StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 3: Security architecture & engineering

Vulnerabilities in architectures: client, server, database, cloud, IoT, ICS/OT, virtualization, containers, serverless

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Every architecture has characteristic weak spots. The exam describes an environment and expects you to recognize its typical vulnerabilities and matching mitigations. The underlying lesson is to understand where trust lives, where trust boundaries sit and where attackers can abuse them. You will not be asked for exploit details; you will be asked which weakness fits the scenario and which control best reduces it.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan