Courseiva
Security Architecture →hardMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is designing a data loss prevention (DLP) strategy for a hybrid environment where sensitive records are stored on-premises and synchronized to a SaaS productivity suite. The architect needs to ensure that policy enforcement follows the data regardless of location and that violations are detected before data leaves the organization. Which TWO of the following capabilities are most critical to achieve these goals? (Choose two.)

⚠ Common exam trap

The trap here is treating encryption or SIEM correlation as DLP enforcement, when only inline content inspection at the cloud edge and endpoint content-aware agents can actually block sensitive data before it leaves.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Endpoint DLP agents with content-aware rules on managed workstations.

Inline CASB inspection enforces DLP policy at the cloud egress point, while endpoint DLP agents enforce policy at the source on managed devices. Together they cover both network and local egress paths, ensuring that sensitive data is inspected and blocked before it leaves the organization and that policy follows the data across hybrid locations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Full-disk encryption (FDE) on all endpoints and servers storing sensitive records.

    Why it's wrong here

    Full-disk encryption protects data at rest if a device is lost or stolen, but it does not inspect content or enforce sharing policies. It cannot detect or block a user uploading sensitive records to the SaaS suite, so it does not meet the requirement for policy enforcement following the data.

  • ✓

    Endpoint DLP agents with content-aware rules on managed workstations.

    Why this is correct

    Endpoint DLP agents monitor and block sensitive data at the source, such as copying files to removable media or pasting into web forms. In a hybrid environment, this complements inline cloud inspection by covering local egress paths that network-based controls cannot see, ensuring enforcement follows the data.

  • ✓

    Cloud access security broker (CASB) with inline data inspection for the SaaS suite.

    Why this is correct

    An inline CASB inspects traffic between users and the SaaS suite in real time, applying DLP policies before data is uploaded or shared. This directly enforces policy at the point of egress and satisfies the requirement to detect violations before data leaves the organization, even when users are remote.

  • ✗

    Security information and event management (SIEM) correlation of DLP alerts.

    Why it's wrong here

    A SIEM aggregates and correlates alerts for investigation, but it is a detective and analytical control, not an enforcement point. It does not inspect or block data flows before egress, so it cannot satisfy the requirement to detect violations before data leaves the organization.

  • ✗

    Network segmentation between the on-premises data center and the SaaS provider.

    Why it's wrong here

    Segmentation limits lateral movement and defines trust boundaries, but it does not inspect data content or enforce DLP policy. Since the SaaS suite must be reachable for synchronization, segmentation alone cannot prevent sensitive data from being uploaded, making it irrelevant to the stated enforcement goal.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.