CAS-004 Security Architecture Practice Question
A security architect is designing a platform for a hospital network. Clinical staff must access patient records from managed workstations, while third-party billing contractors use unmanaged personal laptops. The architect wants a single architecture that continuously validates device posture and user identity before granting access to each microservice, regardless of network location. Which approach should the architect implement?
⚠ Common exam trap
The trap here is assuming that strong network segmentation or VPN access alone achieves zero trust, when zero trust requires continuous, per-request identity and posture evaluation rather than one-time network admission.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a zero trust architecture using a policy engine and policy enforcement points at each microservice.
A zero trust architecture with a policy engine and enforcement points at each microservice continuously validates identity and device posture for every request, independent of network location. This single architecture covers managed clinical workstations and unmanaged contractor laptops alike, unlike network-centric controls that authenticate once and then trust the connection. Per-microservice enforcement also limits lateral movement if a device is compromised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a next-generation firewall with VLAN segmentation for clinical and contractor traffic.
Why it's wrong here
A next-generation firewall with VLAN segmentation is a perimeter-centric control. It separates traffic by network segment but does not continuously evaluate user identity or device posture per request, and it cannot distinguish an unmanaged contractor laptop from a managed clinical workstation once both reach the same VLAN. It fails to meet the requirement for per-microservice, identity-aware authorization independent of network location.
- ✓
Implement a zero trust architecture using a policy engine and policy enforcement points at each microservice.
Why this is correct
Zero trust architecture continuously evaluates identity and device posture through a policy engine and enforces decisions at policy enforcement points. Placing enforcement at each microservice allows the hospital to authorize every request based on user, device, and context regardless of network location, satisfying both the managed workstation and unmanaged contractor scenarios with one consistent model.
- ✗
Establish an IPsec VPN concentrator that assigns contractors to a restricted subnet.
Why it's wrong here
An IPsec VPN concentrator authenticates the tunnel but grants broad network-level access once connected. It does not perform continuous device posture checks or per-microservice authorization, so a compromised contractor laptop on the restricted subnet could still probe internal services. This approach is location-bound and does not meet the continuous validation requirement.
- ✗
Configure 802.1X port-based authentication on all wired switch ports.
Why it's wrong here
802.1X authenticates devices at the network access layer, typically once at connection time. It does not evaluate user identity per microservice request or continuously reassess device posture during a session. Contractors on unmanaged laptops outside the hospital's wired network would not be covered, and the control stops at layer 2 rather than protecting each microservice.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.