High School IntermediateModule I625-Question Module Test

I6 Module Test: Identity and Access Management

Test your understanding of fictional identity, authentication, authorization, accounts, roles, least privilege, MFA, access-control models, privileged access, lifecycle, monitoring, remediation, and evidence-based IAM closure.

Lesson Progress

Module Test

High School IntermediateI6: Identity and Access Management • Lesson 9 of 9

100% complete

Readiness Check

Before You Begin

0/5 ready

Test Instructions

Complete All 25 Questions

Recommended process

  1. Read the exact wording of the question.
  2. Choose the best evidence-based defensive answer.
  3. Reveal the explanation only after making your choice.
  4. Record any missed topic for review.
  5. Complete the final readiness checklist.

Suggested benchmark

A score of 20 out of 25 or higher shows strong readiness to move forward. Review every explanation, including questions answered correctly, because the explanation identifies the evidence and reasoning standard expected in later modules.

Module Coverage

Eight Lessons Assessed

I6.1

Identity, Authentication, and Authorization

Identity, accounts, credentials, authentication, authorization, sessions, access decisions, and evidence limitations.

I6.2

Accounts, Roles, and Least Privilege

User, service, shared, temporary, emergency, and privileged accounts; roles, groups, permissions, ownership, and least privilege.

I6.3

Passwords, MFA, and Authentication Factors

Knowledge, possession, inherence, device trust, MFA, passwordless authentication, recovery, factor lifecycle, and session review.

I6.4

Access Control Models and Permissions

DAC, MAC, RBAC, rule-based, attribute-based, relationship-based, resource-level, and policy-based controls.

I6.5

Privileged Access and Administrative Accounts

Administrative identities, standing privilege, temporary elevation, emergency access, separation of duties, and de-elevation.

I6.6

Account Lifecycle and Access Reviews

Joiners, movers, leavers, temporary access, dormant accounts, recertification, ownership transfer, and closure.

I6.7

Identity Logs and Access Monitoring

Identity-provider, directory, application, device, session, recovery, privileged, lifecycle, and case evidence.

I6.8

Identity and Access Management Lab

Integrated IAM evidence, findings, prioritization, remediation, validation, monitoring, residual risk, and reporting.

Fake Dashboard

Fake IAM Module-Test Readiness Dashboard

Training dashboard summarizing the fictional evidence domains assessed in this module test.

Questions

25

Identity, authentication, authorization, roles, MFA, access models, privilege, lifecycle, monitoring, and closure.

Evidence domains

8

Account, authentication, authorization, permission, privilege, lifecycle, monitoring, and validation evidence.

Target score

20+

Review every missed question and return to the related lesson before advancing.

Fake SOC Alert

IAM Review Finds Several Connected Control Gaps

Source: Fake Module-Test Evidence Console • Time: 04:25 PM

High Severity
A fictional mover retains old application access, a service account has no owner, a privileged role expires before its session, and a recovery event leaves an old factor registered. Each issue requires a different owner and correction, but all require evidence, narrow remediation, validation, and closure.
Defensive recommendation: Do not apply one broad response. Separate each finding, preserve its source evidence, identify technical and business owners, correct narrowly, validate required and denied paths, monitor, and document residual risk.

Fake Log Panel

Fake IAM Review Summary

training-log-viewer.log
IAM-01 identity='svc-report-old' finding='orphaned_service_account' priority='high'
IAM-02 identity='training-mchen' finding='mover_privilege_accumulation' priority='high'
IAM-03 role='service-operator' finding='privileged_session_gap' priority='high'
IAM-04 identity='training-amorgan' finding='old_factor_after_recovery' priority='high'
IAM-05 identity='training-rpatel' finding='excessive_report_role' priority='medium'
IAM-06 resource='restricted-child-folder' finding='unsafe_inheritance' priority='medium'
IAM-07 monitoring='dormant_reactivation_alert' finding='context_gap' priority='medium'
IAM-08 account='break-glass-training' finding='review_overdue' priority='medium'
VALIDATION required_access='pass' denied_access='pass'
VALIDATION sessions='pass' factors='pass' local_access='pass'
OWNER_REVIEW technical='approved' business='approved'
CLOSURE residual_risk='documented'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Warm-Up Evidence Question

A fictional user is approved for report-view for thirty days.
The account receives report-admin instead.
The application confirms view, edit, export, and configuration permissions.
No evidence shows the extra permissions were used.
The owner confirms only view is required.
After remediation, report viewing succeeds.
After remediation, configuration is denied.

Which conclusion is strongest?

Check Your Understanding

I6 Module Test: 25 Questions

Choose your answers first. Explanations appear only after submission.

1. Which statement best distinguishes identity from an account?

2. What does successful authentication directly establish?

3. What is authorization?

4. Which example best follows least privilege?

5. Why can direct permissions become difficult to govern?

6. What makes a service account orphaned?

7. Which design best supports separation of duties?

8. What makes authentication multi-factor?

9. What does an approved fictional MFA challenge directly support?

10. Why is account recovery a critical security control?

11. What is step-up authentication?

12. Which statement best describes role-based access control?

13. What is attribute-based access control?

14. What is effective access?

15. Why can permission inheritance be risky?

16. What is standing privilege?

17. What is just-in-time privileged access?

18. What is just-enough privileged access?

19. What should happen when a temporary privileged role expires?

20. What is a mover event?

21. What is privilege accumulation?

22. Why must leaver workflows include session revocation?

23. What does a correlation ID help defenders do?

24. What is the strongest response when identity logs are incomplete?

25. Which closure plan is strongest for an IAM finding?

Scenario Decision Lab

Final Scenario: Several IAM Findings Appear at Once

A fictional organization finds a mover with old access, an unowned service account, an expired privileged role with an active session, and a recovery event with an old factor still registered.

Defender Habits

Module I6 Completion Checklist

Key Takeaways

What You Should Remember

1.Authentication establishes accepted account or session evidence; authorization decides which resource actions are permitted.
2.Least privilege requires exact actions, resources, duration, ownership, and business purpose.
3.MFA strengthens authentication but does not prove physical identity, intent, or authorization for every later action.
4.Effective access includes direct, inherited, role, group, local, resource, policy, and session paths.
5.Privileged access should be named, narrow, time limited, approved, monitored, and fully de-elevated.
6.IAM closure requires technical validation, business validation, monitoring, ownership, evidence traceability, and residual-risk documentation.

Module Complete

You Completed I6: Identity and Access Management

Review any missed questions, revisit the related lesson, and verify that all eight lessons and this module test open correctly from the module homepage before committing the completed module.