Free PBQ Demo · Advanced

Topology · Zero-Trust Architecture

Replace flat perimeter trust with identity-driven micro-segmentation — IdP, policy engine, conditional access, continuous verification.

Tests: Zero-trust principles, IdP integration, policy decision/enforcement, device posture — Security+ Domain 3.

~10 minNo signup needed

Scenario

Move from perimeter VPN to zero-trust — IdP, policy engine, posture, continuous verification.

Wire the IdP, policy decision point, and resources so every request is identity-verified, posture-checked, and re-evaluated continuously.

Network Topology — Live View

monitoring
Identity ProviderIdP / SSOPolicy EnginePDP / PEPManaged Devicecorp laptopInternal HR AppPIIMarketing CMSpublic-facingFinance DBSOX-scoped
InfectedAlertConfiguredclick any hostto configure

Identity Provider

IdP / SSO

Authentication

SSO session lifetime:

Tasks

  • IdP — MFA required, FIDO2 allowed, 8h session.
  • Policy engine — use identity + device + location + behaviour, re-eval 5m.
  • Managed device must have EDR + patches + disk encryption.
  • PII app → high trust. CMS → managed. Finance DB → high trust.

0 settings configured

Liked this PBQ? There are 80+ more inside.

Sign up free to take full timed exams with mixed MCQs and all 6 PBQ types — across 10 CompTIA and Cisco certifications.