What This Guide Actually Covers
Aws Security Study Guide is something I keep pulling together for people who need to pass the AWS Security Specialty exam without going through six months of fluff. The exam is heavily focused on real scenarios, not definitions. I wrote this because I watched too many people memorize bullet points and still fail when they get to the scenario questions. Most free guides online cover IAM, KMS, CloudTrail, and GuardDuty. That's the surface. Here's what actually matters for the exam and for doing the job. Not just creating users. They test conditional policies, SCPs, IAM Roles Anywhere, and cross-account trust relationships. The trick is that most people learn IAM through the console. You can't. The exam gives you JSON policy documents and asks what's wrong with them.
I remember spending three weeks on a single question about IAM Access Analyzer findings. The scenario involved a resource sharing configuration that looked fine on the surface but had a misconfigured resource policy allowing a neighboring account to assume a role it shouldn't have access to. The answer wasn't "disable cross-account access." It was "add a PrincipalOrgID condition to the role trust policy." I looked it up in the docs and basically memorized every condition key under iam:PrincipalOrgID.
Key things to actually know about IAM
Policy evaluation logic: explicit deny always wins. That means even if a user has permission through a group, an SCP, and an organizational policy, a single explicit deny anywhere in the chain blocks them. Most people forget this until they're reading a question that has two conflicting permissions and wonder why the answer is "denied." Permissions boundaries are separate from policies. They act as an upper limit, like a cage around what the policy can allow. You can attach a permissions boundary that is more restrictive than the attached policies, and it will override them. This shows up in the exam as a troubleshooting scenario where someone has broad admin permissions but still can't do something, and the answer involves checking for a permissions boundary on the role. SSM Session Manager with IAM roles is more common than you think on the exam. They ask about situations where EC2 instances need to talk to other services but you don't want to manage long-lived credentials. The answer usually involves IAM roles and Session Manager, not environment variables or parameter store for secrets.
Get the Full Details

KMS and Encryption
This section is where people lose points. Not because the concepts are hard. Because the exam mixes service-integrated encryption with KMS key policies and grants in ways that feel intentional and mean to test whether you actually read the documentation. You need to understand the difference between envelope encryption and native service encryption. S3 uses envelope encryption by default with SSE-KMS, but the key details matter: which key, who controls the key, and how decryption flows back through the service. The exam loves to throw in scenarios where an application can't decrypt data and you have to trace the issue through the KMS key policy, the IAM policy, and the grant. One thing that caught me once: KMS grants have a principal and a operations field. If the operations field says "Decrypt" but the application also needs "GenerateDataKey," the grant is insufficient. I spent an hour debugging this in a lab environment before I realized the grant was missing GenerateDataKey as an operation. The exam definitely has questions like this, where someone has a grant that looks correct but is functionally broken because of a missing operation.
Data protection specifics
S3 object-level encryption is different from bucket-level defaults. S3 defaults apply at the bucket level, but individual objects can have their own encryption configuration. CloudFront uses S3 Origin Access Control, not Origin Access Identity anymore. The old OAI still works but the exam may reference the newer OAC, and mixing them up will cost you points. VPC endpoints for KMS: if you're using a VPC endpoint policy to restrict which KMS keys an instance can use, and that instance also needs to access other AWS services through privateLink, the endpoint policy needs to allow both. A common pitfall is writing an endpoint policy that only mentions KMS and then wondering why the instance can't reach S3 through the same VPC setup.
CloudTrail and Log Validation
Log file validation is a specific topic that trips people up. CloudTrail doesn't just log events. It creates a digest file every five minutes that contains hashes of the previous log files. If someone tampers with a log file, the digest won't match. The exam asks about detecting tampering, and the answer usually involves using the CloudTrail log validation feature or the aws cloudtrail validate-logs CLI command. Multi-region trails with uniform log file validation are the standard answer for organizations that need forensic-grade log integrity. If the question mentions a need to detect whether logs were deleted or modified, this is the answer, not just enabling logging on a single trail.

GuardDuty and Threat Detection
GuardDuty findings have severity levels: low, medium, high. The exam expects you to know what each finding type means and how to respond. Some findings are expected behavior, like an instance making DNS queries for a known good domain through a proxy. Others are actual threats, like cryptomining or unauthorized access from a Tor exit node. I worked on a project where GuardDuty fired a "InstanceProfiling" finding on a production server. The investigation showed the server was running a legitimate profiling tool that made unusual system calls. We had to create a suppression rule based on the specific EC2 instance ID and the known process. The exam tests this kind of operational knowledge, not just "enable GuardDuty and call it done."
Response automation
GuardDuty integrates with Lambda for automated response. You can set up triggers that investigate findings and take action. The exam sometimes presents a scenario where you need to automatically isolate a compromised instance and notify the security team. The answer involves GuardDuty finding, EventBridge rule, and Lambda function. Macie is another service that appears frequently. It discovers sensitive data in S3. If the question involves PII, PHI, or financial data discovery, Macie is usually the answer. But Macie and GuardDuty overlap in some areas, and the exam tests whether you know which service handles which type of problem. Macie is about data classification and discovery. GuardDuty is about threat detection and anomaly monitoring.
Network Security
Security Groups and NACLs are basic, but the exam goes deeper with WAF, Shield, and Network Firewall. WAF rules can be ordered by priority. If you have a rule blocking all requests from a specific IP and another rule allowing requests from a specific user agent, the order matters. The exam has questions about rule evaluation order that seem designed to make you second-guess yourself. Shield Advanced provides DDoS protection. The difference between Shield Standard and Shield Advanced matters for the exam. Standard is free and covers common attacks. Advanced provides resource-specific protection, cost protection, and 24/7 access to the DRT. If the question mentions a business-critical application that needs guaranteed DDoS protection with financial safeguards, Shield Advanced is the answer.

