SCP, permissions boundary, or KMS key policy? Each looks like it could deny the request, but only one meets the requirement.
This app covers all six domains of AWS Certified Security - Specialty (SCS-C03), weighted like the real exam, five questions at a time.
SCS-C03 tests whether you can protect AWS workloads and an entire organization. Many candidates say they could narrow a question down to two options but not decide, and that the real exam was harder than the practice questions. IAM policy evaluation logic, condition keys such as aws:SourceVpce, how GuardDuty, Detective and Security Hub differ, the steps to isolate a compromised EC2 instance: knowing service names is not enough. The fine details decide the result.
■ Six domains, weighted like the real exam
- Detection (16%)
- Incident Response (14%)
- Infrastructure Security (18%)
- Identity and Access Management (20%)
- Data Protection (18%)
- Security Foundations and Governance (14%)
Start with Identity and Access Management, now the largest domain. Your progress by domain maps onto the real exam, so your gaps show up as numbers.
■ What you get
[Built by a developer who holds all 12 AWS certifications]
Every question, option and explanation was written by a developer with all 12 AWS certifications, focused on where candidates stumble.
[Learn why the other options are wrong]
The most common complaints about practice tests are shallow explanations and wrong answer keys. All 300 questions explain why the answer is right and why the tempting wrong options are wrong, with details checked against the official AWS documentation. SCPs do not apply to the management account; suppression rules archive findings instead of stopping them. You learn to tell similar options apart.
[Least privilege, LEAST overhead, FASTEST containment]
SCS asks for the most secure, lowest-effort or fastest way to meet a requirement. The wrong answers here work too, but grant too much access or leave manual work in every account, so you practice the same doubts you will face on exam day.
[Covers the new SCS-C03 scope]
Checked by script against the official guide for SCS-C03, launched in December 2025. Includes Amazon Bedrock Guardrails and OWASP Top 10 for LLM, log integration with OCSF, node-to-node encryption, imported key material, log masking, multi-Region keys, AWS Private CA, RCPs and declarative policies: topics missing from SCS-C02 material.
[Get used to ordering questions]
SCS-C03 asks you to put steps in order. Practice with questions such as "What is the correct order for incident response?"
[No outdated knowledge]
Retired and closed services (Inspector Classic, CodeGuru Security, WAF Classic and more) and old names are left out. Learn current behavior, such as Security Hub CSPM versus the new Security Hub, and S3 SSE-C now disabled by default.
[Made for spare minutes]
Five questions per set: one commute is enough. Each correct answer is recorded once, whether in domain practice or Random Practice, which draws 5 to 10 questions from all six domains in exam proportions.
[Offline, 10 languages, no sign-up]
All questions are in the app, so it works in airplane mode. Questions, options and explanations in English, Japanese, Korean, Chinese, German and more. No account, no login, no subscription.
■ Who it is for
- Candidates for AWS Certified Security - Specialty (SCS-C03)
- Anyone who studied with SCS-C02 material and needs the new C03 topics
- SAA or SOA holders aiming for the security specialty next
- Security engineers with gaps outside their own services
■ Please note
This is an unofficial study app. AWS and Amazon Web Services are trademarks of Amazon.com, Inc. or its affiliates. Always check the official AWS website for the latest exam information and exam scope.
SCS-C03 security specialty prep: 300 questions, every wrong option explained.