High School AdvancedA20 Module Test25 Questions

Advanced Capstone

A20 Module Test

This 25-question assessment checks the complete A20 capstone: Advanced knowledge integration, case briefing, architecture and threat modeling, detection and monitoring, incident response, cloud and identity, risk and privacy, executive communication, final portfolio submission, and Advanced readiness.

Choose the most defensible answer. All organizations, identities, services, records, alerts, risks, incidents, architecture, and evidence are fictional and synthetic. No real security testing or private information is required.

Readiness Check

Before You Start

0/4 ready

Assessment Coverage

What the 25 Questions Measure

Questions 1–2

A20.1 — Advanced Track Knowledge Review

Cross-domain reasoning, evidence-supported readiness, review by decision, and identifying weak concepts without relying on memorization alone.

Questions 3–5

A20.2 — Capstone Scenario Briefing

Mission, scope, stakeholders, assumptions, unknowns, evidence inventories, source limitations, fact-vs-hypothesis discipline, and decision framing.

Questions 6–8

A20.3 — Architecture and Threat Model Phase

Assets, trust boundaries, identities, dependencies, degraded states, control expectations, bounded threat statements, recovery paths, and design-vs-implementation evidence.

Questions 9–11

A20.4 — Detection and Monitoring Phase

Defensive questions, telemetry, source health, correlation, severity vs. confidence, safe validation, tuning, degraded visibility, and monitoring quality.

Questions 12–14

A20.5 — Incident Response Phase

Triage, scope, competing hypotheses, proportional containment, decision ownership, recovery criteria, closure, residual uncertainty, and reassessment triggers.

Questions 15–17

A20.6 — Cloud and Identity Review Phase

Shared responsibility, authentication vs. authorization, workforce and workload identities, privilege, lifecycle, federation, configuration governance, and recovery access.

Questions 18–20

A20.7 — Risk and Privacy Review Phase

Likelihood, impact, controls, inherent and residual risk, treatment, acceptance, privacy purpose, minimization, access, retention, lifecycle, and proportionality.

Questions 21–22

A20.8 — Executive Communication Phase

Materiality, confidence, audience adaptation, business impact, recommendations, ownership, tradeoffs, residual risk, and next checkpoints.

Questions 23–24

A20.9 — Final Portfolio Submission

Curation, traceability, cross-artifact consistency, revision history, contribution transparency, limitations, oral defense, and publication safety.

Question 25

A20.10 — Advanced Final Readiness Review

Integrated Advanced reasoning, targeted review, assessment strategy, evidence boundaries, and readiness based on applied scenario performance.

25-Question Assessment

A20 Advanced Capstone

Complete all 25 questions using the established CyberShield quiz controls. Answers and explanations remain hidden according to the shared component behavior until you submit or reveal your results.

Check Your Understanding

A20 Module Test: Advanced Capstone

Choose your answers first. Explanations appear only after submission.

1. A student can define least privilege, residual risk, and source health but struggles when one scenario combines all three. What is the strongest readiness conclusion?

2. Which self-review method best matches A20.1?

3. Why should a capstone begin with a case charter?

4. A privileged administrative action occurs during an approved maintenance window. What is the strongest briefing statement if exact task-level authorization is not yet available?

5. A monitoring source was delayed during part of the case. What should the evidence inventory record?

6. What makes a trust boundary security-relevant?

7. Which statement is the strongest bounded threat statement?

8. A recovery architecture shows current backups but older-than-preferred restoration evidence. What is the strongest conclusion?

9. What is the strongest starting point for detection design?

10. A synthetic alert has High severity and Moderate confidence. What does that mean?

11. Approved maintenance causes repeated false escalation because the alert lacks change context. What is the strongest tuning response?

12. Why should incident responders preserve competing hypotheses early in a case?

13. Which containment choice is strongest when evidence is incomplete but potential impact is meaningful?

14. Portal errors return to normal, but task authorization and monitoring validation remain open. What is the strongest response state?

15. What does cloud shared responsibility mean?

16. A privileged user authenticates successfully. What does that prove?

17. The worker service has a valid business purpose, but exact current permissions are not fully documented. What is the strongest finding?

18. What is residual risk?

19. A monitoring team wants to collect additional identity fields only because the platform makes them available. What is the strongest privacy response?

20. Which example best represents professional risk acceptance?

21. What should change when the same case is communicated to technical reviewers and executives?

22. Which executive recommendation is strongest?

23. What is the strongest way to organize the final A20 portfolio?

24. A technical artifact says the 09:11 action is unresolved, while an executive slide labels it unauthorized. What is the strongest portfolio correction?

