Module 3: Identity, Access, and Security Architecture
Week of Tue, Oct 27 · module closes Sun, Nov 8 · 100 points
Take Meerk's quiz for Module 3
This module's items
- M3 Quizdue Fri, Nov 6 · 50 pts
- M3 Labdue Sun, Nov 8 · 50 pts
Exact due times are in Canvas.
Know these cold
- Authentication factors: something you know (password), something you have (token/smart card), something you are (biometric). MFA requires two or more.
- Access control models: DAC (owner decides), MAC (labels, government), RBAC (role-based, most common in business), ABAC (attribute-based, most flexible).
- Zero Trust: 'never trust, always verify' — no implicit trust based on network location; every request is authenticated and authorized.
- Security frameworks: NIST CSF (Identify, Protect, Detect, Respond, Recover), ISO 27001 (information security management system).
- Defense in depth: layered security controls so no single failure exposes the system — physical, network, host, application, and data layers.
Meerk's quiz — open the Module 3 gate
10 questions, no time limit. 85% on your first attempt in a 24-hour window opens the gate. Retakes inside the window are practice — they help you learn, they don't count. Work alone; the point is to know it, not to have seen it.
Dinner Table Question
Ask at home: Why should employees have different levels of access to company systems — not everyone the same?
En español: ¿Por qué los empleados deben tener diferentes niveles de acceso a los sistemas de la empresa, en lugar de todos el mismo?