top of page

CISSP Domain 3 Master Cheat Sheet: Security Architecture & Engineering

1. Security Engineering Principles

Security engineering integrates security into every phase of system design rather than adding controls after deployment.


Core Principles

  • Confidentiality

  • Integrity

  • Availability

  • Least Privilege

  • Separation of Duties

  • Defense in Depth

  • Fail Secure

  • Open Design

  • Economy of Mechanism

  • Complete Mediation

  • Least Common Mechanism

  • Psychological Acceptability


Secure Design Goals

Goal

Description

Confidentiality

Prevent unauthorized disclosure

Integrity

Prevent unauthorized modification

Availability

Ensure reliable access

Resilience

Continue operating during failures

Simplicity

Reduce unnecessary complexity

Reliability

Produce predictable results

Trustworthiness

Demonstrate secure operation


2. Security Architecture

Security Architecture defines how security controls work together to protect organizational assets.

Major architectural components include:

  • Identity Management

  • Access Control

  • Cryptography

  • Network Segmentation

  • Monitoring

  • Secure Storage

  • Logging

  • Backup

  • Disaster Recovery

  • Physical Security


Architecture Objectives

✔ Protect information assets

✔ Reduce attack surface

✔ Support compliance

✔ Enable business operations

✔ Improve resilience


3. Trusted Computing Concepts

Trusted Computing ensures that systems behave as expected under defined security policies.

Key concepts include:

  • Trusted Computing Base (TCB)

  • Security Kernel

  • Reference Monitor

  • Trusted Path

  • Trusted Channel

  • Trusted Recovery


Trusted Computing Base (TCB)

The Trusted Computing Base consists of all hardware, software, firmware, and security controls responsible for enforcing an organization's security policy.

If the TCB fails, the security of the entire system is compromised.

Examples:

  • Operating System Kernel

  • Hypervisor

  • TPM

  • Security Kernel

  • Authentication Mechanisms


CISSP Tip

Smaller TCBs are generally more secure because they reduce complexity and the potential attack surface.


4. Reference Monitor

The Reference Monitor is an abstract security concept responsible for enforcing access control policies.

Every request to access an object should pass through the Reference Monitor.

A valid Reference Monitor must be:

  • Tamper Resistant

  • Always Invoked

  • Small Enough to Verify


CISSP Remember

Reference Monitor = Access Control Gatekeeper


5. Security Kernel

The Security Kernel is the trusted component that implements the Reference Monitor. It operates inside the operating system kernel and enforces security policies.

Responsibilities include:

  • Access Control

  • Authentication

  • Authorization

  • Process Isolation

  • Memory Protection


Relationship

Reference Monitor
        ↓
Implemented by
        ↓
Security Kernel
        ↓
Part of
        ↓
Trusted Computing Base

6. Protection Rings

Modern processors use privilege levels called Protection Rings.

Ring

Privilege Level

Ring 0

Operating System Kernel

Ring 1

Device Drivers (rare)

Ring 2

System Services (rare)

Ring 3

User Applications


CISSP Tip

Ring 0 has unrestricted access to hardware.

Applications normally execute in Ring 3.


7. Processor Modes

Processors operate in two primary modes.

Mode

Purpose

Supervisor Mode

Full hardware access

User Mode

Restricted application execution

Applications should never execute with unnecessary privileges.


8. Memory Protection

Memory protection prevents one process from accessing another process's memory.

Common techniques include:

  • Virtual Memory

  • Address Space Layout Randomization (ASLR)

  • Data Execution Prevention (DEP)

  • Memory Isolation

  • Page Protection


Benefits

  • Prevents privilege escalation

  • Stops unauthorized memory access

  • Improves operating system stability


9. Hardware Security

Secure hardware provides the foundation for trustworthy computing.

