CloudPath Academy

Your guide to AWS certification success

Amazon Web Services AWS Broken Labs

AWS Certified Security - Specialty (SCS-C03) Domain 2

Incident Response

Official Exam Guide: Domain 2: Incident Response

Skill Builder: AWS Certified Security - Specialty Exam Prep


Domain Overview

Domain 2 (14%) focuses on designing and testing incident response plans, and responding to security events.


Task 2.1: Design and test an incident response plan

Key Skills:

Essential Documentation:


Task 2.2: Respond to security events

Key Skills:

Essential Documentation:


AWS Service FAQs


Study Tips

  1. Master incident response workflow - Prepare → Detect → Analyze → Contain → Eradicate → Recover → Post-incident analysis.

  2. Learn forensics preservation - EBS snapshots for forensic analysis, memory dumps, isolate compromised instances, preserve logs.

  3. Understand automated remediation - Systems Manager Automation, Step Functions for orchestration, Lambda for custom actions, EventBridge triggers.

  4. Practice with Detective - Visualize security findings, investigate GuardDuty findings, analyze VPC Flow Logs, trace relationships.

  5. Study DDoS response - Shield Advanced protections, AWS DDoS Response Team (DRT) engagement, WAF rate limiting, CloudFront distributions.


Note: This is Domain 2 of 6, representing 14% of exam content.