CloudPath Academy

Your guide to AWS certification success

Amazon Web Services AWS Broken Labs

AWS Certified Security - Specialty (SCS-C03) Domain 1

Detection

Official Exam Guide: Domain 1: Detection

Skill Builder: AWS Certified Security - Specialty Exam Prep


Domain Overview

Domain 1 (16%) focuses on designing and implementing monitoring/alerting solutions, logging solutions, and troubleshooting security monitoring.


Task 1.1: Design and implement monitoring and alerting solutions

Key Skills:

Essential Documentation:


Task 1.2: Design and implement logging solutions

Key Skills:

Essential Documentation:


Task 1.3: Troubleshoot security monitoring, logging, and alerting

Key Skills:

Essential Documentation:


AWS Service FAQs


Study Tips

  1. Master threat detection services - GuardDuty for threats, Macie for sensitive data, Security Hub for centralized findings, Inspector for vulnerabilities.

  2. Learn log aggregation - Security Lake for OCSF format, CloudWatch Logs for centralization, Athena for querying S3 logs, OpenSearch for analysis.

  3. Understand CloudTrail thoroughly - Organization trails, event selectors, data events, management events, S3 data events, Lambda data events.

  4. Practice monitoring design - Which logs to enable (VPC Flow Logs, CloudTrail, ALB logs, CloudFront logs), retention policies, cost optimization.

  5. Study Config rules - Conformance packs, auto-remediation, aggregators for multi-account, custom rules with Lambda.


Note: This is Domain 1 of 6, representing 16% of exam content.