Examples include:

  • Trusted Platform Module (TPM)

  • Hardware Security Module (HSM)

  • Secure Enclave

  • Smart Cards

  • Hardware Root of Trust


Trusted Platform Module (TPM)

Provides:

  • Secure key storage

  • Platform integrity measurement

  • Secure Boot support

  • Device authentication


Hardware Security Module (HSM)

Dedicated hardware used for:

  • Cryptographic key storage

  • Certificate management

  • PKI operations

  • High-performance encryption


TPM vs. HSM

TPM

HSM

Installed in endpoint devices

Dedicated enterprise appliance

Device security

Enterprise key management

Secure Boot

PKI infrastructure

Local cryptographic operations

Large-scale cryptographic services


10. Secure Boot

Secure Boot ensures only trusted software loads during system startup.

Boot process:

Firmware
     ↓
Boot Loader
     ↓
Operating System
     ↓
Applications

Each component verifies the integrity of the next before execution.


11. Root of Trust

A Root of Trust is the foundational hardware or software component upon which all other trust depends.

Examples include:

  • TPM

  • Secure Boot

  • Hardware Security Module

  • CPU Security Features


12. Isolation Concepts

Isolation limits the impact of compromise.

Common mechanisms:

  • Sandboxing

  • Virtual Machines

  • Containers

  • Process Isolation

  • Memory Isolation

Isolation helps contain malware and reduces lateral movement.


13. Common CISSP Domain 3 Mistakes

❌ Confusing the Reference Monitor with the Security Kernel.

❌ Assuming the TCB is only hardware.

❌ Believing Ring 3 applications have unrestricted privileges.

❌ Forgetting that Secure Boot verifies software integrity before loading.

❌ Assuming TPM and HSM serve identical purposes.


14. CISSP Exam Tips

✔ Understand the relationship between TCB, Security Kernel, and Reference Monitor.

✔ Remember that Ring 0 is the most privileged execution level.

✔ Favor architectures that reduce complexity and minimize the Trusted Computing Base.

✔ Think in terms of secure system design, not individual security products.

✔ Trusted computing concepts are frequently tested using scenario-based questions.


15. Quick Revision Checklist

□ Security Engineering Principles

□ Trusted Computing Base (TCB)

□ Security Kernel

□ Reference Monitor

□ Protection Rings

□ Processor Modes

□ Memory Protection

□ TPM

□ HSM

□ Secure Boot

□ Root of Trust

□ Hardware Security

□ Isolation Mechanisms


16. Memory Aids

Topic

Memory Trick

TCB

Everything enforcing security

Reference Monitor

Gatekeeper

Security Kernel

Implements Reference Monitor

Ring 0

Operating System

Ring 3

Applications

TPM

Endpoint trust

HSM

Enterprise cryptography

Secure Boot

Verify before loading

Root of Trust

Foundation of trust


Cryptography, PKI & Physical Security


17. Cryptography Fundamentals

Cryptography protects information by transforming readable data (plaintext) into unreadable data (ciphertext). It is fundamental to achieving Confidentiality, Integrity, Authentication, and Non-repudiation.


Security Goals Supported

Goal

Cryptographic Mechanism

Confidentiality

Encryption

Integrity

Hashing

Authentication

Digital Certificates, Keys

Non-repudiation

Digital Signatures


Key Cryptographic Terms

  • Plaintext

  • Ciphertext

  • Cipher

  • Encryption

  • Decryption

  • Key

  • Initialization Vector (IV)

  • Nonce

  • Salt

  • Entropy


CISSP Tip

Encryption protects confidentiality.

Hashing protects integrity.

Digital signatures provide authentication, integrity, and non-repudiation.


18. Symmetric vs Asymmetric Encryption

Symmetric Encryption

Uses the same key for encryption and decryption.

Examples

  • AES ⭐⭐⭐⭐⭐

  • DES (obsolete)

  • 3DES (legacy)

  • Blowfish

  • Twofish

  • ChaCha20


Advantages

  • Very fast

  • Efficient

  • Suitable for large amounts of data


Disadvantages

  • Difficult key distribution

  • Scalability challenges


Asymmetric Encryption

Uses public/private key pairs.

Examples

  • RSA

  • ECC

  • ElGamal


Advantages

  • Secure key exchange

  • Digital signatures

  • Authentication


Disadvantages

  • Slower than symmetric encryption


Comparison

Symmetric

Asymmetric

Same key

Public & Private keys

Fast

Slower

Bulk encryption

Key exchange

AES

RSA, ECC


CISSP Remember

AES protects data.

