Courseiva
Security Engineering →hardMultiple Select

CAS-004 Security Engineering Practice Question

A security architect is designing a network segmentation strategy for a data center that hosts both web servers and database servers. The architect wants to ensure that if a web server is compromised, the attacker cannot directly access the database servers. The architect plans to implement microsegmentation using software-defined networking (SDN). Which TWO of the following are essential components to achieve this goal? (Choose two.)

⚠ Common exam trap

The trap here is assuming that perimeter security controls or monitoring tools can prevent lateral movement between internal servers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A hypervisor-based firewall that inspects traffic between virtual machines.

Microsegmentation with SDN requires a centralized policy controller to define and distribute security rules, and a hypervisor-based firewall to enforce those rules between virtual machines. Together, they enable granular, dynamic segmentation that prevents lateral movement. HSMs, network taps, and perimeter NGFWs serve other purposes and do not provide the necessary internal enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A hypervisor-based firewall that inspects traffic between virtual machines.

    Why this is correct

    A hypervisor-based firewall enforces security policies at the virtual switch level, controlling traffic between VMs even on the same host. This is critical for microsegmentation because it prevents lateral movement within the virtualized environment. It ensures that a compromised web server VM cannot communicate with database VMs unless explicitly allowed, directly supporting the goal.

  • ✓

    A centralized policy controller that defines and enforces security group rules.

    Why this is correct

    A centralized policy controller is essential in SDN-based microsegmentation. It defines security policies based on logical groups (e.g., web servers, database servers) and pushes them to the data plane. This allows dynamic, granular enforcement independent of physical topology. Without a controller, microsegmentation policies cannot be consistently managed and applied across the infrastructure, making it a core component.

  • ✗

    A next-generation firewall (NGFW) at the perimeter of the data center.

    Why it's wrong here

    A perimeter NGFW protects the boundary between the data center and external networks but does not control east-west traffic between internal servers. Microsegmentation specifically addresses lateral movement inside the data center. Relying solely on a perimeter firewall would not prevent a compromised web server from reaching database servers. Thus, it is not an essential component for this internal segmentation goal.

  • ✗

    A network tap or SPAN port for traffic monitoring and analysis.

    Why it's wrong here

    A network tap or SPAN port is used for passive traffic monitoring and analysis, often for IDS or forensics. It does not enforce segmentation policies or block traffic between segments. While visibility is valuable, it is not an essential component for achieving microsegmentation. The goal requires active policy enforcement, which taps do not provide.

  • ✗

    A hardware security module (HSM) to store encryption keys for VPN tunnels.

    Why it's wrong here

    An HSM is used for cryptographic key management and secure operations, such as for VPNs or TLS. While important for data protection, it does not directly enable microsegmentation or prevent lateral movement between web and database servers. The scenario focuses on network segmentation, not encryption key storage. Therefore, an HSM is not an essential component for this specific goal.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.