CAS-004 Security Architecture Practice Question
A security architect is designing segmentation for a manufacturing network where legacy programmable logic controllers cannot be patched or run endpoint agents. The architect wants to prevent a compromised business workstation from initiating connections to the controllers while still allowing the controllers to send telemetry to a historian server. Which of the following design elements best achieves this objective?
⚠ Common exam trap
The trap here is relying on inspection-based controls like IPS or permissive firewall rules, which still allow a compromised host to initiate sessions with controllers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A unidirectional gateway enforcing one-way data flow from the controller network out to the historian
A unidirectional gateway enforces that data can flow only from the protected controller network outward, so telemetry reaches the historian while no inbound path exists from the business network. This protects unpatched controllers that cannot run agents or be hardened, precisely matching the constraint that a compromised workstation must never initiate connections to them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network address translation between the business network and the controller subnet with private addressing
Why it's wrong here
NAT hides internal addressing and can complicate inbound reachability, but it is not a security control and does not enforce direction or identity. A compromised host that knows or discovers the translated address can still initiate sessions. It also breaks some industrial protocols that embed IP addresses in payloads, creating operational risk without delivering the required isolation.
- ✗
An intrusion prevention system deployed inline on the business network with industrial protocol signatures
Why it's wrong here
An IPS can detect and block known exploit patterns, but it is signature-dependent and cannot reliably stop novel or legitimate-looking traffic to the controllers. It also inspects flows rather than enforcing a strict directional boundary. A capable attacker can craft traffic that evades signatures, so the unpatched controllers remain reachable and exposed to lateral movement from a compromised workstation.
- ✓
A unidirectional gateway enforcing one-way data flow from the controller network out to the historian
Why this is correct
A unidirectional gateway physically or logically enforces one-way traffic, so controllers can emit telemetry toward the historian while no path exists for inbound connections from the business network. This directly satisfies the requirement to block workstation-initiated access to unpatched controllers. It is purpose-built for this exact industrial constraint, where endpoints cannot defend themselves.
- ✗
A stateful firewall rule permitting any internal source to reach the controller subnet on the industrial protocol port
Why it's wrong here
Permitting any internal source to reach the controllers on the industrial protocol port directly enables the lateral movement the architect is trying to stop. A compromised business workstation would be an allowed source. Stateful inspection tracks sessions for return traffic, but it does not enforce the directional, identity-based restriction needed to protect unpatched controllers from initiating hosts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.