CISSP Mastery

CISSP Mastery · Module 3 / 8

Domain 3: Security Architecture & Engineering

Mastering the blueprints of secure systems: from hardware to the cloud.

Your progress

Domain 3 of 8 38%

Module 3
  1. Domain 1
  2. Domain 2
  3. Domain 3
  4. Domain 4
  5. Domain 5
  6. Domain 6
  7. Domain 7
  8. Domain 8

13%

Exam weight

Models

Bell-LaPadula · Biba · Brewer-Nash

3 / 8

Domain focus

PKI

Crypto · Cloud · Physical

Open preview · Domain overview

Why Domain 3 is the engineering brain of the CISSP

Domain 3 connects abstract security principles to concrete engineering. You learn to read a system the way a CISO would: which model governs its access decisions, where the cryptography lives, how the physical layer protects it, and how the cloud reshapes every assumption.

Domain 3 is the bridge between the data layer mastered in Domain 2 and the network & identity controls coming in Domains 4 and 5. Get the architecture vocabulary right and every later domain stops feeling like a separate exam.

  • Models = formalized policy

    Security models (Bell-LaPadula, Biba, Clark-Wilson, Brewer-Nash) translate confidentiality, integrity, well-formed transactions, and conflict-of-interest walls into rules a system can enforce.

  • Cryptography = trust at scale

    Symmetric for speed, asymmetric for trust establishment, PKI for binding identities to keys. Every other domain plugs into this layer.

  • Physical = the bottom of the stack

    No firewall protects an unlocked rack. Site selection, perimeter design, and environmental controls are graded as security architecture, not facilities.

  • Cloud & virtualization = shared fate

    Multi-tenancy, hypervisors, and containers redraw the trust boundary. The exam tests how the shared responsibility model changes with IaaS / PaaS / SaaS.

Quick check

Domain 3 quiz

One question at a time — instant feedback. Pair it with the diagrams and Pro-Tip callouts above.

Quiz progress

Question 1 of 5 · 20%

Q 1

Question 1 of 5

1.In a typical shared-responsibility model, who usually patches the guest OS in IaaS?

Ready for Domain 4?

Module 3 ties security models, cryptography, physical controls, and cloud architecture into one engineering narrative. Mark your progress, then move on to Domain 4. Every domain module is free to consult — premium access applies only to the full Final Mock Exam experience.