StudyToCert

All certifications / CySA+ / Lessons

CompTIA CySA+ CS0-004 · Domain 1: Security operations

System and network architecture: on-prem, cloud, hybrid, serverless, containers, segmentation, zero trust, SASE

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

As a security analyst you defend whatever architecture the organization actually runs, and each model changes three things you care about: where your logs come from, who is responsible for which controls, and how far an attacker can move after getting in. The CySA+ exam expects you to recognize the common models and reason about their security trade-offs rather than configure them in detail. When a scenario describes an environment, your first job is to picture where the data lives, who manages each layer and which telemetry you can realistically collect.

identity · device health · threat intelPolicy enginedecides grant/denyPolicy adminsets up sessiontogether: policy decision pointControl planeData planeallow / denySubjectuser + devicePEPgatewayResourceapp, dataEvery request is checked;location grants no trust
Zero trust architecture: policy engine, administrator and PEP

An on-premises (on-prem) environment is one where the organization owns the hardware, the network and the data center, so it also owns every layer of security, from physical locks to patching. Cloud environments split that work under the shared responsibility model: the provider secures the underlying facilities, hardware and virtualization, while the customer always remains responsible for its data, identities, access policies and configuration. How much else the customer handles depends on the service model. Infrastructure as a Service (IaaS) leaves the operating system and everything above it to you, Platform as a Service (PaaS) hides the operating system, and Software as a Service (SaaS) leaves you mainly with accounts, data and settings. A hybrid environment mixes on-prem and cloud, which usually means two sets of controls, two logging pipelines and identity that has to be synchronized between them.

Serverless computing, such as functions that run only when an event triggers them, removes the server you would normally harden. You cannot install an agent on it, so visibility comes from the provider's logs, and the main risks move to overly broad permissions on the function's role, untrusted event input and vulnerable code dependencies. Containers package an application with its libraries and share the host's kernel. They start quickly and are easy to replace, but a vulnerable base image gets copied everywhere, a container running with excessive privileges can threaten its host, and short-lived containers may vanish before you collect evidence. Image scanning, minimal base images, non-root containers and logging from the orchestration platform are the usual controls.

Segmentation divides a network into zones so that a compromise in one zone does not give access to everything. It can be done with virtual local area networks (VLANs) and firewalls between them, with a screened subnet, also called a demilitarized zone (DMZ), for internet-facing servers, or with microsegmentation, which applies policy down to individual workloads. Zero trust goes further and drops the idea that anything inside the perimeter is trustworthy. Every request is authenticated, authorized and evaluated in context (user, device health, location, sensitivity of the resource) each time, with least privilege. The architecture separates a control plane, where a policy engine and policy administrator decide, from a data plane, where policy enforcement points allow or block traffic. Secure Access Service Edge (SASE) delivers networking and security as a cloud service close to the user, combining software-defined wide area networking (SD-WAN) with a secure web gateway, a cloud access security broker, firewall as a service and zero trust network access (ZTNA).

Consider a worked example. A retailer moves its web store to containers in a public cloud while payroll stays in the on-prem data center, connected by a site-to-site virtual private network (VPN) that allows all traffic. During a review you notice that a compromised container could reach the payroll database directly across that tunnel. Your recommendations follow the models above: restrict the tunnel so only the one application programming interface (API) port the store needs is allowed, run containers as non-root from a scanned minimal image, send orchestration and cloud audit logs to the security information and event management (SIEM) system, and put administrator access to both environments behind a zero trust access broker that checks user identity and device health.

Common mistakes: assuming the cloud provider is responsible for customer data or misconfigured storage (it never is); treating a VPN as zero trust, when a traditional VPN grants broad network access once connected; thinking segmentation alone stops attackers, when it only limits where they can go and makes cross-zone traffic visible; and forgetting that serverless and container workloads need different visibility, because you cannot simply install the usual endpoint agent everywhere. Another trap is confusing SASE, which is an architecture delivered from the cloud, with a single product such as a firewall.

Exam questions usually describe an environment and ask for the best fit. Clue words such as 'remote users, cloud applications, no central office, combined networking and security delivered from the cloud' point to SASE. 'Never trust, always verify', 'continuous verification' or 'regardless of network location' point to zero trust. 'Limit lateral movement between workloads' points to microsegmentation. 'Who is responsible for the guest operating system in IaaS' is the customer. 'Cannot install an agent' and 'event-driven code' point to serverless, and 'vulnerable base image' points to containers.

Key terms

Shared responsibility model
The division of security duties between a cloud provider, which secures the underlying infrastructure, and the customer, which secures its data, identities and configuration.
Serverless
A cloud model where code runs only when triggered and the provider manages all servers, so security focuses on permissions, inputs and dependencies.
Container
A lightweight package of an application and its libraries that shares the host operating system kernel.
Microsegmentation
Applying security policy between individual workloads rather than only between large network zones.
Zero trust
A model that verifies every access request in context and grants least privilege, regardless of network location.
Policy enforcement point
The zero trust component in the data plane that allows or blocks a connection based on the policy engine's decision.
SASE
Secure Access Service Edge, a cloud-delivered combination of SD-WAN and security services such as secure web gateway, CASB, firewall as a service and ZTNA.
Real-world example

A retailer runs its web store in cloud containers and payroll on-prem, joined by a VPN that allows any traffic. An analyst finds that a compromised container could reach the payroll database. The team restricts the tunnel to one API port, rebuilds images from a minimal scanned base running as non-root, forwards orchestration and cloud audit logs to the SIEM, and requires a zero trust broker with device checks for all admin access.

Exam tip: If a scenario stresses remote users and cloud apps with networking and security delivered from the cloud, choose SASE. If it stresses verifying every request regardless of location, choose zero trust. The customer always owns data and configuration in the cloud.

Check yourself

In an IaaS deployment, who is responsible for patching the guest operating system?

The customer, because in IaaS the provider secures only the physical infrastructure and virtualization layer.

Why is visibility harder for serverless functions than for virtual machines?

There is no server you manage, so you cannot install an endpoint agent and must rely on the provider's logs and the function's own logging.

What does microsegmentation add beyond VLAN-based segmentation?

It enforces policy between individual workloads, limiting lateral movement even between systems in the same zone.

A company wants SD-WAN, secure web gateway and ZTNA delivered as one cloud service for a remote workforce. What is this called?

Secure Access Service Edge (SASE).

Study CySA+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CySA+ study plan