✓ Live now — AWS 5 hands-on projects

SCS-C03 Hands-On Labs
Real AWS Security. Real GitHub portfolio.

Five real AWS Security Specialty projects mapped directly to the SCS-C03 exam objectives. Mark a step complete and HandsOnCert commits the evidence — IAM policies, GuardDuty findings, incident response runbooks — straight to your own GitHub repo. The portfolio employers actually click into.

$79 one-time · Project 1 free · No subscription

5
Hands-on projects
12h
Estimated time
$300
SCS-C03 exam cost
$79
HandsOnCert price

What you'll build

Every project maps to an official SCS-C03 exam domain. Each one ends with evidence committed to your GitHub repo automatically.

1

Threat Detection and Incident Response — Free

Enable GuardDuty and Security Hub, generate a sample finding, and create an EventBridge rule that triggers a Lambda function to automatically respond (e.g., isolate an instance). Commit your detection configuration and automated response code.

Threat Detection & Incident Response — 14% of exam
2

Security Logging and Monitoring

Configure CloudTrail with a multi-region trail and log file validation, set up VPC Flow Logs, and create a CloudWatch Logs Insights query to detect a specific pattern (e.g., failed login attempts). Commit your trail configuration and query results.

Security Logging & Monitoring — 18% of exam
3

Infrastructure Security

Configure security groups and NACLs following least-privilege, set up AWS WAF with a rate-limiting rule on a CloudFront distribution, and configure AWS Network Firewall for VPC traffic inspection. Commit your security group rules and WAF configuration.

Infrastructure Security — 20% of exam
4

Identity and Access Management

Create a permissions boundary for an IAM role, configure an SCP at the Organizations level, and set up cross-account access using IAM roles with external ID. Commit your permissions boundary policy and cross-account role configuration.

Identity & Access Management — 16% of exam
5

Data Protection

Create a KMS customer-managed key with a key policy, enable encryption at rest for S3 and RDS using the key, and configure automatic key rotation. Commit your KMS key policy and encryption configuration evidence.

Data Protection — 18% of exam

Why HandsOnCert

🗂️

Real GitHub portfolio

Every completed step auto-commits evidence to your own repo. No fake portfolio templates — real configs, real screenshots, real history.

☁️

Real AWS resources

No simulators. You work in the actual AWS console and tools, the same ones you'll use on the job and in the SCS-C03 exam.

🤖

Cert Buddy AI mentor

Stuck on a step or an exam concept? Cert Buddy is trained on SCS-C03 objectives and helps you debug and understand — not just copy-paste.

💰

Cost alerts built in

Every chargeable resource has a clear alert telling you exactly when to stop, deallocate, or delete — so a lab break doesn't become a surprise bill.

📄

Downloadable lab guide

Get the full SCS-C03 lab guide as a PDF — step-by-step instructions, screenshots to capture, and an exam quick-reference section.

💵

One-time price

$79 once. No subscription, no recurring charges. Or get All-Access to all 21 cert paths for $199.

Frequently Asked Questions

Are the SCS-C03 hands-on labs free?

Project 1 (Threat Detection) is completely free, including unlimited access to Cert Buddy for that project and the manual GitHub commit workflow. The remaining 4 projects unlock for a one-time payment of $79.

Do I need an AWS account for SCS-C03 labs?

Yes, and several services (GuardDuty, Security Hub, KMS) have costs beyond free tier if left running. Each project includes a cost alert with exact commands to disable or delete these services after use.

How does the GitHub portfolio auto-commit work for SCS-C03?

When you mark a lab step complete, HandsOnCert commits your IAM policies, KMS key configurations, and security findings directly to your own GitHub repository via OAuth — demonstrating real security configuration work.

How long does the SCS-C03 path take to complete?

The 5 projects take approximately 12 hours total, covering threat detection/incident response, security logging/monitoring, infrastructure security, IAM, and data protection — the same domains tested on the SCS-C03 exam.

Do I need other AWS certifications before SCS-C03?

AWS recommends a foundational AWS certification (CLF-C02 or an associate-level cert) plus security work experience before SCS-C03. SCS-C03 is a specialty certification that builds on broad AWS knowledge with a security-specific deep dive.

How does SCS-C03 compare to Azure SC-500 or GCP-PCSE?

SCS-C03 (AWS Security Specialty), SC-500 (Microsoft Cloud and AI Security Engineer), and GCP-PCSE (Professional Cloud Security Engineer) are each platform-specific security certifications covering similar concepts — IAM, encryption, threat detection, incident response — applied to their respective clouds.

Build your SCS-C03 portfolio today

Start Project 1 free — no credit card required. See exactly how the GitHub auto-commit works before you pay anything.

Start Free →