RSA exchanges keys.


19. Key Management

Strong encryption depends upon proper key management.

Key lifecycle includes:

Generate

Distribute

Store

Rotate

Archive

Destroy


Best Practices

  • Least privilege

  • Hardware protection

  • Regular rotation

  • Separation of duties

  • Key escrow when required


Key Escrow

Copies of encryption keys are securely stored for authorized recovery.

Often required for:

  • Legal investigations

  • Business continuity

  • Disaster recovery


20. Public Key Infrastructure (PKI)

PKI manages digital identities using certificates.

PKI Components

Component

Purpose

Certificate Authority (CA)

Issues certificates

Registration Authority (RA)

Verifies identity

Certificate Repository

Stores certificates

CRL

Revoked certificates

OCSP

Real-time revocation checking


Certificate Lifecycle

Generate Key Pair
        ↓
Submit CSR
        ↓
Identity Verification
        ↓
Certificate Issued
        ↓
Install
        ↓
Renew
        ↓
Revoke

CISSP Tip

The CA establishes trust.

The RA verifies identity.


21. Digital Certificates

Digital certificates bind:

Identity


Public Key


Certificates contain:

  • Subject

  • Issuer

  • Public Key

  • Validity Period

  • Serial Number

  • Digital Signature


X.509

The most common certificate standard used on the Internet.


22. Digital Signatures

Digital signatures provide:

✔ Authentication

✔ Integrity

✔ Non-repudiation


Process

Hash Document

Encrypt Hash with Private Key

Receiver decrypts using Public Key

Compare Hashes


CISSP Tip

Digital signatures do not encrypt the document.

They encrypt the hash.


23. Hash Functions

Hashing creates a fixed-length fingerprint.

Characteristics:

  • One-way

  • Deterministic

  • Fixed output

  • Collision resistant


Common Algorithms

Secure

Legacy

SHA-256

MD5

SHA-384

SHA-1

SHA-512



Uses

Password storage

Integrity verification

Digital signatures

File validation

Blockchain


24. Password Protection

Passwords should never be encrypted for storage.

Instead:

Hash


Salt


Key Stretching


Modern Algorithms

  • bcrypt

  • scrypt

  • Argon2 ⭐⭐⭐⭐⭐

  • PBKDF2

Salt

Prevents rainbow table attacks.


25. Random Number Generation

Good cryptography depends upon randomness.

Sources include:

  • Hardware RNG

  • Entropy

  • TPM

  • Secure operating system generators


CISSP Tip

Weak randomness produces weak encryption.


26. Cryptographic Attacks

Common attacks include:

Brute Force

Dictionary

Birthday Attack

Known Plaintext

Chosen Plaintext

Chosen Ciphertext

Replay

Side Channel

Meet-in-the-Middle

Downgrade Attacks


Comparison

Attack

Target

Birthday

Hashes

Replay

Authentication

MITM

Key Exchange

Brute Force

Passwords

Side Channel

Hardware


27. Physical Security

Physical security protects people, facilities, and equipment.

Layers

Perimeter

Building

Floor

Room

Rack

Device


Controls

Fences

Guards

Lighting

Locks

Badges

Biometrics

Cameras

Mantraps


28. Facility Security

Important considerations:

Location

Crime rate

Flood zones

Earthquake zones

Political stability

Utilities

Transportation

Emergency services


29. Environmental Controls

HVAC

Maintains:

  • Temperature

  • Humidity

  • Airflow


EMI Protection

Protects against:

Electromagnetic interference

Radio-frequency interference


Power Protection

UPS

Generators

Power conditioning

Surge suppressors

Redundant power feeds


30. Fire Suppression

Fire classes are frequently tested.

Fire

Description

A

Ordinary combustibles

B

Liquids

C

Electrical

D

Metals

K

Cooking oils


Suppression Systems

Wet Pipe

Dry Pipe

Pre-action ⭐⭐⭐⭐⭐

Deluge

Clean Agent (FM-200, Novec 1230)


CISSP Tip

Server rooms commonly use:

Pre-action or Clean Agent systems.


