TB.

Security+ SY0-701 · Domain 3

Domain 3: Security Architecture

Why This Domain Matters

Domain 3 covers network and system architecture — firewalls, VPNs, segmentation, high availability, DMZs — plus modern vocabulary like cloud responsibility matrices, IaC, SASE, and SD-WAN, and data-classification language close to what regulated and legal-sector organizations deal with day to day.

Treat this domain as learn-from-scratch with occasional déjà vu even with prior networking exposure: half-remembered networking is more dangerous on exam day than none, because the distractors are built to catch it.

Before starting this domain, work through the networking primer to rebuild IP addressing, ports, and VLAN fundamentals — then study every section here fully.

Objective-by-Objective Breakdown

3.1 Architecture Models

Cloud — the shared responsibility matrix shifts by service model: in IaaS you own the OS, applications, and data while the provider owns physical infrastructure and the hypervisor; in PaaS the provider also manages the OS/runtime, leaving you the application and data; in SaaS the provider manages nearly everything except your data and who has access to it.

Hybrid architectures raise their own issues:

  • identity federation between environments
  • consistent policy enforcement across the boundary
  • data synchronisation

Third-party vendors extend your trust boundary (and your risk) into whatever the vendor does with your data.

IaC (infrastructure as code) defines infrastructure through version-controlled templates rather than manual configuration — consistent, repeatable, reviewable before deployment, but a misconfiguration or embedded secret now replicates at scale instead of on one box.

Serverless (FaaS) runs code without you managing the underlying server — shrinks OS-patching responsibility but shifts it to correctly scoping each function's permissions.

Microservices break an application into small, independently deployable services talking over APIs — smaller blast radius per service, but many more API endpoints to secure. [All three: NEW.]

Network infrastructure:

  • physical isolation/air-gapped: no network path at all between systems — the strongest segmentation available, used for ICS/SCADA
  • logical segmentation: VLANs and subnets — dividing one physical network into separate broadcast/security domains in software; devices in different segments can't talk without crossing a routing/filtering point
  • SDN: software-defined networking — the decision-making "control plane" is centralised in a software controller, while switches just forward packets; this makes network-wide policy changes programmable from one place

On-premises vs. cloud, centralized vs. decentralized administration is a cost/control trade-off common in the field.

Containerization (OS-level virtualisation sharing the host kernel — lightweight, fast to deploy, but a kernel-level escape affects every container on the host) vs. virtualization (full VMs, each with its own OS under a hypervisor — heavier, but a stronger isolation boundary).

IoT, ICS/SCADA (industrial control systems prioritising availability of a physical process over confidentiality, frequently unpatchable without shutting down production), RTOS (an OS guaranteeing processing within a fixed time window, used where timing failure is itself a safety issue), and embedded systems (purpose-built, fixed-function, resource-constrained, often unpatched for the device's entire life) — the unifying idea, "this thing can't take a Defender agent," will feel familiar from supporting any legacy hardware in the field.

High availability — designing for continuous operation through redundancy, so no single component failure takes the service down.

Considerations checklist (the exam's favourite trade-off framing across every model above): availability, resilience, cost, responsiveness, scalability, ease of deployment, risk transference (shifting risk to a third party — e.g., insurance or a cloud provider's SLA), ease of recovery, patch availability, inability to patch, power, and compute.

Any architecture question can be reframed as "which of these twelve did the stem just describe?"

3.2 Secure Enterprise Infrastructure

A typical segmented network — public traffic never reaches the internal LAN directly

Infrastructure considerations: device placement and security zones — a security zone is a network segment with one trust level; the classic three are the internet (untrusted), the internal LAN (trusted), and the DMZ/screened subnet between them, where public-facing servers live so a compromise there doesn't reach the internal network.

Attack surface (everything reachable — minimise by killing unused services), connectivity, and failure modes: fail-open (allows traffic through on failure — prioritises availability) vs. fail-closed (blocks traffic on failure — prioritises confidentiality/integrity).

Device attribute: active (can act on traffic — e.g., block it) vs. passive (only observes), and separately inline (physically sits in the traffic path) vs. tap/monitor (receives a mirrored copy of traffic, out of path).

These two pairs usually travel together — an IPS is active+inline, a tap-fed IDS is passive+monitor — but the exam can test either dimension alone, so don't treat them as one concept.

