Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

A financial services firm is designing a microsegmentation strategy for its VMware-based private cloud. The security team wants to enforce east-west policy based on workload identity rather than IP address, and it must survive IP address changes during automated redeployments. Which approach best satisfies these requirements?

⚠ Common exam trap

The trap here is equating microsegmentation with VLAN or subnet zoning, when true microsegmentation enforces policy at the workload level using identity labels that persist across IP changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install host-based firewall agents on each virtual machine and manage rules through a central console keyed to workload labels.

Microsegmentation requires policy that follows the workload rather than the network. Host-based enforcement managed by workload labels keeps rules valid across IP changes caused by automated redeployments and allows east-west policy expressed in terms of identity. VLAN, private VLAN, and perimeter firewall approaches all bind policy to topology, which the scenario explicitly rules out.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create VLANs per application tier and enforce inter-VLAN access control lists on the core switches.

    Why it's wrong here

    VLAN-based segmentation enforces policy on network topology and IP subnets, not workload identity. When automated redeployments change IP addresses or move workloads between subnets, the ACLs become stale and either block legitimate traffic or permit unauthorized flows, so this approach cannot meet the identity-based and redeployment-resilient requirements.

  • ✗

    Deploy a next-generation firewall between the data center core and aggregation layers and define zones by subnet.

    Why it's wrong here

    A perimeter next-generation firewall inspects north-south traffic crossing the core, but east-west traffic between virtual machines on the same host or cluster may never traverse it. Zone definitions based on subnets also break when redeployments change IP addressing, so this design neither enforces identity-based policy nor remains accurate after automation.

  • ✗

    Use 802.1Q trunking to isolate each application into a dedicated broadcast domain and apply private VLANs.

    Why it's wrong here

    Private VLANs and 802.1Q trunking provide Layer 2 isolation between broadcast domains, but policy is still anchored to switch ports and VLAN identifiers rather than workload identity. Automated redeployments that move a virtual machine to a different port or host require manual reconfiguration, making this approach operationally fragile and unable to express identity-based rules.

  • ✓

    Install host-based firewall agents on each virtual machine and manage rules through a central console keyed to workload labels.

    Why this is correct

    Host-based enforcement keyed to workload labels decouples policy from IP addresses and network topology. Because the agent travels with the workload, rules continue to apply correctly after automated redeployments change IP addresses, and policy can be expressed in terms of workload identity such as application tier or environment, satisfying both stated requirements.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.