Courseiva
Security Engineering →hardMultiple Select

CAS-004 Security Engineering Practice Question

A security architect is designing a zero trust architecture for a hybrid workforce that accesses internal applications from managed and unmanaged devices. The architect wants to enforce continuous verification of device and user trust for every session. Which TWO controls are essential to meet this goal? (Choose two.)

⚠ Common exam trap

The trap here is assuming that network segmentation or a perimeter firewall constitutes zero trust, when those controls grant implicit trust based on network location rather than per-request evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce identity-aware access proxies that mediate every session and apply the policy decision to each request.

Continuous verification in zero trust depends on two functions working together: a policy decision point that evaluates identity, device posture, and context on every request, and identity-aware enforcement points that mediate sessions and apply those decisions inline. Together they replace implicit network trust with per-request authorization; perimeter rules, long-lived VPN sessions, and VLAN segmentation do not evaluate trust dynamically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require all traffic to traverse a traditional perimeter firewall with static rules based on internal IP subnets.

    Why it's wrong here

    Static perimeter rules based on internal subnets assume that everything inside the network is trusted, which is the model zero trust replaces. A perimeter firewall cannot evaluate device posture or user context and does not provide continuous verification, so it fails to satisfy the requirement even if it remains useful for coarse network hygiene.

  • ✗

    Issue long-lived VPN credentials so users authenticate once and retain access for the duration of the workday.

    Why it's wrong here

    Long-lived credentials and a single authentication event contradict continuous verification; once a session is established, a compromised device or stolen credential retains access until the credential expires. Zero trust favors short-lived, frequently re-evaluated sessions and per-request authorization rather than a day-long implicit trust window.

  • ✗

    Segment the internal network into VLANs and rely on switch ACLs to isolate application tiers.

    Why it's wrong here

    VLAN segmentation and switch ACLs limit east-west movement and are valuable defense in depth, but they are network-location controls that do not evaluate user identity or device posture. They cannot provide continuous verification of trust for a session, so they do not satisfy the core requirement even though they complement a zero trust design.

  • ✓

    Enforce identity-aware access proxies that mediate every session and apply the policy decision to each request.

    Why this is correct

    Policy decisions only matter if they are enforced inline. Identity-aware proxies act as policy enforcement points that terminate sessions and apply the decision point's verdict per request, which is how continuous verification becomes effective. They also hide application endpoints so that access cannot bypass the control path, supporting the zero trust principle of never trusting the network.

  • ✓

    Deploy a policy decision point that evaluates device posture, user identity, and contextual signals on each access request.

    Why this is correct

    Zero trust requires an explicit policy decision point that combines identity, device health, and contextual signals rather than trusting a network location. Evaluating on each request, not just at login, is what enables continuous verification and adaptive access decisions. Without this component, enforcement points have no authoritative basis for allowing or denying a session as conditions change.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.