Network appliances:

  • jump server: hardened intermediary for admin access into a more sensitive zone, keeping your credentials off that segment directly
  • proxy server: forward proxy filters/anonymises outbound client requests; reverse proxy sits in front of servers
  • IPS/IDS: prevention = inline+active+blocks; detection = passive+alerts only
  • load balancer: distributes traffic across multiple servers for performance/availability
  • sensors: telemetry collection feeding monitoring/SIEM

Learn each appliance's one-line role — "which appliance goes here?" questions are common.

Port security: 802.1X (port-based network access control — a device plugged into a switch port or joining Wi-Fi gets no network access at all until it authenticates) and EAP (the authentication framework 802.1X rides on, with multiple certificate- or credential-based methods).

Memorise the pairing:

  • 802.1X is the gate
  • EAP is how you prove yourself at the gate
  • RADIUS is the server checking your proof

Firewall types: a Layer 4 firewall filters on IP address, port number, and protocol — it can see where traffic is going but not what's inside it. A Layer 7 firewall inspects the application-layer content itself — the actual HTTP request, the actual file.

WAF is a Layer-7-only firewall purpose-built to protect web applications from web attacks (SQLi, XSS). UTM bundles several security functions (firewall, IPS, AV, content filtering) into one appliance under one console — convenient, but a single point of failure.

NGFW is the modern enterprise standard:

  • Layer 7-aware
  • application- and identity-aware
  • integrated IPS

Secure communication/access: a VPN creates an encrypted tunnel over an untrusted network so remote traffic is protected in transit.

Two tunneling families to study properly: TLS (the encryption behind HTTPS, also used for user-friendly remote-access VPNs) and IPsec (network-layer encryption for site-to-site and client VPNs — know that it has two modes: tunnel mode encrypts the whole original packet, transport mode encrypts only the payload).

SD-WAN centralises control of an organisation's wide-area links with application-aware routing and built-in security functions at the WAN edge, replacing branch-office hardware firewalls.

SASE is the cloud-delivered convergence of SD-WAN networking with a security stack (secure web gateway, CASB, ZTNA, firewall-as-a-service) for a distributed workforce — a favourite exam term for modern architecture questions.

Selection of effective controls always comes back to the 3.1 considerations checklist matched against the asset being protected — cost and ease of deployment matter as much as raw security strength.

3.3 Data Protection Concepts and Strategies

Data types: regulated (governed by specific law — e.g., health or financial privacy legislation), trade secret, intellectual property, legal information (privileged communications, case files, legal work product — the kind of data legal and professional-services organizations exist to protect), financial information, human-readable (plain text, directly understandable) vs. non-human-readable (binary/encoded, needs processing to interpret).

Classifications are organisation-defined labels, not one universal ladder:

  • sensitive
  • confidential
  • public
  • restricted
  • private
  • critical

In practice, client case files and privileged legal correspondence sit at the "restricted/confidential" end regardless of which exact label scheme a stem uses — expect scenario questions to hand you a label and ask what control it implies, not to ask you to rank the six labels against each other.

General considerations:

  • data states — at rest: stored; protect with encryption and permissions
  • in transit: moving across a network; protect with TLS/IPsec/VPN
  • in use: actively processed in memory — the hardest state to protect

Data sovereignty (data is subject to the laws of whatever country it physically resides in) and geolocation (knowing/verifying/restricting based on physical location — the mechanism that enforces sovereignty).

Methods:

  • geographic restrictions: geofencing access/storage
  • encryption: reversible with a key
  • hashing: one-way, for integrity — not reversible
  • masking: hides part of the data while preserving format, e.g., showing only the last four digits
  • tokenization: swaps sensitive data for a non-sensitive token, with the real value stored separately in a secure vault/lookup
  • obfuscation: broader term — deliberately making data or code hard to interpret
  • segmentation: isolating data/systems to limit exposure
  • permission restrictions: least-privilege access control on the data itself

3.4 Resilience and Recovery in Security Architecture

High availability: load balancing distributes live traffic across multiple active, largely independent nodes for performance and uptime; clustering joins multiple servers into a single logical system with shared state, so one node can take over for a failed peer. See Confusables.

Site considerations:

  • hot site: fully operational duplicate, ready to take over almost immediately — highest cost
  • warm site: partially equipped, some systems/data preloaded, needs extra setup before it's live — moderate cost
  • cold site: bare infrastructure only — power, space, connectivity — nothing preloaded, longest time to operational, lowest cost

Geographic dispersion spreads sites across regions so one disaster (flood, cyclone — relevant living in Darwin) can't take out every site at once.

