CAS-004 Security Operations Practice Question
A security administrator is configuring a new VPN concentrator to support remote workers. The organization requires that all remote access use strong authentication and that the VPN concentrator validate the health of connecting devices before granting access. Which technology should the administrator implement?
⚠ Common exam trap
The trap here is assuming that IKEv2 with certificate-based authentication alone satisfies the health validation requirement, when it only provides strong authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network Access Control (NAC) with posture assessment
The requirement is for strong authentication and device health validation for remote VPN access. NAC with posture assessment provides exactly that by evaluating endpoint compliance before granting access. While IKEv2 with certificates offers strong authentication, it lacks health checks. RADIUS with PAP is weak, and 802.1X is not typically used for VPN health validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPN with IKEv2 and certificate-based authentication
Why it's wrong here
IKEv2 with certificate-based authentication offers strong authentication for VPN connections, but it does not validate device health before granting access. The requirement includes checking the health of connecting devices, which is a function of NAC, not just the VPN protocol. Therefore, this option is incomplete.
- ✗
802.1X with EAP-TLS
Why it's wrong here
802.1X with EAP-TLS provides port-based network access control and strong certificate-based authentication, but it is typically used for LAN and Wi-Fi access, not for VPN concentrators. It does not inherently perform device health checks. While it can be part of a NAC solution, it is not the primary technology for VPN health validation.
- ✓
Network Access Control (NAC) with posture assessment
Why this is correct
NAC with posture assessment checks the health of devices, such as ensuring antivirus is up-to-date and patches are installed, before allowing network access. When integrated with VPN, it can enforce health policies for remote workers. This directly meets the requirement for strong authentication and device health validation.
- ✗
RADIUS with PAP
Why it's wrong here
RADIUS with PAP provides authentication but sends passwords in cleartext, which is not strong authentication. It also does not include device health validation. This option fails to meet the requirement for strong authentication and health checks, making it unsuitable for the scenario.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.