Architecture Vulnerabilities, Facilities and Lifecycle
This topic covers system architecture vulnerabilities, cloud and distributed systems, embedded and IoT risks, physical facility controls, environmental protection, and system lifecycle management.
How to study for CISSP
Treat each CISSP question as a risk decision: identify the owner, objective, control type, lifecycle phase, and business consequence before choosing.
Core concepts
Concept 1
Architecture Vulnerabilities, Facilities and Lifecycle questions test whether a security leader can choose a defensible control, process, or governance response for a business risk.
Exam cue: Identify the domain objective: govern risk, protect assets, engineer securely, secure networks, control identity, test, operate, or secure software.
Concept 2
The best CISSP answer usually protects people, policy, data, and mission before jumping to a narrow technical fix.
Exam cue: Match the response to the risk owner, data owner, control objective, lifecycle phase, and assurance evidence in the scenario.
Concept 3
Eliminate answers that skip authorization, ignore legal or contractual duties, weaken least privilege, or confuse preventive, detective, and corrective controls.
Exam cue: Prefer documented policy, due care, defense in depth, least privilege, validated recovery, and continuous improvement.
Risk pitfalls and guardrails
Choosing a tool before confirming business requirements, ownership, and risk treatment.
Guardrail: Avoid answers that jump to a tool, ignore the risk owner, weaken least privilege, skip evidence, or treat one security objective as the only concern.
Treating confidentiality as the only goal when integrity, availability, authenticity, accountability, and safety also matter.
Guardrail: Avoid answers that jump to a tool, ignore the risk owner, weaken least privilege, skip evidence, or treat one security objective as the only concern.
Ignoring legal, regulatory, contractual, audit, and evidence-handling obligations.
Guardrail: Avoid answers that jump to a tool, ignore the risk owner, weaken least privilege, skip evidence, or treat one security objective as the only concern.
Memory anchors
Shared Responsibility
Shared responsibility divides security duties between provider and customer based on the service model.
Virtualization Risk
Virtualization risk includes hypervisor compromise, VM escape, insecure images, and management plane exposure.
IoT Risk
IoT risk often includes weak update paths, default credentials, limited monitoring, and physical exposure.
Container Risk
Container risk includes vulnerable images, secrets exposure, insecure registries, and excessive runtime privileges.
Facility Control
Facility controls protect sites through zones, barriers, locks, guards, monitoring, and visitor processes.
Environmental Control
Environmental controls manage power, HVAC, fire detection, suppression, water, and physical hazards.
Mantrap
A mantrap controls physical entry by allowing one authenticated person through a controlled space.
System Lifecycle
System lifecycle management covers requirements, design, build, validation, deployment, operation, and retirement.
Secure Disposal
Secure disposal removes sensitive data and components before reuse, transfer, or destruction.
Residual Risk
Residual risk remains after selected controls are implemented and assessed.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A web application places session tokens in URLs. What is the GREATEST architectural concern?
A database account used by a public application also has permission to create new database administrators. What change is MOST important?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
