High School AdvancedModule A2Module Test30 Questions

A2 Module Test: Security Architecture

Test your understanding of security architecture, defense in depth, trust boundaries, segmentation, identity, visibility, resilience, secure defaults, tradeoffs, and integrated architecture design. Every scenario, organization, system, identity, record, and outcome in this assessment is fictional.

Lesson Progress

Module Test

High School AdvancedA2: Security Architecture • Lesson 11 of 11

100% complete

Readiness Check

Module Test Readiness

0/6 ready

Test Instructions

Complete All 30 Questions

Questions

30 multiple-choice questions divided into three sections.

Answer method

Choose your answer first, then reveal the hidden answer and explanation.

Recommended time

30–45 minutes without using outside notes on the first attempt.

Mastery target

Aim for at least 24 correct answers out of 30.

Retake rule

Review missed concepts before attempting the test again.

Safety boundary

Use only the fictional evidence and defensive reasoning presented in Module A2.

Test Blueprint

What This Assessment Covers

Section 1 · Questions 1–10

Security architecture, defense in depth, trust boundaries, requirements, assumptions, control stacks, and effective-state validation.

Section 2 · Questions 11–20

Segmentation, approved flows, identity-centered architecture, service identities, authorization, visibility, source health, and evidence quality.

Section 3 · Questions 21–30

Recovery, secure defaults, hardening, exceptions, constraints, lifecycle cost, accessibility, tradeoffs, and final portfolio safety.

Check Your Understanding

Section 1: Architecture Foundations

Choose your answers first. Explanations appear only after submission.

1. What best describes security architecture in the fictional Northbridge environment?

2. Which statement best reflects defense in depth?

3. What makes a fictional trust boundary meaningful?

4. A fictional internal service is allowed to call every other internal service because it is inside the network. What is the main architecture weakness?

5. Which item belongs in a strong fictional trust-boundary register?

6. A fictional security control, approval workflow, evidence source, and recovery process all depend on one platform. What risk does this create?

7. What is strongest evidence that a fictional architecture diagram matches reality?

8. What should happen when a fictional design assumption becomes uncertain?

9. Which control stack is most complete for a fictional high-impact risk?

10. Which statement best describes a fictional architecture requirement?

Check Your Understanding

Section 2: Segmentation, Identity, and Visibility

Choose your answers first. Explanations appear only after submission.

1. What is the strongest starting point for fictional network segmentation?

2. What should every approved fictional network flow define?

3. A fictional emergency network rule remains active after recovery. What is the strongest response?

4. What best describes identity-centered architecture?

5. What is the difference between fictional authentication and authorization?

6. Which design best supports separation of duties?

7. What is the strongest approach to fictional service identities?

8. What best describes logging and visibility by design?

9. Why must fictional source health be monitored?

10. A fictional parser update removes approver and target fields from privileged events. What is the strongest conclusion?

Check Your Understanding

Section 3: Recovery, Hardening, and Decisions

Choose your answers first. Explanations appear only after submission.

1. Why is a fictional backup not the same as recovery?

2. The fictional application is online, but identity synchronization, logging, and supplier validation are incomplete. What is strongest?

3. Which fictional recovery identity design is strongest?

4. What best describes a fictional secure default?

5. What makes a fictional baseline exception defensible?

6. A fictional hardening change breaks an undocumented identity dependency. What is strongest?

7. What should be defined before comparing fictional architecture options?

8. The fictional lowest-price option has the highest training, migration, lock-in, and recovery cost. What is strongest?

9. A fictional preferred identity design fails accessibility testing. What should happen?

10. What makes the complete fictional A2 architecture safe to publish as a student portfolio artifact?

Score Guide

Interpret Your First Attempt

27–30 correct

Advanced mastery. Review any missed explanation, then continue.

24–26 correct

Module ready. Review missed topics before beginning A3.

18–23 correct

Developing. Revisit the matching A2 lessons and retake the test.

0–17 correct

Rebuild foundations. Review A2.1–A2.10 in order before retaking.

Targeted Review Plan

Match Missed Questions to the Correct Lesson

A2.1–A2.3

Review architecture meaning, defense in depth, trust boundaries, assumptions, requirements, and control layering.

A2.4

Review mission-based segmentation, flow decisions, denied paths, temporary rules, and effective-flow validation.

A2.5

Review identity types, authentication, authorization, least privilege, separation of duties, and identity lifecycle.

A2.6

Review evidence questions, event fields, source health, time quality, privacy, schema drift, and end-to-end visibility.

A2.7

Review continuity, backup versus recovery, recovery identities, dependency order, service validation, and closure.

A2.8

Review secure defaults, least functionality, measurable baselines, drift, exceptions, rollback, and restored states.

A2.9

Review constraints, consistent criteria, lifecycle cost, accessibility, privacy, pilots, reversibility, and sunset criteria.

A2.10

Review integrated requirements, control stacks, validation scenarios, decision records, ownership, and final approval gates.

Module Reflection

Record Your Architecture Readiness

Which fictional architecture concept felt strongest on your first attempt?
Which lesson produced the most missed questions?
Which fictional evidence limitation or failure mode changed your answer?
Which architecture decision would you explain most confidently to a review board?
Which recovery, privacy, accessibility, or ownership issue still needs review?
What will you revise before starting Module A3: Threat Modeling?

Key Takeaways

What You Should Remember

1.Security architecture coordinates fictional mission, trust, identity, data, controls, evidence, failure, recovery, ownership, and governance.
2.Defense in depth uses multiple independent fictional control layers rather than one shared point of failure.
3.Trust boundaries and segmentation require explicit identities, actions, data, paths, owners, evidence, failure behavior, and denied alternatives.
4.Authentication establishes fictional identity; authorization decides whether a specific action on a specific target is allowed.
5.Visibility by design begins with fictional evidence questions and includes source health, time quality, context, privacy, access, retention, resilience, and confidence.
6.Recovery is broader than backup or application availability and requires identity, data, dependencies, evidence, users, communication, closure, and owner acceptance.
7.Secure defaults begin with minimum fictional capability and add only approved access, services, paths, data, privilege, and integrations.
8.Architecture tradeoffs must compare fictional security, privacy, accessibility, availability, operations, cost, evidence, recovery, suppliers, and reversibility consistently.
9.Effective-state validation is stronger than diagrams, policies, baselines, or intended configuration alone.
10.Every CyberShield architecture artifact must remain fully fictional, defensive, non-operational, privacy-safe, and incapable of exposing real organizations or systems.

Navigation

Module A2 Complete

Return to the module homepage to review any lesson or return to the Advanced track before beginning Module A3.