High School AdvancedA12 Module Test25 Questions

Module A12 Assessment

Cloud Security Architecture — Module Test

Test your ability to reason across cloud shared responsibility, identity, storage, network boundaries, logging and monitoring, secrets, recovery, misconfiguration prevention, and governance.

All scenarios are fictional and defensive. The test focuses on architecture judgment, evidence quality, ownership, and safe security decision-making.

Readiness Check

A12 Module Test Readiness

0/4 ready

Test Coverage

What the 25 Questions Measure

A12.1

Shared Responsibility

Provider-operated capabilities, customer-owned configuration, shared outcomes, ownership, accountability, and evidence boundaries.

Review emphasis

Know why shared responsibility should clarify ownership instead of making responsibility vague.

A12.2

Cloud IAM Architecture

Human identities, workload identities, least privilege, privileged access, external access, separation of duties, lifecycle, and access evidence.

Review emphasis

Know why private network location does not replace identity and why workload identity is preferred where practical.

A12.3

Storage Security and Data Exposure

Data classification, public/private exposure, access scope, retention, encryption responsibilities, copies, backups, lineage, and ownership.

Review emphasis

Know why encryption alone does not prove storage security and why secondary copies expand the protected data boundary.

A12.4

Cloud Network Boundaries

Public ingress, private service paths, partner connectivity, administrative access, egress, environment separation, trust boundaries, and monitoring.

Review emphasis

Know why public exposure should be limited and why internal/private network placement is not the same as authorization.

A12.5

Cloud Logging and Monitoring

Telemetry domains, source health, identity context, configuration changes, data access, alerting, retention, evidence quality, and visibility gaps.

Review emphasis

Know the difference between no-event and no-source states.

A12.6

Secrets and Key Handling

Workload identity, managed secret references, service credentials, key references, certificates, emergency access, rotation, revocation, environment separation, and retirement.

Review emphasis

Know why architecture documentation should use safe metadata and never secret values.

A12.7

Backup, Recovery, and Resilience

Availability, redundancy, backup, restoration, recovery, RTO, RPO, dependencies, failure domains, recovery ownership, and current exercise evidence.

Review emphasis

Know why healthy backups do not automatically prove full service recovery.

A12.8

Cloud Misconfiguration Prevention

Secure baselines, desired vs. observed state, drift, preventive guardrails, detective controls, exceptions, remediation, and closure evidence.

Review emphasis

Know why configuration assurance is continuous and why a valid exception remains different from the preferred baseline.

A12.9–A12.10

Cloud Governance

Policy, standards, ownership, service inventory, risk acceptance, review cadence, evidence, lifecycle, architecture decisions, blockers, and release recommendations.

Review emphasis

Know why unowned risk should not be silently accepted and why finding impact matters more than a simple majority of passing controls.

Assessment

25-Question A12 Module Test

Work through all 25 questions before reviewing explanations. Focus on what the evidence actually supports and which architecture decision is most defensible.

Check Your Understanding

A12 Cloud Security Architecture Module Test

Choose your answers first. Explanations appear only after submission.

1. Which statement best describes cloud shared responsibility?

2. A provider encrypts a managed storage platform by default. What does the customer still need to own?

3. Which is the strongest IAM design for a production application calling a managed database?

4. Why should privileged cloud access be treated differently from normal workforce access?

5. Which statement best describes a secure cloud storage review?

6. Why should backup repositories be included in the protected data boundary?

7. When can public cloud storage be appropriate?

8. What is a cloud trust boundary?

9. Why is a private network path not enough to prove application access is authorized?

10. What is the strongest design for a cloud partner integration?

11. Why is outbound egress part of cloud security architecture?

12. A dashboard shows zero suspicious storage events, but the storage log source stopped reporting six hours ago. What is the correct conclusion?

13. What should an actionable cloud security alert include?

14. Why should security logs avoid secret values and unnecessary sensitive payloads?

15. Which is the strongest way to represent a cloud secret in architecture documentation?

16. A production service credential has no owner, overdue rotation, and no documented revocation path. What status is most appropriate?

