Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A global retailer is deploying a microsegmentation strategy in its data center to limit lateral movement after a breach. The security architect must enforce policy based on workload identity and allow only required east-west flows, even when workloads are migrated between hosts. Which of the following should be implemented?

⚠ Common exam trap

The trap here is assuming that network-layer segmentation such as VLANs or perimeter firewalls provides microsegmentation, when only identity-based host enforcement can follow workloads and control east-west flows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Host-based firewalls with workload identity labels and a central policy controller.

Host-based firewalls with identity labels and a central policy controller enforce microsegmentation based on workload identity rather than IP addresses. This design allows only necessary east-west flows and automatically follows workloads during migration, which is essential in a dynamic data center where lateral movement must be contained.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VLAN segmentation with ACLs applied on the core switches.

    Why it's wrong here

    VLANs and core ACLs enforce policy based on network topology and IP subnets, not workload identity. When workloads migrate between hosts or subnets, the rules must be manually updated, which breaks the requirement to follow workloads and can leave lateral movement paths open.

  • ✗

    A next-generation firewall (NGFW) deployed at the data center perimeter.

    Why it's wrong here

    A perimeter NGFW inspects north-south traffic entering and leaving the data center but does not control east-west flows between internal workloads. Lateral movement after a breach occurs inside the perimeter, so this placement cannot enforce the required workload-to-workload policy.

  • ✗

    802.1X port-based network access control on all switch ports.

    Why it's wrong here

    802.1X authenticates devices and users at the port level, which controls initial network access but not ongoing workload-to-workload communication. It does not provide granular east-west policy based on workload identity, so it cannot limit lateral movement between internal workloads as required.

  • ✓

    Host-based firewalls with workload identity labels and a central policy controller.

    Why this is correct

    Host-based firewalls with identity labels enforce policy at the workload level regardless of host or IP changes, and a central controller distributes consistent rules. This allows only required east-west flows and follows workloads across migrations, directly satisfying the microsegmentation requirement in a dynamic data center.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.