CloudPath Academy

Your guide to AWS certification success

Amazon Web Services AWS Broken Labs

AWS Certified Security - Specialty (SCS-C03) Domain 6

Security Foundations and Governance

Official Exam Guide: Domain 6: Security Foundations and Governance

Skill Builder: AWS Certified Security - Specialty Exam Prep


Domain Overview

Domain 6 (14%) focuses on centralized account management, secure deployment strategies, and compliance evaluation.


Task 6.1: Develop strategy for centralized account deployment and management

Key Skills:

Essential Documentation:


Task 6.2: Implement secure and consistent deployment strategy

Key Skills:

Essential Documentation:


Task 6.3: Evaluate compliance of AWS resources

Key Skills:

Essential Documentation:


AWS Service FAQs


Study Tips

  1. Master multi-account strategy - Organizations OUs, SCPs for guardrails, delegated administrators, consolidated billing, RCPs for resources.

  2. Learn Control Tower - Landing zones, Account Factory, guardrails (preventive/detective), baseline controls, customizations.

  3. Understand compliance automation - Config rules and conformance packs, Security Hub standards (CIS, PCI-DSS, NIST), Audit Manager frameworks.

  4. Practice IaC security - CloudFormation Guard for policy-as-code, StackSets for multi-account deployment, cfn-lint for validation.

  5. Study centralized security - Security Hub as aggregator, GuardDuty delegated administrator, Firewall Manager for WAF/Shield policies.


Complete Exam Summary

Exam Format:

Domain Weightings:

Target Candidate:

Key AWS Security Services:

Key Security Concepts:

Study Resources:

Good luck with your AWS Certified Security - Specialty certification!


Note: This is Domain 6 of 6, representing 14% of exam content.