CAS-004 Security Architecture Practice Question
A security architect is designing a microsegmentation strategy for a data center hosting legacy and modern applications. The architect must ensure that workloads can only communicate with explicitly authorized peers and that policy follows the workload even if it is migrated between hosts. Which two of the following controls best meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is equating VLAN segmentation with microsegmentation, when VLANs tie policy to network location and do not follow a workload that migrates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Host-based firewall agents that enforce allow-list rules based on workload identity tags.
Microsegmentation requires policy that is based on workload identity and portable across hosts. Host-based firewall agents with identity-tag rules and an SDN overlay enforcing label-based policy both deliver explicit peer authorization and follow workloads during migration. VLAN ACLs, a single perimeter zone, and 802.1X either tie policy to topology or address admission rather than ongoing east-west control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VLAN segmentation with ACLs applied at the core switch.
Why it's wrong here
VLANs and switch ACLs segment by network topology and IP subnet, so policy is tied to location rather than workload identity. When a workload migrates to a different VLAN or host, the rules no longer follow it, and east-west traffic within a VLAN remains unrestricted. This does not meet the portability requirement.
- ✗
A next-generation firewall with a single perimeter zone for all internal servers.
Why it's wrong here
A perimeter firewall with one internal zone permits unrestricted east-west traffic among all servers, which contradicts microsegmentation. It cannot enforce per-workload peer authorization or follow a workload across hosts, and it reintroduces a flat internal network vulnerable to lateral movement.
- ✓
Host-based firewall agents that enforce allow-list rules based on workload identity tags.
Why this is correct
Host-based firewall agents enforce policy at the workload level and can use identity tags rather than IP addresses, so rules remain valid when the workload moves between hosts. This satisfies both explicit peer authorization and policy portability, making it a core microsegmentation control.
- ✓
A software-defined networking overlay that enforces policy based on workload labels.
Why this is correct
An SDN overlay decouples policy from physical topology and applies rules based on workload labels, so authorized peer relationships persist across host migrations. This provides dynamic, identity-based microsegmentation and is a standard approach for following workloads in modern data centers.
- ✗
802.1X port-based network access control for all server NICs.
Why it's wrong here
802.1X authenticates devices at the switch port and can assign a VLAN, but it does not provide workload-to-workload authorization or follow a workload when it moves. It addresses initial network admission, not ongoing east-west policy enforcement, so it does not satisfy the microsegmentation requirements.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.