31. Water Damage Protection

Raised floors

Leak detection

Water sensors

Proper drainage

Equipment elevation


32. Secure Facility Design

Secure facilities include:

  • Layered security

  • Visitor management

  • CCTV

  • Badge systems

  • Security guards

  • Asset inventory

  • Alarm systems

  • Restricted areas


33. Common Domain 3 Mistakes

❌ Confusing encryption with hashing.

❌ Assuming digital signatures encrypt documents.

❌ Confusing CA and RA.

❌ Forgetting that salts are unique.

❌ Selecting wet pipe sprinklers for data centers.


34. CISSP Domain 3 Exam Tips

✔ AES protects confidentiality.

✔ RSA exchanges keys.

✔ ECC provides similar security with smaller keys.

✔ Hashing protects integrity.

✔ Digital signatures provide authentication.

✔ Certificates establish trust.

✔ Clean agent systems protect equipment.

✔ Always think about confidentiality, integrity, and availability together.


35. Quick Revision Checklist

□ AES

□ RSA

□ ECC

□ PKI

□ CA

□ RA

□ Digital Certificates

□ Digital Signatures

□ Hash Functions

□ Salt

□ bcrypt

□ Argon2

□ Fire Classes

□ HVAC

□ UPS

□ Clean Agent

□ Pre-action


36. Memory Aids

Topic

Memory Trick

AES

Bulk Encryption

RSA

Key Exchange

ECC

Smaller Keys

Hash

Integrity

Signature

Authenticate + Integrity + Non-repudiation

CA

Issues Certificates

RA

Verifies Identity

Salt

Stops Rainbow Tables

Argon2

Modern Password Hashing

Pre-action

Data Centers

Clean Agent

No Water Damage


The next section of the GoCyberNinja Domain 3 Master Cheat Sheet covers:

  • Secure System Design Principles

  • Evaluation Criteria (TCSEC, ITSEC, Common Criteria)

  • Virtualization & Hypervisors

  • Containers & Serverless Security

  • Cloud Security Architecture

  • Internet of Things (IoT)

  • Operational Technology (OT) & Industrial Control Systems (ICS)

  • Embedded Systems

  • Artificial Intelligence Security Considerations

  • Security Architecture Best Practices

  • 5 CISSP-Style Practice Questions

  • Key Takeaways and GoCyberNinja Practice CTA


Secure System Design, Virtualization, Cloud, IoT & Modern Architectures

37. Secure System Design Principles

Security should be incorporated into systems from the initial design phase, not added after deployment.


Fundamental Principles

  • Least Privilege

  • Separation of Duties

  • Defense in Depth

  • Fail Secure

  • Fail Safe

  • Open Design

  • Economy of Mechanism

  • Complete Mediation

  • Least Common Mechanism

  • Psychological Acceptability

  • Secure Defaults

  • Minimize Attack Surface


CISSP Tip

The simplest secure architecture is often the strongest.

Complexity introduces vulnerabilities.


38. System Evaluation Models

Governments and organizations evaluate systems to determine whether they meet defined security requirements.

Trusted Computer System Evaluation Criteria (TCSEC)

Also known as:

Orange Book

Focus:

  • Confidentiality

  • Military systems


Security Levels:

Rating

Meaning

D

Minimal Protection

C1

Discretionary Security

C2

Controlled Access Protection

B1

Labeled Security

B2

Structured Protection

B3

Security Domains

A1

Verified Design


Information Technology Security Evaluation Criteria (ITSEC)

European framework.

Evaluates:

  • Functionality

  • Assurance


Common Criteria (CC)

The international standard replacing TCSEC and ITSEC.

ISO/IEC 15408

Evaluation Assurance Levels (EAL)

Level

Meaning

EAL1

Functionally Tested

EAL2

Structurally Tested

EAL3

Methodically Tested

EAL4

Methodically Designed & Reviewed ⭐

EAL5

Semi-formally Designed

EAL6

Semi-formally Verified

EAL7

Formally Verified


CISSP Tip

Most commercial products achieve EAL4.


39. Trusted Execution Technologies

Modern processors include hardware security features.

