Review synthetic cloud access, design a least-privilege target state, plan zero trust tests, and compare the result with a full answer key and rubric.
#answer key
Test cloud identity, effective permissions, human and workload access, zero trust policy, and teardown with a complete answer key.
#answer key
Model human and workload principals, credentials, sessions, policies, roles, resources, and trust relationships across major cloud providers.
Evaluate cloud access across identity policies, resource policies, boundaries, hierarchy controls, conditions, inheritance, and explicit denies.
#Least Privilege
Design federated human access with strong authentication, short sessions, privileged activation, emergency recovery, and continuous review.
#privileged access
Design workload identity with federation, managed identities, service accounts, short-lived tokens, narrow roles, and verified rotation or revocation.
Turn zero trust principles into explicit cloud access decisions using identity, resource, device, workload, context, policy enforcement, and telemetry.
Create a read-only identity in one cloud sandbox, inspect its grant, then remove and verify every lab object. AWS adds policy simulation.