Security Hub: Security Standards (CIS/FSBP), Consolidated Score, Finding Aggregation and Normalization (ASFF), Automated Response
  • Day 3Log Analysis: Query CloudTrail/VPC Flow with Athena, OpenSearch, CloudWatch Logs Insights
  • Day 4EventBridge Security Automation: Finding Routing, Alert Pipelines, Security Data Lake Concept
  • Day 5Week 8 Integration: Monitoring, Aggregation, Analysis Scenario Comprehensive Review

Week 9

  • Day 1Amazon GuardDuty: Threat Detection Principles, Finding Types, Threat Intelligence, Multi-Account Delegated Administrator
  • Day 2Amazon Detective: Finding Investigation and Root Cause, Behavior Graph, GuardDuty Integration
  • Day 3Amazon Inspector: EC2/ECR/Lambda Vulnerability Scanning, CVE, Automated Assessment
  • Day 4Detection Integration: GuardDuty + Security Hub + Detective + Inspector One Picture, Multi-Account Detection Baseline
  • Day 5Week 9 Synthesis: Integrated Review of Threat Detection Scenarios

Week 10

  • Day 1Automated Response Pipeline: EventBridge + SSM Automation + Lambda for Auto-Remediation of Findings
  • Day 2Incident Response for Compromised EC2: Isolation, Snapshots, Forensics, Credential Revocation
  • Day 3Credential Exposure Response: Access Key Exposure, Root Compromise, IAM Neutralization and Rotation Playbook
  • Day 4Incident Response Framework: NIST Phases, Runbooks, Automation vs Human Judgment Boundary
  • Day 5Week 10 Synthesis: Integrated Incident Response Scenario Review

Week 11

  • Day 1AWS Organizations Security Governance: SCP Design, Delegated Administrators, Central Security Account Model
  • Day 2Control Tower and Landing Zone: Guardrails (Preventive/Detective), Account Factory, Compliance Baseline
  • Day 3Audit Manager and Compliance: Automated Evidence Collection, Frameworks (CIS/PCI), Config Integration
  • Day 4Multi-Account Security Operations: Firewall Manager, Central Policy Distribution, Cost/Tag Governance, Security Baseline Automation
  • Day 5Week 11 Comprehensive Review: Integrated Governance Scenarios

Week 12

  • Day 1Integrated Review Domains 1 & 2: Threat Detection and Incident Response ↔ Security Logging and Monitoring
  • Day 2Integrated Review Domains 3 & 4: Infrastructure Security ↔ Identity and Access Management
  • Day 3Integrated Review Domains 5 & 6: Data Protection ↔ Management and Governance
  • Day 4Full Practice Exam Pace: Six-Domain Synthesis Scenario Review
  • Day 5D-Day Final: Exam Strategy, Keyword Translation, Trap Summary