Examples

  • Intel TXT

  • AMD SEV

  • ARM TrustZone

  • Secure Enclave

  • TPM

Purpose

  • Protect memory

  • Secure boot

  • Hardware isolation

  • Measured boot


40. Virtualization

Virtualization allows multiple operating systems to share the same physical hardware.


Hypervisors

Type 1 (Bare Metal)

Runs directly on hardware.

Examples

  • VMware ESXi

  • Microsoft Hyper-V

  • Xen


Advantages

  • Better performance

  • Better security

  • Enterprise deployments


Type 2 (Hosted)

Runs on top of an operating system.

Examples

  • VirtualBox

  • VMware Workstation

Advantages

  • Easy testing

  • Development


Comparison

Type 1

Type 2

Bare Metal

Hosted

Faster

Slower

Enterprise

Desktop

More Secure

Less Secure


Virtualization Risks

  • VM Escape

  • Hypervisor attacks

  • Snapshot theft

  • Resource exhaustion

  • VM Sprawl


CISSP Tip

Type 1 hypervisors generally provide stronger isolation and are preferred for production environments.


41. Containers

Containers package applications together with their dependencies.

Examples

  • Docker

  • Kubernetes

  • Podman

Benefits

  • Lightweight

  • Fast deployment

  • Portability

  • Scalability

Risks

  • Shared kernel

  • Container escape

  • Insecure images

  • Misconfigured orchestration

  • Excessive privileges


Containers vs Virtual Machines

Containers

Virtual Machines

Share OS Kernel

Separate OS

Lightweight

Heavier

Fast Startup

Slower Startup

Less Isolation

Stronger Isolation


42. Serverless Computing

Applications execute without managing servers.

Examples

  • AWS Lambda

  • Azure Functions

  • Google Cloud Functions

Benefits

  • Automatic scaling

  • Reduced administration

  • Pay per execution

Security Concerns

  • IAM permissions

  • Secrets management

  • Third-party libraries

  • Event injection

  • Logging


43. Cloud Security Architecture

Cloud computing changes—not eliminates—security responsibilities.

Service Models

Model

Customer Manages

IaaS

OS, Applications, Data

PaaS

Applications, Data

SaaS

Primarily Data


Deployment Models

  • Public Cloud

  • Private Cloud

  • Hybrid Cloud

  • Community Cloud

  • Multi-Cloud


Shared Responsibility Model

Cloud Provider

  • Infrastructure

  • Physical Security

  • Hypervisor

Customer

  • Identity

  • Data

  • Configuration

  • Access Control

  • Encryption


CISSP Tip

The customer is always responsible for protecting data.


44. Secure Cloud Design

Important considerations:

  • Zero Trust

  • IAM

  • Encryption

  • Logging

  • Monitoring

  • Network Segmentation

  • Backup

  • Key Management

  • Data Residency

  • Compliance


45. Internet of Things (IoT)

IoT devices often have limited resources.

Challenges include:

  • Weak authentication

  • Default passwords

  • Lack of patching

  • Insecure firmware

  • Limited encryption

  • Supply chain risks


Best Practices

  • Change default credentials

  • Network segmentation

  • Firmware updates

  • Device inventory

  • Continuous monitoring


46. Operational Technology (OT) & Industrial Control Systems (ICS)

Examples

  • Manufacturing

  • Utilities

  • Oil & Gas

  • Water Treatment


Components

PLC

SCADA

RTU

DCS

HMI

Primary Objective

Safety

Availability

Reliability

CISSP Tip

Unlike IT, operational technology prioritizes availability and safety above confidentiality.


47. Embedded Systems

Examples

  • Medical Devices

  • Vehicles

  • Smart TVs

  • Routers

  • Industrial Controllers


Security Challenges

  • Limited updates

  • Hardcoded credentials

  • Legacy firmware

  • Long life cycles


48. Artificial Intelligence Security

AI is increasingly incorporated into enterprise systems.