Platform diversity (different vendors/technology for redundant systems, so one vulnerability doesn't take down every instance), multi-cloud (spreading across providers to avoid single-vendor lock-in/outage exposure), continuity of operations (keeping essential functions running through a disruption), capacity planning across people (trained staff available during an event), technology (systems sized to absorb failover load), and infrastructure (physical facilities/power/network headroom).

Testing:

  • tabletop exercise: discussion-based walkthrough, no systems touched — cheapest, most frequent
  • failover test: actually triggers the failover to validate it works
  • simulation: a realistic mock scenario, more interactive than tabletop, short of a full cutover
  • parallel processing: recovery system runs alongside production simultaneously to validate correct output without cutting production over

Backups:

  • onsite (fast recovery, same-location risk) vs. offsite (protects against a site-wide event)
  • frequency: how often — drives how much data you can lose
  • encryption: protecting the backup itself
  • snapshots: point-in-time capture of a volume/system state
  • recovery: the restore process
  • replication: continuous copying of data to another location/system, near real time
  • journaling: logging every change/transaction so recovery can replay forward from a snapshot to an exact point rather than losing everything since the last one

Power: generators (fuel-based, sustain operations through a prolonged outage) and UPS (battery-based, bridges the short gap until generator power kicks in or enables a graceful shutdown).

Confusables — Don't Mix These Up

Fail-Open vs. Fail-Closed

TermWhat happens on device failurePriorityExam tell
Fail-openTraffic is allowed throughAvailability over security"Business operations continued uninterrupted after the device failed"
Fail-closedTraffic is blockedSecurity/confidentiality over availability"All traffic stopped when the device went offline"

Inline/Tap vs. Active/Passive

DimensionOption AOption BKey point
Path positionInline — physically in the traffic pathTap/monitor — receives a mirrored copy, out of pathInline traffic must physically traverse the device; tapped traffic is a copy
BehaviourActive — can act on traffic (block/alter)Passive — can only observeThese two dimensions usually pair (IPS = inline+active; tap-fed IDS = passive+monitor) but the exam can test either alone

WAF vs. UTM vs. NGFW vs. Layer 4/Layer 7 Firewall

TermWhat it isKey differentiatorExam tell
Layer 4 firewallFilters on IP/port/protocolStateful, no application awareness"Filters based on source/destination IP and port"
Layer 7 firewallFilters on application-layer contentUnderstands the application protocol itself"Inspects the actual HTTP request/content"
WAFAn L7 firewall purpose-built for web appsProtects specifically against web attacks (SQLi, XSS)"Protects a web application from injection attacks"
UTMMultiple security functions bundled in one applianceConvenience/single management pane; single point of failure"All-in-one security appliance"
NGFWModern L7-aware firewall with integrated IPS/identity awarenessEnterprise-grade application- and identity-aware inspection"Application-aware next-generation firewall with built-in IPS"

Hot vs. Warm vs. Cold Site

TermReadinessCostTime to operational
Hot siteFully operational duplicateHighestNear-immediate
Warm sitePartially equipped, some data/systems preloadedModerateRequires additional setup
Cold siteBare infrastructure only (power, space, connectivity)LowestLongest

Load Balancing vs. Clustering

TermWhat it doesKey differentiatorExam tell
Load balancingDistributes live traffic across multiple nodesNodes are largely independent, goal is distributing work"Traffic is spread evenly across several servers"
ClusteringJoins servers into one logical system with shared stateGoal is failover — one node takes over for a failed peer"If one node fails, another automatically takes over the workload"

Snapshot vs. Replication vs. Journaling

TermWhat it capturesKey differentiatorExam tell
SnapshotPoint-in-time image of a system/volumeA single frozen moment; restoring returns you to that moment only"Point-in-time capture before the change was made"
ReplicationContinuous copy of data to another location/systemOngoing, near real time; no single frozen point"Data is continuously mirrored to a secondary site"
JournalingLog of every individual change/transactionEnables replay to an exact point beyond the last snapshot"Transactions were replayed from the log to the moment of failure"

