Courseiva
Security Architecture →mediumMultiple Select

CAS-004 Security Architecture Practice Question

A healthcare organization is architecting a microsegmentation strategy for its hybrid data center. The security architect must limit lateral movement between workloads, enforce policy based on workload identity rather than IP addresses, and maintain visibility into inter-workload flows. Which TWO of the following controls BEST support these requirements? (Choose two.)

⚠ Common exam trap

The trap here is treating host firewalls or zone-based firewalls as sufficient for microsegmentation, when they still rely on IP or zone constructs and do not enforce policy by cryptographic workload identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a software-defined perimeter (SDP) controller that authenticates endpoints before granting access to protected workload segments.

A software-defined perimeter and a service mesh with mutual TLS both base access decisions on authenticated workload identity rather than IP addresses, which limits lateral movement and supports visibility into inter-workload flows. The other controls either rely on static IP or zone constructs, or address layer 2 threats without providing identity-based segmentation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable dynamic ARP inspection and DHCP snooping on all access-layer switches.

    Why it's wrong here

    Dynamic ARP inspection and DHCP snooping mitigate layer 2 attacks such as ARP spoofing and rogue DHCP servers, but they do not enforce identity-based segmentation between workloads or provide visibility into inter-workload flows. They are supportive controls, not primary microsegmentation mechanisms.

  • ✓

    Deploy a software-defined perimeter (SDP) controller that authenticates endpoints before granting access to protected workload segments.

    Why this is correct

    A software-defined perimeter authenticates and authorizes endpoints before any network access is granted, creating identity-based, need-to-know connectivity between workloads. This directly limits lateral movement because unauthenticated workloads cannot reach protected segments, and it supports policy based on workload identity rather than static IP addresses.

  • ✓

    Use a service mesh with mutual TLS and identity-based authorization policies between microservices.

    Why this is correct

    A service mesh assigns cryptographic identities to workloads and enforces authorization policies based on those identities, not IP addresses. Mutual TLS ensures only authenticated services communicate, which limits lateral movement and provides flow-level visibility. This aligns with microsegmentation requirements in a hybrid environment where workloads may move.

  • ✗

    Place all workloads behind a next-generation firewall and create zone-based policies for north-south traffic.

    Why it's wrong here

    A next-generation firewall with zone-based policies primarily inspects north-south traffic entering and leaving the data center. It does not provide identity-based policy for east-west workload-to-workload flows, so lateral movement between workloads inside the same zone remains possible and inter-workload visibility is limited.

  • ✗

    Implement host-based firewalls with rules based on IP address ranges that mirror the existing VLAN segmentation.

    Why it's wrong here

    Host-based firewalls add a control point, but rules based on IP ranges replicate the weaknesses of VLAN segmentation and do not enforce policy by workload identity. In dynamic environments, IP addresses change and can be spoofed, so lateral movement is not reliably limited and visibility into identity-based flows is not provided.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.