Security considerations include:

  • Model poisoning

  • Prompt injection

  • Data leakage

  • Model theft

  • Adversarial attacks

  • Sensitive training data


Defensive AI Uses

Threat detection

Fraud detection

Malware analysis

Behavior analytics

Security automation


49. Secure Architecture Best Practices

✔ Defense in Depth

✔ Zero Trust

✔ Secure by Design

✔ Privacy by Design

✔ Least Privilege

✔ Segmentation

✔ Continuous Monitoring

✔ Secure Defaults

✔ Minimize Attack Surface

✔ Infrastructure as Code Security


50. Common Domain 3 Mistakes

❌ Confusing containers with virtual machines.

❌ Assuming cloud providers secure customer data automatically.

❌ Forgetting the Shared Responsibility Model.

❌ Believing virtualization completely isolates workloads.

❌ Prioritizing confidentiality over availability in OT environments.

❌ Ignoring secure configuration of cloud resources.


51. CISSP Domain 3 Exam Tips

✔ Always understand who owns security responsibilities.

✔ Cloud questions often test the Shared Responsibility Model.

✔ Virtual machines provide stronger isolation than containers.

✔ Zero Trust applies equally to cloud, on-premises, and hybrid environments.

✔ OT environments prioritize safety and availability.

✔ Modern CISSP questions frequently include cloud and virtualization scenarios.


52. Quick Revision Checklist

□ Common Criteria

□ EAL Levels

□ Hypervisors

□ Virtual Machines

□ Containers

□ Serverless

□ Cloud Service Models

□ Cloud Deployment Models

□ Shared Responsibility

□ IoT Security

□ OT / ICS

□ Embedded Systems

□ AI Security

□ Zero Trust


53. Memory Aids

Topic

Memory Trick

Common Criteria

ISO/IEC 15408

EAL4

Most Commercial Products

Type 1 Hypervisor

Bare Metal

Type 2 Hypervisor

Hosted

Containers

Share Kernel

Virtual Machines

Separate OS

IaaS

Customer manages OS

SaaS

Provider manages application

IoT

Small Devices, Big Risks

ICS

Safety Before Confidentiality

Shared Responsibility

Provider secures Cloud; Customer secures Data


54. Architecture Comparison Table

Technology

Primary Benefit

Primary Risk

Virtual Machines

Strong isolation

Hypervisor attacks

Containers

Fast deployment

Container escape

Serverless

Reduced administration

IAM misconfiguration

Cloud

Scalability

Misconfiguration

IoT

Automation

Weak security

OT/ICS

Operational continuity

Safety impacts

TPM

Hardware trust

Physical compromise

HSM

Enterprise key protection

Cost and complexity


The final part of the GoCyberNinja Domain 3 Master Cheat Sheet will include:

  • 10 CISSP-style scenario questions with detailed explanations

  • Common Domain 3 exam traps

  • Manager vs. Engineer mindset

  • Final revision checklist

  • Key takeaways


Final Review, CISSP Questions & Exam Readiness


55. Common CISSP Domain 3 Exam Traps

Many Domain 3 questions include multiple technically correct answers. Your task is to select the BEST answer from a business and architectural perspective.


Trap 1 – Choosing the Newest Technology

The newest technology is not always the most appropriate.

Choose the solution that:

  • Meets business requirements

  • Reduces risk

  • Supports governance

  • Is cost-effective


Trap 2 – Confusing Confidentiality with Integrity

Remember:

  • Encryption protects Confidentiality

  • Hashing protects Integrity

  • Digital Signatures provide Authentication, Integrity, and Non-repudiation


Trap 3 – Confusing TPM with HSM

TPM

  • Device security

  • Secure Boot

  • Local keys

HSM

  • Enterprise cryptographic services

  • PKI

  • Certificate Authority

  • Centralized key management


Trap 4 – Thinking Like an Administrator

The CISSP is not a system administrator exam.

Avoid answers focused only on:

  • Commands

  • Configuration

  • Vendor features

Instead choose answers based on:

  • Architecture

  • Risk

  • Business objectives

  • Security principles


Trap 5 – Forgetting the Shared Responsibility Model

Cloud providers secure:

Infrastructure

Customers secure:

  • Identity

  • Data

  • Configuration

  • Access


56. Manager vs Engineer Mindset

One of the biggest transitions in CISSP preparation is learning to think like a security architect and business advisor.

