Cloud IAM and Zero Trust Quiz
Table of Contents
Return to the Cloud IAM and Zero Trust Lab Course
Answer every question before reading the key. Add one sentence explaining each choice.
Questions
Which item answers who receives a temporary session? A. Permission policy only B. Trust relationship C. Audit retention D. Resource tag only
Which design best fits a CI workload? A. Shared administrator password B. Long-lived access key in repository secrets C. OIDC federation with exact issuer, audience, subject, and short session D. Human emergency account
What happens when an applicable AWS explicit deny conflicts with an allow? A. The newest policy wins B. The broadest policy wins C. The request is denied D. The user chooses
Which record establishes effective access? A. One role name B. One group membership C. Principal, session, action, resource, every applicable layer, conditions, and final decision D. A console screenshot only
Which access belongs in an emergency path? A. Daily deployments B. Routine report review C. Recovery from identity or policy failure D. Every privileged change
Which zero trust statement is accurate? A. A private network grants implicit trust B. Resource access uses identity, action, context, policy, and telemetry C. Every request needs a human approval D. Zero trust is one vendor product
Why is service-account impersonation sensitive? A. Impersonation never creates logs B. A less privileged principal might obtain a more privileged session C. Service accounts lack permissions D. Impersonation requires static keys
Which lab action violates the course safety rules? A. Confirming the active project B. Creating a temporary read-only identity C. Creating a service account key for convenience D. Verifying absence after deletion
What does a last-used value prove? A. Complete safety of removal B. Activity observed within the provider’s tracking and retention limits C. Business ownership D. Absence of indirect use
What completes teardown? A. Running a delete command B. Closing the terminal C. Removing grants and identities, then passing absence checks D. Waiting for the next billing cycle
Answer Key
- B. Trust defines who or which workload receives the identity session.
- C. Exact federation claims and short sessions remove the stored cloud key.
- C. An applicable explicit deny overrides the allow.
- C. Effective access depends on the full request and all applicable layers.
- C. Emergency access exists for recovery and stays separate from routine work.
- B. Zero trust evaluates the request around the resource and current context.
- B. Impersonation creates an escalation path when the target identity has more privilege.
- C. The lab avoids long-lived keys and client secrets.
- B. Tracking windows and missing log sources limit the inference.
- C. Verified absence closes the lab.
Score and Review
| Score | Next action |
|---|---|
| 9 to 10 | Start the capstone |
| 7 to 8 | Revisit each missed lesson and correct the reason |
| 0 to 6 | Repeat Lessons 1 through 6 and rebuild the decision records |
Expected Result: your reasons explain policy behavior, not provider logo or role-name guesses.
Troubleshooting
- Two answers look close: select the choice which includes full policy context and verification.
- Provider terms blur together: return to the identity-model comparison table.
- Your lab result differs: record provider version, permissions, hierarchy controls, and error text.
Verify Your Work
- All ten questions have answers and reasons
- Missed items link to a lesson
- Provider terms stay distinct
- Revised answers explain the deciding fact
Next Steps
Complete the Cloud IAM and Zero Trust Capstone .


