Same secret key encrypts and decrypts. Fast, but key distribution is the hard problem.
Watchpoint: the same key sits on both endpoints — protect it as you would a password vault.
CISSP Mastery · Module 3 / 8
Mastering the blueprints of secure systems: from hardware to the cloud.
Your progress
Domain 3 of 8 38%
13%
Exam weight
Models
Bell-LaPadula · Biba · Clark-Wilson
3 / 8
Domain focus
PKI
Crypto · Cloud · Physical
Open preview · Domain overview
Domain 3 connects abstract security principles to concrete engineering. You learn to read a system the way a CISO would: which model governs its access decisions, where the cryptography lives, how the physical layer protects it, and how the cloud reshapes every assumption.
Domain 3 is the bridge between the data layer mastered in Domain 2 and the network & identity controls coming in Domains 4 and 5. Get the architecture vocabulary right and every later domain stops feeling like a separate exam.
Models = formalized policy
Security models (Bell-LaPadula, Biba, Clark-Wilson) translate confidentiality, integrity and well-formed transactions into rules a system can actually enforce.
Cryptography = trust at scale
Symmetric for speed, asymmetric for trust establishment, PKI for binding identities to keys. Every other domain plugs into this layer.
Physical = the bottom of the stack
No firewall protects an unlocked rack. Site selection, perimeter design, and environmental controls are graded as security architecture, not facilities.
Cloud & virtualization = shared fate
Multi-tenancy, hypervisors, and containers redraw the trust boundary. The exam tests how the shared responsibility model changes with IaaS / PaaS / SaaS.
Quick check
One question at a time — instant feedback. Pair it with the diagrams and Pro-Tip callouts above.
Quiz progress
Question 1 of 5
1.In a typical shared-responsibility model, who usually patches the guest OS in IaaS?
Exam Pro-Tip
Pro-Tip: In IaaS, customers retain significant responsibility above the virtualization layer.
2.Which cloud model usually gives customers the LEAST control over infrastructure?
Exam Pro-Tip
Pro-Tip: SaaS abstracts most infrastructure operations from the customer.
3.For IoT risk reduction, which control combination is MOST effective early?
Exam Pro-Tip
Pro-Tip: IoT resilience depends on hardening, segmentation, and continuous monitoring.
4.Compared to RSA at equivalent security levels, ECC generally provides:
Exam Pro-Tip
Pro-Tip: ECC offers strong security with smaller keys, useful for constrained systems.
5.Which key validates a digital signature created by a sender?
Exam Pro-Tip
Pro-Tip: Sign with private key, verify with corresponding public key.
Your score: 0 / 5
Module 3 ties security models, cryptography, physical controls, and cloud architecture into one engineering narrative. Mark your progress, then move on to Domain 4. Every domain module is free to consult — premium access applies only to the full Final Mock Exam experience.