Get Even More Visitors To Your Blog, Upgrade To A Business Listing >>

AWS Certified Security Specialty (SCS-C01)

Exam Tips and Tricks

If you’re like me and planning to add to your ever-growing AWS Certifications, even after you completed the 5 major ones then these tips will help. Between the three specialty certifications (Network, Security and Big Data) I decided to pursue the Security Specialty Exam only because working with AWS daily Security has become the number one thing a client talks about. Not to scare anyone from taking the exam but out of all the ones that I’ve taken, this exam was harder than either of the Professional exams.

Before I get started, I advise you to

Get a good night’s sleep

Have a healthy breakfast

Limit your caffeine consumption


Here’s a quick run-down of specific items that I would focus on, please review the following important exam prep.

The Exam is 170 minutes long, so manage your time wisely.

Flag any question you are unsure of and move on.

Typically, there are 1-2 blatantly incorrect answers, one very right answer and two that could work.

I used the extra sheet of paper and put what number question I was on and then A, B, C, D to match the number of answers available. Then I crossed off the ones that were incorrect, circled the correct one and if I still couldn’t figure out the answer, I flagged it.

Sometimes the answer is provided in another
question within the exam

Key Areas To Put Your Focus On

  • KMS – Focus on all the different KMS options
    1. API commands (Encrypt, Decrypt, Recrypt)
    2. CMK – AWS created vs Imported
    3. How to enforce annual rotation of keys
  • AWS Config
    1. The type of rules that can be setup and how to automatically remediate non-compliant rules utilizing lambda
  • Know the difference between Cloudtrail vs Cloudwatch
  • SSL communication from on-premise to ec2 including how legacy applications communicate when changing from an ELB to ALB
  • S3 access
    1. I didn’t have any questions on Bucket ACL’s but know the difference between an ACL and Policy
  • Cross-Account Access (S3)
  • How to regain access to an EC2 or change the key pair if they’ve been compromised
  • How does AWS WAF and Shield work
  • When and why should you implement a proxy server
  • Network Access Control List (Stateless) vs Security Groups (SG’s are stateful)
  • How AWS Organizations work including
    1. Service Control Policies and enforcements
  • Cloudfront OAI communicate to S3
    1. Think static website or content
  • AWS Athena and viewing VPC flow logs
    1. Query the VPC flow logs
  • VPC flow logs – How can you automate or make sure VPC flow logs are enabled (Hint: AWS Config & Lambda)
  • Troubleshooting
    1. Why some instances are writing logs to Cloudwatch and others aren’t or they stopped after a period of time

Items that I didn’t find on my exam but that doesn’t mean you shouldn’t know about them.

  • CloudHSM
  • AWS Trusted Advisor

Training Materials I used:

  • ACloudGuru
  • LinuxAcademy – I actually worked for them for a brief period of time and enjoy putting together some training courses. The instructor for the Security Specialty Course is really good.

Whitepapers:

  • AWS Key Management Service Best Practices – https://d1.awsstatic.com/whitepapers/aws-kms-best-practices.pdf
  • Exam Guide – https://d1.awsstatic.com/training-and-certification/eligibilityupdates/AWS%20Certified%20Security%20Specialty_Exam%20Guide_v1.6_FINAL.pdf

Here’s the Current Content or Exam Layout

Domain 1: Incident Response

1.1 Given an AWS abuse notice, evaluate the suspected compromised instance or exposed access keys.
1.2 Verify that the Incident Response plan includes relevant AWS services.
1.3 Evaluate the configuration of automated alerting, and execute possible remediation of security-related incidents and emerging issues.

Domain 2: Logging and Monitoring

2.1 Design and implement security monitoring and alerting.
2.2 Troubleshoot security monitoring and alerting.
2.3 Design and implement a logging solution.
2.4 Troubleshoot logging solutions.

Domain 3: Infrastructure Security

3.1 Design edge security on AWS.
3.2 Design and implement a secure network infrastructure.
3.3 Troubleshoot a secure network infrastructure.
3.4 Design and implement host-based security.

Domain 4: Identity and Access Management

4.1 Design and implement a scalable authorization and authentication system to access AWS resources.
4.2 troubleshoot an authorization and authentication system to access AWS resources.

Domain 5: Data Protection

5.1 Design and implement key management and use.
5.2 Troubleshoot key management.
5.3 Design and implement a data encryption solution for data at rest and data in transit.

My final piece of advice for those taking the exam is to stay positive. It can do wonders.

About Author

Jon Myer
Sr. Cloud Solutions Architect, NetEnrich

Jon has more than fifteen years of experience working in IT. He started working with AWS 8 years ago and holds five certifications – SysOps, CSA Associate & Pro, DevOps Associate and Pro.

The post Aws Certified Security Specialty (SCS-C01) appeared first on NetEnrich.

Share the post

AWS Certified Security Specialty (SCS-C01)

×

Subscribe to Netenrich Blog - Managed Service Providers | It Operations | Cloud | Security Services | Datacenter

Get updates delivered right to your inbox!

Thank you for your subscription

×