CloudPath Academy

Your guide to AWS certification success

Amazon Web Services AWS Broken Labs

AWS Certified Security - Specialty (SCS-C03) Domain 4

Identity and Access Management

Official Exam Guide: Domain 4: Identity and Access Management

Skill Builder: AWS Certified Security - Specialty Exam Prep


Domain Overview

Domain 4 (20% - largest domain) focuses on authentication strategies and authorization strategies.


Task 4.1: Design and implement authentication strategies

Key Skills:

Essential Documentation:


Task 4.2: Design and implement authorization strategies

Key Skills:

Essential Documentation:


AWS Service FAQs


Study Tips

  1. Master IAM policy structure - Principal, Action, Resource, Effect, Condition elements. Identity-based vs resource-based policies.

  2. Learn ABAC implementation - Tag-based access control, principal tags, resource tags, request condition tags, session tags.

  3. Understand permission boundaries - Maximum permissions for IAM entities, prevent privilege escalation, delegate administration safely.

  4. Practice with Access Analyzer - Identify resources shared with external entities, validate policies, generate policies from CloudTrail logs.

  5. Study federation patterns - SAML 2.0 federation, OIDC providers, IAM Identity Center (SSO), Cognito user pools and identity pools.


Note: This is Domain 4 of 6, representing 20% (largest domain) of exam content.