CAS-004 Security Architecture Practice Question
A security architect is designing a data loss prevention (DLP) strategy for a hybrid environment where sensitive records are stored on-premises and synchronized to a SaaS productivity suite. The architect needs to ensure that policy enforcement follows the data regardless of location and that violations are detected before data leaves the organization. Which TWO of the following capabilities are most critical to achieve these goals? (Choose two.)
⚠ Common exam trap
The trap here is treating encryption or SIEM correlation as DLP enforcement, when only inline content inspection at the cloud edge and endpoint content-aware agents can actually block sensitive data before it leaves.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Endpoint DLP agents with content-aware rules on managed workstations.
Inline CASB inspection enforces DLP policy at the cloud egress point, while endpoint DLP agents enforce policy at the source on managed devices. Together they cover both network and local egress paths, ensuring that sensitive data is inspected and blocked before it leaves the organization and that policy follows the data across hybrid locations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Full-disk encryption (FDE) on all endpoints and servers storing sensitive records.
Why it's wrong here
Full-disk encryption protects data at rest if a device is lost or stolen, but it does not inspect content or enforce sharing policies. It cannot detect or block a user uploading sensitive records to the SaaS suite, so it does not meet the requirement for policy enforcement following the data.
- ✓
Endpoint DLP agents with content-aware rules on managed workstations.
Why this is correct
Endpoint DLP agents monitor and block sensitive data at the source, such as copying files to removable media or pasting into web forms. In a hybrid environment, this complements inline cloud inspection by covering local egress paths that network-based controls cannot see, ensuring enforcement follows the data.
- ✓
Cloud access security broker (CASB) with inline data inspection for the SaaS suite.
Why this is correct
An inline CASB inspects traffic between users and the SaaS suite in real time, applying DLP policies before data is uploaded or shared. This directly enforces policy at the point of egress and satisfies the requirement to detect violations before data leaves the organization, even when users are remote.
- ✗
Security information and event management (SIEM) correlation of DLP alerts.
Why it's wrong here
A SIEM aggregates and correlates alerts for investigation, but it is a detective and analytical control, not an enforcement point. It does not inspect or block data flows before egress, so it cannot satisfy the requirement to detect violations before data leaves the organization.
- ✗
Network segmentation between the on-premises data center and the SaaS provider.
Why it's wrong here
Segmentation limits lateral movement and defines trust boundaries, but it does not inspect data content or enforce DLP policy. Since the SaaS suite must be reachable for synchronization, segmentation alone cannot prevent sensitive data from being uploaded, making it irrelevant to the stated enforcement goal.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.