Exam Traps

  • Fail-open vs. fail-closed — the stem describes an outcome after failure, not a normal operating state. If traffic kept flowing after the device died, that's fail-open, even if the same device blocks aggressively when healthy.
  • Inline/tap and active/passive are two separate dimensions — don't assume "passive" always means "tap" or "active" always means "inline." They usually pair, but the objective lists them separately for a reason.
  • WAF is not a general-purpose firewall — it operates at Layer 7 specifically for web application traffic; don't pick it for a stem describing generic network perimeter filtering.
  • UTM's weakness is its strength — bundling everything into one box is convenient but creates a single point of failure; if a stem highlights that trade-off, it's pointing at UTM.
  • Hot/warm/cold is a spectrum of readiness and cost, not just speed — a warm site question will often test the "some systems/data preloaded, still needs setup" middle ground, which is the option most likely to be miscategorised as hot or cold.
  • Load balancing ≠ clustering — load balancing is about distributing ongoing work; clustering is about failover continuity. A stem about "even traffic distribution" is load balancing even if it also improves availability.
  • Data sovereignty is a legal consequence of geolocation, not a synonym for it — geolocation is the mechanism (knowing/restricting by physical location); sovereignty is the legal exposure that follows from where the data actually sits.
  • Tokenization vs. masking vs. encryption — masking only hides part of the value for display (format-preserving, not necessarily reversible by design); tokenization fully substitutes the value with a token whose real data lives elsewhere in a vault; encryption is mathematically reversible with the correct key. Don't treat these as interchangeable "hide the data" answers.

Acronym Table

AcronymExpansionOne-line meaning
IaCInfrastructure as CodeManaging infrastructure through version-controlled templates/scripts
SDNSoftware-Defined NetworkingCentralises the network control plane in a software controller
ICSIndustrial Control SystemSystems managing physical industrial processes
SCADASupervisory Control and Data AcquisitionA type of ICS for monitoring/controlling distributed industrial processes
RTOSReal-Time Operating SystemAn OS guaranteeing processing within a fixed time constraint
WAFWeb Application FirewallLayer 7 firewall purpose-built to protect web applications
UTMUnified Threat ManagementSingle appliance bundling multiple security functions
NGFWNext-Generation FirewallApplication- and identity-aware firewall with integrated IPS
EAPExtensible Authentication ProtocolAuthentication framework used within 802.1X
TLSTransport Layer SecurityProtocol encrypting data in transit
IPsecInternet Protocol SecuritySuite securing IP traffic via AH/ESP, tunnel or transport mode
SD-WANSoftware-Defined Wide Area NetworkCentrally managed, application-aware routing across WAN links
SASESecure Access Service EdgeCloud-delivered convergence of SD-WAN and security services
UPSUninterruptible Power SupplyBattery power bridging a short outage or graceful shutdown

Drills: 20 flashcards + 10 exam-realistic questions, at the end of this page.

Interactive drills

Flashcards

Click a card to flip it, then rate how well you knew it — cards you rate lower come back sooner. 20 cards from real study drills, scheduled with spaced repetition.

Due today: 20

Flipped: 0/20

Quiz

10 exam-style questions, easy to hard. Pick an option to see whether you're right, and why.

Score: 0/9

Q1EasyWhich cloud service model leaves the provider responsible for managing the operating system and runtime, while the customer is responsible only for the application and its data?

Q2EasyWhich architecture pattern breaks an application into small, independently deployable services that communicate with each other over APIs?

Q3EasyAn industrial control network has no physical connection point to any other network. What is this architecture called?

Q4MediumA security appliance sits directly in the traffic path and is capable of blocking malicious packets in real time before they reach the destination. Which two attributes describe this appliance?

Q5MediumA perimeter firewall fails due to a power event, and all traffic that would normally pass through it is immediately blocked until the firewall is restored. Which failure mode is this?

Q6Mediumthe organization's case management system stores privileged client communications and legal work product. Which SY0-701 data type applies most specifically?

Q7MediumWhich network appliance provides a hardened, tightly controlled intermediary host that administrators use to reach systems in a more sensitive security zone, without exposing their credentials directly to that zone?

Q8MediumAn organisation wants to converge SD-WAN routing with cloud-delivered security services (secure web gateway, CASB, ZTNA) into a single service for its distributed remote workforce. Which architecture best fits?

Q9Hard, PBQ — appliance placement

A network diagram shows this layout: Internet → [Position 1] → DMZ (containing a public-facing web server) → [Position 2], directly in front of that web server → Internal LAN (case management servers) → [Position 3] → an isolated ICS segment with no other path in.

Match each position to the correct appliance: A) NGFW B) WAF C) Jump server D) Load balancer

Q10Hard, PBQ — recovery sequencingA database server crashes at 14:32. The recovery team has a snapshot taken at 14:00, a continuous transaction journal recording every change up to the crash, and an asynchronously replicated copy at the DR site lagging about 5 seconds behind. Which sequence minimises data loss and restores the most complete state?