CAS-004 Security Engineering Practice Question
A security architect is designing a zero trust architecture for a hybrid environment where users access internal applications from managed and unmanaged devices. The requirement is that access decisions consider device health and user identity on every request rather than relying on network location. Which of the following BEST implements this requirement?
⚠ Common exam trap
The trap here is equating strong network segmentation or a hardened bastion with zero trust, when those still grant implicit trust based on location once the initial check passes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a policy engine that evaluates user identity and device posture from a device attestation service for each access request, brokered through a policy enforcement point
Zero trust requires a policy decision point that consumes identity and device-posture telemetry and a policy enforcement point that applies the decision to each request. Perimeter, bastion, and segmentation approaches all evaluate trust at connection or network admission time and do not continuously factor device health into every access decision.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement a policy engine that evaluates user identity and device posture from a device attestation service for each access request, brokered through a policy enforcement point
Why this is correct
A policy engine that consumes identity and device-posture signals and enforces decisions through a policy enforcement point on every request is the core of zero trust. It removes implicit trust based on network location and makes access contingent on current device health and authenticated identity, matching the stated requirement precisely.
- ✗
Segment the internal network into microsegments with host-based firewalls and require 802.1X for all wired and wireless access
Why it's wrong here
Microsegmentation and 802.1X reduce lateral movement and control network admission, but they make decisions based on network identity and port authentication rather than user identity and device posture per request. A device that passes 802.1X and sits in the right segment is still trusted without ongoing health evaluation.
- ✗
Require all users to connect through a bastion host that performs multi-factor authentication before reaching internal applications
Why it's wrong here
A bastion host with MFA strengthens authentication at a chokepoint but evaluates trust once at connection time and does not continuously assess device health. After the session is established, a compromised device retains access, and the decision is still anchored to reaching the bastion rather than per-request evaluation.
- ✗
Deploy a next-generation firewall with IP-based allow lists for the corporate VPN address pool and enable TLS inspection
Why it's wrong here
IP allow lists and TLS inspection operate on network location and traffic content, which is exactly the perimeter model zero trust replaces. A user on a compromised managed device inside the VPN pool would still be trusted, and device health is never evaluated. This does not satisfy per-request, identity-and-device-aware decisions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.