Architecture Lab

Secure Architecture Builder

Design production-grade infrastructure with Zero Trust controls baked in. Each scenario presents a real architecture decision — VPC layout, WAF placement, secret stores, region failover — and asks you to pick the design that holds up under attack.

6 scenarios~20 minutesHard
RUNHard

How the simulator works

  • Each scenario shows a system architecture and a specific design question.
  • Choose the most secure design from four plausible options — the wrong answers explain why they look reasonable but introduce risk.
  • Read the production explanation, follow the link to the relevant lesson, and move to the next scenario.
  • Score yourself across all six rounds — covering network segmentation, WAF placement, bastion vs IAM, secret stores, CDN auth, and multi-region resilience.