High School AdvancedA13 Module Test

Identity, Zero Trust, and Access Control

A13 Module Test

This 25-question assessment checks whether you can connect identity perimeter, zero trust, federation, conditional access, RBAC/ABAC, privileged access, monitoring, governance, and usability into one defensible access-control model.

Answer from the defensive architecture concepts taught in A13. The quiz hides answers until you reveal them through the existing CyberShield Academy quiz component.

Readiness Check

A13 Module Test Readiness

0/4 ready

Coverage Map

What the 25 Questions Cover

Questions 1–2A13.1

Identity perimeter and workload identity

Questions 3–4A13.2

Zero-trust principles and environment boundaries

Questions 5–7A13.3

Federation and SSO

Questions 8–10A13.4

Conditional access and policy decisions

Questions 11–14A13.5

RBAC, ABAC, hybrid models, and role explosion

Questions 15–18A13.6

Privileged access management

Questions 19–20A13.7

Identity logging and monitoring

Questions 21–23A13.8

Access reviews and governance

Question 24A13.9

Security and usability tradeoffs

Question 25A13.10

Integrated zero-trust architecture decision

Assessment

25-Question Module Test

Work through all 25 questions before using the explanations to review missed concepts.

Check Your Understanding

A13 Module Test: Identity, Zero Trust, and Access Control

Choose your answers first. Explanations appear only after submission.

1. What is the strongest reason identity is treated as a security perimeter in modern architecture?

2. Which identity relationship is strongest for a production application connecting to its database?

3. What best describes zero trust?

4. A staging workload successfully authenticates but requests a production database without an approved production purpose. What should happen?

5. What is the core purpose of federation?

6. What does single sign-on improve most directly?

7. What is the strongest design for external federation?

8. What is conditional access?

9. When is step-up verification most appropriate?

10. A sensitive access policy depends on device context, but the device-context source is stale. What is strongest?

11. What is the core idea of RBAC?

12. What is the core idea of ABAC?

13. When is a hybrid RBAC + ABAC model especially useful?

14. What is role explosion?

15. What is the difference between privileged eligibility and active privilege?

16. Why is just-in-time privileged access valuable?

17. A migration project ended, but a former administrator remains eligible for the migration-admin role. What should happen?

18. What is strongest for emergency or break-glass access?

19. Why should identity monitoring include authorization events in addition to sign-ins?

20. What does source health tell an identity-monitoring team?

21. What is the main purpose of an access review?

22. A reporting analyst still needs dashboard access but no longer needs sensitive export capability. What is the strongest review outcome?

23. What is strongest for an unowned legacy production identity with partial monitoring and uncertain business purpose?

24. Which design best balances security and usability for high-impact production administration?

25. A zero-trust architecture review finds strong modern controls but two material Blocked findings: an unowned legacy identity and obsolete privileged eligibility. What is the strongest overall recommendation?

Performance Guide

Interpret Your Result

21–25

Strong readiness. You can integrate identity, access, privilege, monitoring, and governance evidence.

Next step: Review only any question explanations you missed, then continue to A14.

17–20

Good readiness with a few targeted gaps.

Next step: Use the coverage map to revisit the lessons tied to missed questions.

13–16

Partial readiness. Core ideas are present, but some architecture relationships need reinforcement.

Next step: Revisit A13.2, A13.4, A13.6, A13.7, and A13.8 before moving on.

0–12

Rebuild the identity architecture model before continuing.

Next step: Review the A13 homepage and work back through the lessons in order, focusing on how identity, authorization, lifecycle, and evidence connect.

Targeted Review

Use Missed Questions to Find the Right Lesson

Questions 1–2A13.1

Review identity perimeter and workload identity.

Questions 3–4A13.2

Review zero-trust principles and environment boundaries.

Questions 5–7A13.3

Review federation and sso.

Questions 8–10A13.4

Review conditional access and policy decisions.

Questions 11–14A13.5

Review rbac, abac, hybrid models, and role explosion.

Questions 15–18A13.6

Review privileged access management.

Questions 19–20A13.7

Review identity logging and monitoring.

Questions 21–23A13.8

Review access reviews and governance.

Question 24A13.9

Review security and usability tradeoffs.

Question 25A13.10

Review integrated zero-trust architecture decision.

Defender Habits

A13 Mastery Checklist

Key Takeaways

What You Should Remember

1.Identity architecture connects principals, resources, authorization, lifecycle, privilege, evidence, and ownership.
2.Zero trust reduces assumed trust rather than blocking legitimate work.
3.Federation centralizes authentication while relying services retain authorization responsibility.
4.Conditional access should use relevant context and visible fallback decisions.
5.RBAC, ABAC, and hybrid models should balance clarity, least privilege, and maintainability.
6.Privileged access should be temporary, attributable, scoped, monitored, and reviewed.
7.Identity monitoring should cover authentication, authorization, lifecycle, privilege, policy, and source health.
8.Access governance asks whether access should still exist now.
9.Usability, accessibility, recovery, and supportability affect whether controls work reliably.
10.Professional architecture decisions preserve strong controls while isolating blockers and defining remediation.

Module Complete

A13 — Identity, Zero Trust, and Access Control

You have completed the A13 learning sequence and its 25-question module assessment. The next Advanced module is A14 — Cryptography and Key Management Concepts.