Asterrr's Handbook

Domain 3 · Infrastructure security

18% of the exam. Putting the right control at each layer, from the edge through the network to the workload, without opening more access than the requirement needs.

Domain 3 questions give you a workload and a threat (a bot swarm, an exposed port, an unpatched AMI, a prompt injection) and ask which control stops it at the right layer with the least operational effort. Most wrong answers are real controls placed at the wrong layer: a security group asked to inspect HTTP, or WAF asked to filter egress.

TaskWhat it's really askingPages
3.1 Network edge servicesFilter and absorb bad traffic before it reaches the origin: WAF, Shield, CloudFront, CORS, IoT policiesEdge protection
3.2 Compute workloadsHarden images, give workloads the right role, find and patch vulnerabilities, remove SSH, scan in the pipeline, guard GenAI appsCompute hardening, Vulnerability and patch management, Generative AI guardrails
3.3 Network security controlsPermit or block flows, connect hybrid networks securely, segment, and prove there's no unintended pathNetwork controls, Hybrid and private access, Segmentation and analysis

Layers and their controls

  • Edge stops volumetric and layer 7 abuse closest to the attacker, where capacity is largest.
  • Network decides which flows may exist at all, both north/south (in and out of the VPC) and east/west (between workloads).
  • Compute assumes something will get through, so it limits what an attacker can do on the host and how long a known flaw stays unpatched.

Exam signal

Look for the layer word in the question. "SQL injection", "User-Agent", "requests per IP" point at WAF. "Domain allow list for outbound traffic" points at Network Firewall or DNS Firewall. "No inbound ports, no bastion" points at Session Manager or EC2 Instance Connect Endpoint. "Unintended network path across many VPCs" points at Network Access Analyzer.

Detection is not prevention

GuardDuty, Inspector and Network Access Analyzer find problems. They don't block anything by themselves. If the question asks to prevent or block, the answer is a control (WAF rule, firewall rule, security group, SCP) or an automated response wired to the finding. See Automated response.

On this page