Courseiva
Security Architecture →mediumMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is designing a microsegmentation strategy for a data center hosting legacy and modern applications. The architect must ensure that workloads can only communicate with explicitly authorized peers and that policy follows the workload even if it is migrated between hosts. Which two of the following controls best meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is equating VLAN segmentation with microsegmentation, when VLANs tie policy to network location and do not follow a workload that migrates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Host-based firewall agents that enforce allow-list rules based on workload identity tags.

Microsegmentation requires policy that is based on workload identity and portable across hosts. Host-based firewall agents with identity-tag rules and an SDN overlay enforcing label-based policy both deliver explicit peer authorization and follow workloads during migration. VLAN ACLs, a single perimeter zone, and 802.1X either tie policy to topology or address admission rather than ongoing east-west control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VLAN segmentation with ACLs applied at the core switch.

    Why it's wrong here

    VLANs and switch ACLs segment by network topology and IP subnet, so policy is tied to location rather than workload identity. When a workload migrates to a different VLAN or host, the rules no longer follow it, and east-west traffic within a VLAN remains unrestricted. This does not meet the portability requirement.

  • ✗

    A next-generation firewall with a single perimeter zone for all internal servers.

    Why it's wrong here

    A perimeter firewall with one internal zone permits unrestricted east-west traffic among all servers, which contradicts microsegmentation. It cannot enforce per-workload peer authorization or follow a workload across hosts, and it reintroduces a flat internal network vulnerable to lateral movement.

  • ✓

    Host-based firewall agents that enforce allow-list rules based on workload identity tags.

    Why this is correct

    Host-based firewall agents enforce policy at the workload level and can use identity tags rather than IP addresses, so rules remain valid when the workload moves between hosts. This satisfies both explicit peer authorization and policy portability, making it a core microsegmentation control.

  • ✓

    A software-defined networking overlay that enforces policy based on workload labels.

    Why this is correct

    An SDN overlay decouples policy from physical topology and applies rules based on workload labels, so authorized peer relationships persist across host migrations. This provides dynamic, identity-based microsegmentation and is a standard approach for following workloads in modern data centers.

  • ✗

    802.1X port-based network access control for all server NICs.

    Why it's wrong here

    802.1X authenticates devices at the switch port and can assign a VLAN, but it does not provide workload-to-workload authorization or follow a workload when it moves. It addresses initial network admission, not ongoing east-west policy enforcement, so it does not satisfy the microsegmentation requirements.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.