Secrets Management
Systems Manager Parameter Store vs Secrets Manager. Parameter Store is free. Secrets Manager costs money and includes automatic rotation. The exam tests whether you know when to use each one. If the question mentions automatic rotation, Secrets Manager is the answer. If it's about storing configuration values that don't need rotation, Parameter Store works fine. I once configured a secret rotation for a database credential using Lambda. The rotation function had to handle the secret's JSON structure, update the database, and test the new credentials. When I first set it up, the rotation failed because the Lambda execution role didn't have permission to call the RDS ModifyDBInstance API. The error message pointed to the role, but it took me a while to realize that the trust relationship and the permissions policy needed to be checked separately. The exam can include questions like this where the obvious answer is wrong because of a missing permission somewhere in the chain.
Compute Security
EC2 instance profiles, EBS encryption, and AMI security are all fair game. The exam sometimes asks about securing data at rest on EC2 volumes. The answer depends on whether you're using AWS-managed keys or customer-managed KMS keys. If the organization has strict key management requirements, CMK is the answer. If they just need encryption enabled, the default AWS-managed key is sufficient. Application Load Balancers support SSL termination. The exam covers certificate management with ACM. If you need certificates for multiple domains across multiple regions, ACM is the service to use. The catch is that ACM certificates are region-specific. A certificate issued in us-east-1 isn't automatically available in us-west-2. This comes up in multi-region deployment scenarios.
Practical Study Strategy
Don't just read the guide. Do labs. Set up a KMS key, write a policy that intentionally has a bug, and try to figure out why decryption fails. Create an IAM role with a permissions boundary that is too restrictive and observe what gets blocked. The exam questions are scenario-based, and your ability to reason through scenarios improves only when you've actually seen the problem happen. The official AWS documentation is worth more than most third-party courses. I spent more time reading the IAM policy evaluation logic page than any tutorial video. It's dry, but it's exactly what the exam tests. The KMS documentation section on key policy and grants is another page I read multiple times. Same for the GuardDuty findings reference.

What to skip
Don't spend hours on services that aren't heavily tested. CodeCommit and CodePipeline security features are mentioned but rarely the focus. CloudFormation and Terraform are infrastructure-as-code tools, and while they have security implications, the exam tests the AWS security services themselves, not the IaC layer. Spend your time on IAM, KMS, CloudTrail, GuardDuty, Macie, WAF, and Shield. Practice exams are useful but not a guarantee. I took two different practice exams before the real thing. One was very close to the actual exam difficulty. The other was significantly easier and gave me a false sense of confidence. The real exam had questions that required reading multiple policy documents and tracing permissions through several layers. If your practice exams don't include that kind of complexity, they're not preparing you properly.
Common Mistakes I See
People confuse resource-based policies with identity-based policies. Resource-based policies are attached to AWS resources like S3 buckets, KMS keys, and IAM roles. Identity-based policies are attached to IAM users, groups, and roles. The exam tests whether you know which type of policy controls what. A common mistake is thinking that an IAM policy can restrict access to a KMS key directly. It can't. You need a KMS key policy or a grant for that. Another mistake is assuming that enabling a security feature is enough. The exam often presents a scenario where a service is enabled but misconfigured. WAF is enabled, but the web ACL isn't associated with the right resource. GuardDuty is enabled, but it's not using enhanced findings or the right data sources. The answer isn't "enable the service." It's "enable it and configure it correctly." Understanding the shared responsibility model at a granular level matters too. AWS manages security of the cloud. The customer manages security in the cloud. But the specifics vary by service. For S3, AWS manages the underlying storage infrastructure, but the customer manages bucket policies, encryption, and access controls. For EC2, AWS manages the hypervisor and physical security, but the customer manages the OS patching, security groups, and instance configuration. The exam tests these boundaries with specific service examples.
Final Notes
This guide is a starting point. The actual exam will throw curveballs, especially around policy evaluation and service integration. The best preparation is hands-on experience combined with reading the official documentation thoroughly. I've seen people pass with minimal hands-on experience by memorizing answers, but those people tend to fail the next time or struggle in real work. The goal should be understanding, not memorization.