Loading course title...
Loading assessment title...
Connecting to LMS...
Progress: in progress
Assessment
1. Why is IAM a major cloud security boundary?
A. It only changes network cable placement
B. It replaces all logging
C. Cloud identities can control resources, policies, networks, workloads, and data through APIs
D. It only applies to billing reports
2. What should every cloud identity have?
A. A purpose, owner, lifecycle, and permission boundary or equivalent guardrail
B. Permanent full administrator access
C. No review process
D. A shared password
3. What does effective access mean?
A. Only the title of one visible role
B. Access that ignores conditions
C. A list of console pages
D. The actual access after policies, inheritance, conditions, and denies are evaluated
4. What is least privilege?
A. Granting every developer owner access
B. Granting only the access needed to perform a specific job
C. Removing all user accounts
D. Disabling all deployment automation
5. Why do organizations commonly federate cloud access?
A. To avoid identity lifecycle management
B. To create more long-lived access keys
C. To centralize sign-in, groups, MFA, and lifecycle controls through an identity provider
D. To remove authorization decisions
6. What is a safer pattern for workload identity?
A. One shared service account for every workload
B. Unowned static keys in source repositories
C. Broad deployment roles for all environments
D. Short-lived, owned, narrowly scoped credentials or managed workload identity
7. Why can role passing or service account impersonation be risky?
A. It may create an indirect path to stronger permissions
B. It always disables all permissions
C. It only affects billing tags
D. It prevents audit logging automatically
8. Which activity should be monitored in cloud IAM governance?
A. Only successful web page loads
B. Role assignments, key creation, policy changes, denied access, and unusual API calls
C. Only monthly invoices
D. Only virtual machine CPU usage
9. What is a good access review question?
A. Can this identity be ignored forever?
B. How can we make this identity permanent?
C. Does this identity still have a valid owner, purpose, and appropriately scoped access?
D. Can logs be deleted after review?
10. What is the best summary of secure cloud IAM?
A. Grant broad access and rely only on network firewalls
B. Create keys once and never rotate them
C. Review access only after an incident
D. Inventory identities, grant least privilege, prefer temporary access, monitor changes, and review continuously
Submit Quiz
Previous