Engineer Thinking

CISSP Thinking

Deploy another firewall

Reduce organizational risk

Encrypt everything

Protect critical assets first

Buy more tools

Design secure architecture

Solve technical issues

Support business objectives

Focus on implementation

Focus on governance and design


Remember

Architecture before Technology

Good architecture makes technology effective.

Poor architecture cannot be fixed by purchasing additional tools.


57. Final Domain 3 Revision Checklist

Review this checklist before the exam.

Security Engineering

□ CIA

□ Defense in Depth

□ Least Privilege

□ Complete Mediation

□ Open Design

□ Fail Secure


Trusted Computing

□ TCB

□ Security Kernel

□ Reference Monitor

□ Protection Rings

□ Processor Modes

□ Memory Protection


Hardware Security

□ TPM

□ HSM

□ Secure Boot

□ Root of Trust


Cryptography

□ AES

□ RSA

□ ECC

□ PKI

□ Certificates

□ Digital Signatures

□ Hashing

□ Salt

□ Argon2


Secure Architecture

□ Hypervisors

□ Virtual Machines

□ Containers

□ Serverless

□ Shared Responsibility

□ Zero Trust


Physical Security

□ Fire Classes

□ Pre-action Systems

□ Clean Agent

□ UPS

□ HVAC

□ EMI


Cloud

□ IaaS

□ PaaS

□ SaaS

□ Public

□ Private

□ Hybrid


IoT / OT

□ PLC

□ SCADA

□ HMI

□ Embedded Systems

□ Availability


58. CISSP Domain 3 Memory Aids

Topic

Memory Trick

CIA

Confidentiality • Integrity • Availability

TCB

Everything enforcing security

Security Kernel

Implements Reference Monitor

Ring 0

Operating System

Ring 3

Applications

TPM

Endpoint Trust

HSM

Enterprise Keys

AES

Bulk Encryption

RSA

Key Exchange

ECC

Smaller Keys

Hash

Integrity

Signature

Authentication + Integrity + Non-repudiation

Type 1 Hypervisor

Bare Metal

Containers

Share Kernel

VM

Separate OS

Shared Responsibility

Provider secures Cloud; Customer secures Data

OT

Safety Before Confidentiality


59. 10 CISSP-Style Practice Questions

Question 1

Which Trusted Computing Base component enforces the access control policy?

A. TPM

B. Security Kernel

C. Hypervisor

D. BIOS

Answer: B

Explanation

The Security Kernel implements the Reference Monitor and enforces access control policies within the Trusted Computing Base.


Question 2

Which encryption algorithm is MOST appropriate for encrypting a large database?

A. RSA

B. ECC

C. AES

D. SHA-256

Answer: C

Explanation

AES is a fast, symmetric encryption algorithm designed for encrypting large volumes of data.


Question 3

A cloud customer stores sensitive customer records in an object storage service.

Who is responsible for protecting the confidentiality of the stored data?

A. Cloud Provider

B. Customer

C. Internet Service Provider

D. Certificate Authority

Answer: B

Explanation

Under the Shared Responsibility Model, customers are responsible for protecting their own data through encryption, access controls, and proper configuration.


Question 4

Which technology provides the strongest isolation between workloads?

A. Containers

B. Virtual Machines

C. Serverless Functions

D. Shared Hosting

Answer: B

Explanation

Virtual machines include separate operating systems and provide stronger isolation than containers, which share the host kernel.


Question 5

What is the PRIMARY purpose of a digital signature?

A. Encrypt data

B. Compress files

C. Provide authentication and integrity

D. Prevent malware

Answer: C

Explanation

Digital signatures verify the sender's identity, protect integrity, and support non-repudiation.


Question 6

An organization is designing a secure architecture. Which principle recommends minimizing unnecessary system complexity?

A. Complete Mediation

B. Economy of Mechanism

C. Separation of Duties

D. Least Privilege

Answer: B

Explanation

Economy of Mechanism promotes simple designs because simpler systems are easier to understand, verify, and secure.


Question 7

Which fire suppression system is generally preferred for a data center?

