Identity, Zero Trust, and Access Control
A13 Module Test
This 25-question assessment checks whether you can connect identity perimeter, zero trust, federation, conditional access, RBAC/ABAC, privileged access, monitoring, governance, and usability into one defensible access-control model.
Answer from the defensive architecture concepts taught in A13. The quiz hides answers until you reveal them through the existing CyberShield Academy quiz component.
Readiness Check
A13 Module Test Readiness
0/4 ready
Coverage Map
What the 25 Questions Cover
Zero-trust principles and environment boundaries
Federation and SSO
Conditional access and policy decisions
RBAC, ABAC, hybrid models, and role explosion
Privileged access management
Identity logging and monitoring
Access reviews and governance
Security and usability tradeoffs
Integrated zero-trust architecture decision
Assessment
25-Question Module Test
Work through all 25 questions before using the explanations to review missed concepts.
Check Your Understanding
A13 Module Test: Identity, Zero Trust, and Access Control
Choose your answers first. Explanations appear only after submission.
1. What is the strongest reason identity is treated as a security perimeter in modern architecture?
2. Which identity relationship is strongest for a production application connecting to its database?
3. What best describes zero trust?
4. A staging workload successfully authenticates but requests a production database without an approved production purpose. What should happen?
5. What is the core purpose of federation?
6. What does single sign-on improve most directly?
7. What is the strongest design for external federation?
8. What is conditional access?
9. When is step-up verification most appropriate?
10. A sensitive access policy depends on device context, but the device-context source is stale. What is strongest?
11. What is the core idea of RBAC?
12. What is the core idea of ABAC?
13. When is a hybrid RBAC + ABAC model especially useful?
14. What is role explosion?
15. What is the difference between privileged eligibility and active privilege?
16. Why is just-in-time privileged access valuable?
17. A migration project ended, but a former administrator remains eligible for the migration-admin role. What should happen?
18. What is strongest for emergency or break-glass access?
19. Why should identity monitoring include authorization events in addition to sign-ins?
20. What does source health tell an identity-monitoring team?
21. What is the main purpose of an access review?
22. A reporting analyst still needs dashboard access but no longer needs sensitive export capability. What is the strongest review outcome?
23. What is strongest for an unowned legacy production identity with partial monitoring and uncertain business purpose?
24. Which design best balances security and usability for high-impact production administration?
25. A zero-trust architecture review finds strong modern controls but two material Blocked findings: an unowned legacy identity and obsolete privileged eligibility. What is the strongest overall recommendation?
Performance Guide
Interpret Your Result
21–25
Strong readiness. You can integrate identity, access, privilege, monitoring, and governance evidence.
Next step: Review only any question explanations you missed, then continue to A14.
17–20
Good readiness with a few targeted gaps.
Next step: Use the coverage map to revisit the lessons tied to missed questions.
13–16
Partial readiness. Core ideas are present, but some architecture relationships need reinforcement.
Next step: Revisit A13.2, A13.4, A13.6, A13.7, and A13.8 before moving on.
0–12
Rebuild the identity architecture model before continuing.
Next step: Review the A13 homepage and work back through the lessons in order, focusing on how identity, authorization, lifecycle, and evidence connect.
Targeted Review
Use Missed Questions to Find the Right Lesson
Questions 1–2 → A13.1
Review identity perimeter and workload identity.
Questions 3–4 → A13.2
Review zero-trust principles and environment boundaries.
Questions 5–7 → A13.3
Review federation and sso.
Questions 8–10 → A13.4
Review conditional access and policy decisions.
Questions 11–14 → A13.5
Review rbac, abac, hybrid models, and role explosion.
Questions 15–18 → A13.6
Review privileged access management.
Questions 19–20 → A13.7
Review identity logging and monitoring.
Questions 21–23 → A13.8
Review access reviews and governance.
Question 24 → A13.9
Review security and usability tradeoffs.
Question 25 → A13.10
Review integrated zero-trust architecture decision.
Defender Habits
A13 Mastery Checklist
Key Takeaways
What You Should Remember
Module Complete
A13 — Identity, Zero Trust, and Access Control
You have completed the A13 learning sequence and its 25-question module assessment. The next Advanced module is A14 — Cryptography and Key Management Concepts.