Courseiva
Security Architecture →hardMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is designing a Zero Trust architecture for a multinational corporation. The organization wants to enforce least-privilege access to applications based on device health, user identity, and contextual factors, and it requires continuous verification of trust. Which TWO of the following are core enforcement mechanisms that should be implemented to achieve these goals? (Choose two.)

⚠ Common exam trap

The trap here is assuming that network location such as the corporate LAN or a VPN implies trust, when Zero Trust explicitly rejects implicit trust and requires continuous, context-aware verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsegmentation with identity-based policies

The PDP/PEP separation and microsegmentation with identity-based policies are core Zero Trust enforcement mechanisms. The PDP/PEP model enables dynamic, context-aware access decisions, while identity-based microsegmentation enforces least privilege and limits lateral movement, together supporting continuous verification and device health evaluation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsegmentation with identity-based policies

    Why this is correct

    Microsegmentation with identity-based policies enforces least-privilege access between workloads and applications by using identity and context rather than IP addresses. It supports continuous verification and limits lateral movement, aligning with Zero Trust. This mechanism is essential for dynamically controlling access based on device health and user identity.

  • ✗

    Static VPN access with split tunneling for all employees

    Why it's wrong here

    Static VPN access with split tunneling grants broad network access once connected and does not provide per-request, context-aware enforcement. It contradicts Zero Trust principles because it assumes trust based on network location rather than continuous verification. It also does not support device health or user context evaluation for each application access.

  • ✗

    A single-factor password authentication for all internal applications

    Why it's wrong here

    Single-factor password authentication does not provide strong identity assurance or support continuous verification. Zero Trust requires multi-factor authentication and device health signals to evaluate trust dynamically. This option weakens the security posture and does not meet the scenario's requirement for contextual, least-privilege access.

  • ✗

    Implicit trust for devices on the corporate LAN

    Why it's wrong here

    Implicit trust for devices on the corporate LAN directly violates Zero Trust principles, which assume no implicit trust based on network location. This approach would allow compromised devices to move laterally and access resources without continuous verification. It fails to meet the requirement for context-aware, least-privilege access.

  • ✓

    Policy Decision Point (PDP) and Policy Enforcement Point (PEP) separation

    Why this is correct

    The separation of the Policy Decision Point and Policy Enforcement Point is a foundational Zero Trust mechanism. The PDP evaluates access requests against policy using identity, device health, and context, while the PEP enforces the decision at the resource. This enables dynamic, least-privilege access and continuous verification, which are central to the scenario's requirements.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.