CISSP Exam Prep · Domain 3

Security Architecture & Engineering

Domain 3 covers secure design principles, security models, cryptography, PKI, and physical security. Expect heavy crypto math and model questions on the exam.

13% of exam weight 6 Lessons 30 Practice Questions
Exam Strategy Domain 3 is heavily tested with scenario-based questions. Cryptography (especially AES modes, key types, and digital signatures) and security models (BLP vs. Biba) are frequent trap areas. Read every question carefully for which property (confidentiality vs. integrity) is being protected.

Lessons

Domain 3 at a Glance

LessonCore TopicKey Models / StandardsTS Relevance
01Secure Design Principles8 Principles, Zero Trust (ZTA)PII incident root cause, Platform C arch
02Security ModelsBLP, Biba, Clark-Wilson, Brewer-NashCredit scoring integrity, loan workflows
03CryptographyAES, RSA, ECC, SHA-256, HMACAES-256-CTR PII, JWT RSA, TLS 1.3
04PKI & Key ManagementX.509, CRL, OCSP, FIPS 140-2Vault, cert-manager, key rotation
05Virtualization & CloudIaaS/PaaS/SaaS, K8s securityGKE, NetworkPolicies, Trivy scanning
06Physical SecurityCPTED, fire suppression, HVACManila data center (Partner E)
Study Plan Start with Lesson 01 (design principles) to build mental models, then tackle Lesson 03 (cryptography) which carries the most exam weight. Security models (Lesson 02) are pure memorization — use the BLP/Biba rule table. Return to Lessons 04-06 for applied architecture questions.