Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is designing a zero trust architecture for a company with a large remote workforce. The requirement is to verify device health and user identity for every session to internal applications, regardless of network location, and to prevent session hijacking after initial authentication. Which of the following BEST meets these requirements?

⚠ Common exam trap

The trap here is treating strong initial authentication such as VPN with MFA or mutual TLS as sufficient, when zero trust requires continuous per-session verification and context-bound tokens to prevent session hijacking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a zero trust network access (ZTNA) service that continuously evaluates identity and device posture and issues per-session, context-bound tokens.

ZTNA continuously evaluates identity and device posture and issues per-session tokens bound to context, so every access request is verified regardless of network location. Because tokens are tied to the session and device context, a stolen token cannot be replayed elsewhere, which directly prevents session hijacking after initial authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require all remote users to connect through a cloud access security broker (CASB) that applies data loss prevention policies to cloud applications.

    Why it's wrong here

    A CASB focuses on visibility and policy enforcement for cloud application usage, not on per-session verification of device health and user identity for internal applications. It does not issue context-bound session tokens or prevent hijacking of sessions to internal resources, so it does not meet the stated requirements.

  • ✗

    Use a reverse proxy with mutual TLS client certificates and enforce certificate revocation checks at each connection.

    Why it's wrong here

    Mutual TLS with client certificates authenticates devices strongly, but it does not continuously evaluate user identity or device health during the session. A stolen certificate and private key can be used to hijack a session, and revocation checks alone do not bind the session to dynamic context such as location or posture.

  • ✓

    Implement a zero trust network access (ZTNA) service that continuously evaluates identity and device posture and issues per-session, context-bound tokens.

    Why this is correct

    ZTNA brokers access per application based on continuous evaluation of user identity and device posture, and it issues context-bound tokens that are validated for each session. This prevents session hijacking because tokens are tied to the session context and cannot be replayed from a different device or location, meeting both requirements.

  • ✗

    Deploy a VPN concentrator with split tunneling and require users to authenticate with a username and password plus a one-time code.

    Why it's wrong here

    A VPN with split tunneling grants broad network access after authentication and does not continuously verify device health or user identity per session. One-time codes protect initial login but do not prevent session hijacking after authentication, and split tunneling can bypass security controls for some traffic.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.