Courseiva
easyMultiple Choice

CAS-004 Practice Question: Deploying a new cloud-based application that…

A company is deploying a new cloud-based application that processes sensitive customer data. The security architect has proposed a zero-trust architecture to secure remote access. The architecture includes identity-aware proxies, microsegmentation, and continuous monitoring. During the transition, several remote users report being unable to access the application. The security architect verifies that the identity-aware proxy is correctly configured and that users are authenticated via SSO. However, access attempts are still failing. The architect suspects that the issue may be related to the microsegmentation rules. What should the security architect do FIRST to resolve the problem?

⚠ Common exam trap

The trap is focusing on authentication or adding network layers (VPN) when the issue is authorization/network policy; candidates may overlook that microsegmentation rules must permit traffic even after successful authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the microsegmentation firewall rules to ensure that traffic to the application's subnet is permitted.

In a zero-trust architecture with microsegmentation, access failures after authentication often stem from network policies blocking traffic. The security architect should first review the microsegmentation firewall rules to ensure traffic to the application's subnet is permitted, as the identity-aware proxy and SSO are confirmed working. This directly addresses the suspected cause and is the most logical first step before other remediations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a VPN to provide a secure tunnel for remote users.

    Why it's wrong here

    A VPN would bypass the zero-trust design rather than diagnose the suspected microsegmentation fault, and it contradicts the architecture already deployed. It is tempting because VPNs traditionally solved remote access failures, and one would be correct where no identity-aware proxy or microsegmentation exists.

  • ✗

    Reset the affected users' credentials and force them to re-authenticate.

    Why it's wrong here

    Credentials are not the failure point: the stem confirms SSO authentication succeeds and the identity-aware proxy is correctly configured, so re-authentication changes nothing. It is tempting because authentication errors commonly cause access failures, and credential reset is the correct first step when authentication itself is failing.

  • ✓

    Review the microsegmentation firewall rules to ensure that traffic to the application's subnet is permitted.

    Why this is correct

    Microsegmentation rules govern east-west traffic between workloads, so overly restrictive firewall rules on the application subnet would block authenticated users even when the identity-aware proxy and SSO function correctly; verifying those rules first isolates the suspected cause.

  • ✗

    Increase logging verbosity on the identity-aware proxy to capture more details.

    Why it's wrong here

    Increasing proxy logging gathers more evidence but does not resolve the suspected microsegmentation rule fault blocking access. It is tempting because logging is a safe diagnostic step, and it is correct when the failure source is unknown and the proxy's behaviour needs investigation first.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.