CAS-004 Security Architecture Practice Question
A security architect is evaluating a SASE solution. Which capability is expected to be part of a SASE platform?
⚠ Common exam trap
CAS-005 often tests whether candidates can distinguish legacy on-premises controls (IPS appliances, VPN concentrators, VLANs) from the cloud-delivered converged services that define SASE — SWG is the canonical correct answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure web gateway (SWG)
Secure Web Gateway (SWG) is one of the core converged capabilities of a SASE platform, alongside CASB, ZTNA, FWaaS, and SD-WAN. SASE merges network and security functions into a cloud-delivered service, and SWG provides web filtering, malware inspection, and policy enforcement for user web traffic. It is explicitly expected in a SASE architecture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Intrusion prevention system (IPS) at the data center
Why it's wrong here
SASE converges security into a cloud-delivered edge, so an IPS appliance anchored in the data centre fails the scenario's requirement for inspection at the point of access. It is tempting because IPS is a genuine SASE security component, but only when delivered as a cloud service rather than on-premises hardware.
- ✗
Network segmentation via VLANs
Why it's wrong here
SASE delivers identity-centric, cloud-enforced policy rather than Layer 2 segmentation, so VLANs tied to physical network topology fail the scenario's requirement for consistent control of remote and branch users. It is tempting because segmentation is a real SASE outcome, achieved through software-defined microsegmentation instead.
- ✓
Secure web gateway (SWG)
Why this is correct
Secure web gateway is a core SASE capability, filtering web traffic and enforcing acceptable-use and threat policies at the cloud edge. SASE converges SWG with CASB, ZTNA and FWaaS, so SWG satisfies the expected-capability constraint rather than endpoint or on-premises controls.
- ✗
Virtual private network (VPN) concentrator
Why it's wrong here
SASE replaces hub-and-spoke backhauling with direct cloud-delivered access, so a VPN concentrator funnelling traffic to a central point fails the scenario's requirement for local internet breakout. It is tempting because VPNs do provide encrypted remote access, which SASE supersedes with zero trust network access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.