Questions 1–3
A11.1 — Security in the Software Lifecycle
Lifecycle ownership, security evidence, traceability, change triggers, and retirement.
A11 Module Assessment
This 25-question test checks your understanding of the full A11 module: lifecycle security, requirements, threat modeling, secrets, dependencies, error handling, logging, code review, safe validation, deployment, and integrated architecture decisions.
Answers remain hidden until you reveal them through the quiz component. Use the explanations to identify exactly which lesson needs review.
Readiness Check
0/4 ready
Assessment Coverage
Questions 1–3
Lifecycle ownership, security evidence, traceability, change triggers, and retirement.
Questions 4–6
Specific, scoped, owned, traceable requirements and acceptance evidence.
Questions 7–9
Assets, trust boundaries, threat statements, controls, evidence, and uncertainty.
Questions 10–11
Metadata, ownership, environment separation, scope, rotation, redaction, and retirement.
Questions 12–14
Provenance, support, runtime context, ownership, updates, exceptions, and evidence limits.
Questions 15–17
Audience separation, correlation, redaction, auditability, retention, and source health.
Questions 18–19
Requirements-driven review, implementation evidence, findings, limitations, and validation needs.
Questions 20–21
Authorization, expected outcomes, synthetic data, evidence, stop conditions, and bounded conclusions.
Questions 22–23
Artifact identity, configuration, release gates, monitoring, rollback, and post-release validation.
Questions 24–25
Integrated architecture assessment, residual risk, evidence conflicts, decision records, and final release reasoning.
Before You Start
When two answers sound possible, choose the one that best matches the evidence actually provided.
Do not turn missing evidence into a pass or convert a possible concern into proof of harm.
Ask how a decision affects requirements, ownership, validation, release, operation, maintenance, and retirement.
After revealing an answer, note the lesson behind any question you missed.
A11 Module Test
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Performance Guide
This guide is for self-review. The most useful result is not only the total score — it is knowing which security reasoning patterns need more practice.
Strong A11 readiness. You are reasoning across the module rather than memorizing isolated terms.
Good understanding. Review the specific evidence or lifecycle areas behind the questions you missed.
Developing understanding. Revisit the targeted lessons before moving to the next Advanced architecture module.
Rebuild the core concepts first: requirements, threat modeling, evidence discipline, ownership, validation, and release reasoning.
Targeted Review Map
Review A11.1–A11.2
You missed questions about ownership, traceability, requirement quality, acceptance evidence, or exceptions.
Review A11.3
You confused threat concerns with proof, or had trouble with trust boundaries and evidence limits.
Review A11.4–A11.5
You missed metadata, environment separation, provenance, runtime context, updates, or exceptions.
Review A11.6–A11.7
You missed correlation IDs, source health, audience separation, implementation evidence, or review limitations.
Review A11.8–A11.9
You missed authorization scope, stop conditions, artifact identity, configuration drift, rollback, or release gates.
Review A11.10
You struggled with residual risk, evidence conflicts, change triggers, or final release recommendations.
A11 Mastery
A11 is not about memorizing isolated security vocabulary. It is about understanding how software security decisions remain connected over time.
Why secure requirements need owners, evidence, and change triggers.
Why a threat concern is not proof of compromise.
Why secret values should stay out of reviews and portfolio artifacts.
Why dependency context matters more than version age alone.
Why useful logging includes redaction, correlation, retention, access, and source health.
Why code review and runtime validation answer different questions.
Why safe testing starts with authorization, scope, expected outcomes, and stop conditions.
Why a release decision must match the exact artifact, configuration, and current evidence.
Why residual risk and Unknowns belong in a professional architecture assessment.
Why meaningful changes should reopen earlier security assumptions.
Defender Habits
Key Takeaways
Assessment Safety Boundary
This module does not authorize scanning, exploitation, bypass testing, credential attacks, fuzzing, malicious payloads, real secret collection, or access to production systems. All examples and assessment scenarios are fictional and school-appropriate.
Module Complete
Completing this assessment finishes Module A11. The next Advanced module is A12 — Cloud Security Architecture, where you will apply architecture reasoning to cloud identity, services, data, configuration, monitoring, resilience, and governance.