Overview

Domain 3 covers the design and implementation of secure network architectures, cryptographic solutions, and resilient infrastructure. At 18% of the exam, it bridges the gap between theoretical concepts (Domain 1) and operational practices (Domain 4), focusing on how security is built into systems and networks.

Exam Weight

18% — approximately 16-17 questions out of 90.

Topics

TopicNoteKey Focus
Network Security Architecturenetwork-security-architectureDMZ, screened subnet, east-west traffic
FirewallsfirewallsNGFW, stateful/stateless, WAF, ACLs
IDS/IPSids-ipsSignature-based, anomaly-based, inline vs. passive
VPNvpnIPSec, SSL/TLS VPN, split vs. full tunnel
Network Segmentationnetwork-segmentationVLANs, microsegmentation, air gaps
Load Balancers & Proxiesload-balancers-and-proxiesReverse proxy, forward proxy, load balancing
NACnac802.1X, agent/agentless, posture assessment
Cloud Securitycloud-securityIaaS/PaaS/SaaS, shared responsibility, CASB
Virtualization Securityvirtualization-securityVM sprawl, escape, hypervisor security
Serverless & Containersserverless-and-containersContainer security, orchestration, FaaS
Infrastructure as Codeinfrastructure-as-codeTerraform, Ansible, immutable infrastructure
EncryptionencryptionSymmetric, asymmetric, AES, RSA, ECC
PKIpkiCertificate authorities, trust chains
CertificatescertificatesX.509, SAN, wildcard, certificate pinning
HashinghashingSHA-256, MD5, HMAC, salting
Key Managementkey-managementKey escrow, rotation, HSM, TPM
Data Protectiondata-protectionEncryption at rest/in transit/in use, tokenization
DLPdlpData loss prevention, endpoint/network/cloud DLP
Embedded Systems Securityembedded-systems-securitySCADA, IoT, RTOS, constraints
Resilience & Redundancyresilience-and-redundancyRAID, clustering, geographic dispersal, RPO/RTO

Cross-Domain Connections