Topic module

Architecture Models and Secure Design

Secure architecture questions test enterprise models, cloud responsibility, virtualization, embedded systems, network placement, and secure design principles.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

Architecture choices define trust boundaries, control placement, resilience, and operational visibility.

Exam cue: Identify the trust boundary and owner of the control.

Concept 2

Cloud models shift responsibilities between customer and provider depending on IaaS, PaaS, SaaS, and deployment model.

Exam cue: Map cloud responsibility before choosing a remediation.

Concept 3

Secure design principles include least privilege, defense in depth, fail secure, secure defaults, and separation of duties.

Exam cue: Use secure design principles to compare choices.

Risk pitfalls and guardrails

Assuming the cloud provider secures customer data configuration.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Placing controls where they cannot observe or enforce traffic.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Designing for convenience without separation of duties.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

Trust Boundary

A trust boundary marks where different levels of trust or responsibility meet.

Defense in Depth

Defense in depth layers controls so one failure does not expose the whole environment.

Fail Secure

Fail secure means a system defaults to a protected state when a failure occurs.

Secure Defaults

Secure defaults ship or deploy with safer settings enabled before customization.

Separation of Duties

Separation of duties splits sensitive tasks so no single person can complete risky actions alone.

IaaS

IaaS gives the customer more control over operating systems, applications, data, and configuration.

PaaS

PaaS gives the provider more platform responsibility while the customer manages applications and data.

SaaS

SaaS shifts most platform responsibility to the provider while the customer manages users, data, and settings.

Virtualization

Virtualization abstracts compute resources and requires host, guest, image, and management-plane protection.

Embedded System

An embedded system has purpose-built hardware or software and may need special patching and segmentation.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

Data crosses from a public web tier into an internal payment service with different security requirements. What should the design identify at that transition?

A company protects an application with secure coding, a WAF, network segmentation, MFA, and monitoring. Which architecture principle is demonstrated?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.