25. A student scores well overall but repeatedly confuses workload identity purpose with proof of current authorization scope. What is the strongest final-readiness strategy?

Performance Guide

How to Interpret Your Result

23–25 correct

Excellent A20 readiness. You are applying the capstone's evidence, architecture, monitoring, response, governance, risk, privacy, recovery, and communication reasoning consistently.

20–22 correct

Strong A20 readiness. Review the few missed reasoning patterns, then make sure you can explain why the corrected answer is stronger than the alternatives.

17–19 correct

Developing A20 readiness. Use the targeted review map and return to the lessons connected to your missed cross-domain decisions.

13–16 correct

Partial A20 readiness. Rebuild the most important evidence boundaries and decision patterns before moving into full-track practice assessments.

0–12 correct

Foundation review recommended. Revisit A20.1–A20.10 in targeted groups and practice applying the concepts to new fictional scenarios before the full Advanced assessments.

Targeted Review Map

What to Review If You Missed a Topic

Missed A20.1 readiness questions

Review A20.1 and focus on review-by-decision, cross-domain relationships, evidence-supported readiness, limitations, and targeted study planning.

Missed A20.2 briefing questions

Review A20.2 and focus on mission, scope, evidence inventory, source limitations, assumptions, unknowns, exclusions, facts, hypotheses, and decision framing.

Missed A20.3 architecture questions

Review A20.3 and focus on trust boundaries, identities, dependencies, degraded states, bounded threat statements, design-vs-implementation evidence, and recovery paths.

Missed A20.4 monitoring questions

Review A20.4 and focus on defensive questions, telemetry, source health, severity vs. confidence, tuning, safe validation, degraded visibility, and monitoring metrics.

Missed A20.5 response questions

Review A20.5 and focus on competing hypotheses, proportional containment, ownership, decision history, recovery criteria, closure, and reassessment triggers.

Missed A20.6 cloud or identity questions

Review A20.6 and focus on shared responsibility, authentication vs. authorization, privileged and workload identities, lifecycle, federation, configuration governance, and recovery access.

Missed A20.7 risk or privacy questions

Review A20.7 and focus on likelihood, impact, controls, inherent vs. residual risk, treatment, acceptance, purpose, minimization, retention, lifecycle, and proportionality.

Missed A20.8 communication questions

Review A20.8 and focus on materiality, confidence, impact, recommendation structure, ownership, tradeoffs, residual risk, audience depth, and next checkpoints.

Missed A20.9 portfolio questions

Review A20.9 and focus on curation, traceability, cross-artifact consistency, revision history, contribution transparency, limitations, oral defense, and publication safety.

Missed A20.10 readiness question

Review A20.10 and focus on integrated Advanced reasoning, targeted review, evidence boundaries, cross-domain scenarios, and assessment strategy.

Defender Habits

A20 Module Mastery Checklist

Key Takeaways

What You Should Remember

1.The A20 capstone integrates the Advanced Track through evidence-aware, cross-domain defensive decision-making.
2.Facts, hypotheses, source health, architecture assumptions, control evidence, authorization, risk, privacy, recovery, and communication should remain distinguishable even when they influence one another.
3.Strong Advanced answers usually preserve uncertainty, respect source limitations, choose proportionate actions, assign ownership, and identify validation or review triggers.
4.Authentication does not prove authorization, design does not prove implementation, sequence does not prove causation, and missing alerts do not prove inactivity when source health is degraded.
5.Cloud, identity, monitoring, response, risk, privacy, recovery, governance, and executive communication should be treated as connected decision systems.
6.The strongest portfolio and assessment work is traceable, internally consistent, bounded by evidence, honest about contribution, and safe to share.
7.Use missed module-test questions to identify reasoning patterns rather than memorizing the exact wording of answers.
8.After A20 is verified and deployed, the Advanced Track can move to two 50-question practice tests and the 125-question final assessment.

Assessment Safety Boundary

Keep every A20 assessment scenario fictional, synthetic, defensive, and non-operational

This assessment does not authorize access, scanning, probing, exploitation, credential testing, bypass, evasion, monitoring of real people, collection of real logs, cloud-account access, configuration changes, incident investigation, or review of real private systems. Use only CyberShield Academy materials and synthetic evidence.

A20 Complete

Advanced Capstone Module Complete

After reviewing your result, revisit any weak A20 lesson and update your Advanced Final Readiness Plan. Your completed A20 outcome is the Advanced Capstone Portfolio Submission and Final Readiness Review Pack, connecting the full Advanced Track through evidence-based defensive reasoning.