A. Wet Pipe

B. Deluge

C. Pre-action

D. Garden Sprinkler

Answer: C

Explanation

Pre-action systems require two triggering events before releasing water, significantly reducing the risk of accidental water damage to IT equipment.


Question 8

Which hardware component securely stores cryptographic keys for enterprise PKI operations?

A. TPM

B. Smart Card

C. HSM

D. USB Token

Answer: C

Explanation

Hardware Security Modules (HSMs) provide highly secure, tamper-resistant storage and management of cryptographic keys in enterprise environments.


Question 9

A company deploys Docker containers to improve application portability. What is the PRIMARY security concern?

A. Excessive encryption

B. Shared operating system kernel

C. Slow performance

D. Large disk usage

Answer: B

Explanation

Containers share the host operating system kernel, which provides less isolation than full virtual machines and introduces container escape risks.


Question 10

A manufacturing company is designing security controls for an Industrial Control System (ICS). Which objective should receive the HIGHEST priority?

A. Confidentiality

B. Marketing

C. Availability and Safety

D. Cost Reduction

Answer: C

Explanation

Operational Technology (OT) environments prioritize the continuous and safe operation of physical processes. Availability and safety typically take precedence over confidentiality.


60. Key Takeaways

  • Domain 3 focuses on designing secure systems rather than configuring individual technologies.

  • Trusted Computing concepts such as the TCB, Security Kernel, and Reference Monitor form the foundation of secure operating systems.

  • Symmetric encryption protects large volumes of data, while asymmetric encryption supports key exchange and digital signatures.

  • Strong cryptography depends on proper key management, secure random number generation, and trusted hardware.

  • Virtualization, containers, cloud computing, and IoT introduce unique architectural and security considerations.

  • Physical security and environmental controls remain essential components of a comprehensive security architecture.

  • Successful CISSP candidates think like architects and advisors—prioritizing secure design, risk reduction, and business objectives over specific products or configurations.


61. Related CISSP Articles

Continue strengthening your Security Architecture & Engineering knowledge with these in-depth guides:

  • Security Concepts

  • Cryptography

  • Security Controls

  • Zero Trust Architecture

  • Identity and Access Management (IAM)

  • Defense in Depth

  • Risk Management

  • Business Continuity Planning

  • Disaster Recovery Planning

  • NIST Risk Management Framework (RMF)

  • NIST Cybersecurity Framework (CSF)

  • Data Classification

  • Compliance

  • Governance, Risk & Compliance (GRC)


GoCyberNinja Master Cheat Sheet Series

Maintain a consistent naming convention across all eight domains to reinforce your brand and improve discoverability:


Continue Your CISSP Journey with GoCyberNinja

Reading about secure software development is only the beginning. The CISSP exam evaluates your ability to apply security principles, assess business risk, and make informed management decisions across the entire software lifecycle.

GoCyberNinja CISSP Exam Prep helps reinforce Domain 8 through realistic, scenario-driven practice designed to build both technical understanding and executive-level decision-making.


Strengthen Your Domain 8 Knowledge

✅ Realistic CISSP Practice Questions covering all eight CISSP domains

✅ 1,200 Full Mock Exam Questions across eight comprehensive practice exams

✅ 400+ Scenario-Based Questions designed to develop the CISSP manager's mindset

✅ 1,040+ Flashcards for rapid review and long-term retention

✅ Adaptive Smart Review that automatically focuses on your weakest topics

✅ Performance Analytics to measure readiness and identify knowledge gaps

✅ Personalized Study Plans based on your learning progress

✅ Three Free CISSP Readiness Tests to benchmark your preparation before attempting full-length exams


Practice. Analyze. Master.

The CISSP is not a programming exam—it is a security leadership and risk management exam. Success comes from understanding how secure software supports business objectives, protects organizational assets, and reduces enterprise risk.

With GoCyberNinja CISSP Exam Prep, you'll build the judgment, confidence, and practical decision-making skills expected of a CISSP professional.

Practice smarter. Analyze deeper. Master the CISSP.


Take the FREE CISSP Readiness Tests to evaluate your knowledge, identify weak areas, and receive a personalized study roadmap before tackling the full question bank.


bottom of page