Courseiva
Security Architecture →mediumMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is implementing a zero trust architecture for a corporate network. Which TWO principles are fundamental to the zero trust approach? (Choose two.)

⚠ Common exam trap

CAS-005 often tests the misconception that zero trust is about strengthening the perimeter or trusting internal users more; the trap is confusing traditional perimeter security (like firewalls) with zero trust principles, leading candidates to select options that reinforce implicit trust or location-based access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify every access request regardless of source

Option D is correct because zero trust requires that every access request be authenticated and authorized explicitly, regardless of whether it originates inside or outside the traditional network perimeter—no user or device is trusted by default. Option E is correct because least privilege access is a core zero trust principle, granting users and devices only the minimum permissions needed for their tasks and limiting lateral movement if credentials are compromised. Options A, B, and C are incorrect because they reflect perimeter-based, castle-and-moat security models: granting access by network location, assuming implicit trust for internal users, and relying on a single perimeter firewall all contradict zero trust's 'never trust, always verify' philosophy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant access based on network location

    Why it's wrong here

    Zero trust rejects network location as a trust signal, so granting access by network location contradicts its core tenet of evaluating every request on identity and context. It is tempting because perimeter-based designs historically trusted internal subnets, and this would be correct for a traditional castle-and-moat architecture.

  • ✗

    Assume implicit trust for internal users

    Why it's wrong here

    Zero trust explicitly removes implicit trust, requiring continuous verification of every user and device regardless of internal or external position. It is tempting because legacy designs trusted users inside the corporate network, and this would be correct for a perimeter-based model rather than a zero trust one.

  • ✗

    Use a single perimeter firewall

    Why it's wrong here

    A single perimeter firewall assumes a defined network edge, whereas zero trust treats the network as hostile and enforces policy per resource through identity-based controls. It is tempting because firewalls remain valuable for traffic filtering, and this would be correct for a perimeter-defence question rather than a zero trust principle.

  • ✓

    Verify every access request regardless of source

    Why this is correct

    Zero trust treats network location as insufficient evidence of trust, so every access request is authenticated and authorised explicitly, regardless of whether it originates inside or outside the corporate perimeter. Continuous verification replaces the implicit trust granted by legacy castle-and-moat designs.

  • ✓

    Implement least privilege access

    Why this is correct

    Least privilege access enforces zero trust by granting identities only the permissions needed for each task, limiting lateral movement if credentials are compromised. This directly satisfies the architecture's requirement that no user or device be implicitly trusted, restricting blast radius across the corporate network.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.