17. What does Recovery Time Objective (RTO) describe?

18. What does Recovery Point Objective (RPO) describe?

19. Why does a successful backup job not prove full service recovery?

20. A recovery exercise passed 10 months ago, but the architecture changed significantly afterward. What is the strongest conclusion?

21. What is configuration drift?

22. What makes a cloud configuration exception well-governed?

23. What is the main difference between a policy and a standard?

24. What is required for a strong residual-risk acceptance?

25. A cloud architecture review has 20 strong controls but two unowned production blockers. What is the strongest release decision?

Performance Guide

Interpret Your Result

21–25 correct

Strong A12 readiness. You can connect cloud architecture domains and reason from evidence, ownership, lifecycle, and governance.

Next action: Review any missed questions, then proceed to A13.

17–20 correct

Good working understanding with a few architecture gaps.

Next action: Use the targeted review map below for the missed domains before moving on.

13–16 correct

Partial understanding. You recognize many concepts but may be treating domains too independently.

Next action: Revisit A12.5–A12.10 and any earlier domain where you missed multiple questions.

0–12 correct

Rebuild the architecture model before continuing.

Next action: Review the full A12 module from shared responsibility through the capstone, focusing on why each control exists and what evidence supports it.

Targeted Review Map

Use Missed Questions to Find the Right Lesson

MissesLessonTopicRevisit
Questions 1–2A12.1Shared responsibilityProvider vs. customer responsibility, customer configuration, ownership, and evidence boundaries.
Questions 3–4A12.2Cloud IAMWorkload identity, least privilege, privileged access, lifecycle, and ownership.
Questions 5–7A12.3Storage securityClassification, exposure, copies, retention, encryption responsibilities, backup sensitivity, and public-content decisions.
Questions 8–11A12.4Network boundariesTrust boundaries, private vs. authorized access, partner connectivity, egress, and environment separation.
Questions 12–14A12.5Logging and monitoringSource health, no-event vs. no-source, alert context, retention, and sensitive-data minimization.
Questions 15–16A12.6Secrets and key handlingSafe metadata, workload identity, ownership, rotation, revocation, environment separation, and retirement.
Questions 17–20A12.7Recovery and resilienceRTO, RPO, backup vs. recovery, current restoration evidence, dependencies, and failure domains.
Questions 21–22A12.8Misconfiguration preventionBaseline, observed state, drift, exceptions, compensating controls, remediation, and closure evidence.
Questions 23–25A12.9–A12.10Governance and architecture decisionsPolicy vs. standard, risk acceptance, decision authority, blockers, release criteria, and evidence-based recommendations.

Defender Habits

A12 Final Readiness Checklist

Key Takeaways

What You Should Remember

1.Cloud security architecture is a connected system of responsibility, identity, data, networks, monitoring, secrets, resilience, configuration, and governance.
2.Provider capabilities do not remove customer responsibility for configuration, ownership, evidence, and risk decisions.
3.Private networking and encryption are useful controls but do not replace identity, authorization, lifecycle, or governance.
4.Monitoring confidence depends on source health as well as event content.
5.Architecture records should never expose real secret values.
6.Backup health and recovery readiness are different claims.
7.Configuration assurance is continuous because cloud state changes after deployment.
8.Exceptions should be bounded, owned, time-limited, and connected to a target state.
9.Residual risk requires explicit decision authority and review.
10.Architecture release decisions should be based on evidence and finding impact, not a simple count of passing controls.

Module Complete

A12 — Cloud Security Architecture Complete

You have completed the A12 module homepage, all ten Advanced lessons, the Cloud Security Architecture Assessment capstone, and the 25-question module test.

The next Advanced module is A13 — Identity, Zero Trust, and Access Control.

Safety Boundary

This assessment is defensive and fictional

Do not use these questions as instructions to access, probe, configure, modify, restore, or test real cloud accounts, networks, storage, credentials, logs, backups, or production services. All scenarios are designed for safe architecture learning.