CAS-004 Security Architecture Practice Question
A security architect at a healthcare provider must design a solution that lets clinicians access patient records from managed laptops and personal tablets without exposing the internal electronic health record (EHR) network. The requirement is that no inbound firewall ports be opened and that access decisions evaluate device posture and user identity on every session. Which solution best meets these requirements?
⚠ Common exam trap
The trap here is assuming that any encrypted remote-access tunnel satisfies Zero Trust, when the defining requirement is outbound-only brokering with continuous per-session identity and posture evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a Zero Trust Network Access (ZTNA) service that brokers outbound-only connections after continuous identity and device-posture checks.
Zero Trust Network Access matches the stated constraints because it inverts the traditional model: users connect outbound to a broker, the internal EHR network is never published, and authorization is continuously re-evaluated based on identity and device posture. VPN concentrators, reverse proxies, and network access control all require either inbound exposure or do not deliver per-session verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Publish the EHR through a reverse proxy in the DMZ and require digital certificates on all client devices.
Why it's wrong here
A reverse proxy still publishes the EHR to the internet and requires inbound connectivity to the DMZ, which the scenario explicitly forbids. Certificate-based authentication verifies device identity but does not provide continuous posture evaluation or per-session authorization, so it fails the requirement to assess user identity and device state on every access.
- ✓
Implement a Zero Trust Network Access (ZTNA) service that brokers outbound-only connections after continuous identity and device-posture checks.
Why this is correct
ZTNA brokers application access over outbound-only connections, so no inbound firewall ports are opened and the EHR network is never directly exposed. It performs identity and device-posture evaluation per session, satisfying the continuous verification requirement for both managed laptops and personal tablets without placing users on the internal network.
- ✗
Segment the clinical VLAN and apply 802.1X port-based authentication to all wired and wireless access switches.
Why it's wrong here
802.1X controls access to the local network segment but does not enable remote access from personal tablets over the internet without a gateway. VLAN segmentation reduces lateral movement inside the data center but does not eliminate the need for inbound ports or provide the per-session posture and identity checks required for remote clinical access.
- ✗
Deploy a hardware VPN concentrator in the DMZ and issue IPsec client profiles to all clinical endpoints.
Why it's wrong here
A hardware VPN concentrator still terminates inbound connections on a public-facing interface and grants broad network-level access once the tunnel is established. It cannot evaluate device posture or user identity on a per-session basis without additional products, and it violates the requirement to avoid exposing the internal EHR network through a persistent tunnel.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.