CAS-004 Security Architecture Practice Question
A security architect is implementing a zero trust model for a financial services company. The goal is to prevent lateral movement in the data center. Which approach best achieves this objective?
⚠ Common exam trap
The trap is selecting a broad zero trust principle (identity-centric controls, defense-in-depth) instead of the specific technical control — micro-segmentation — that directly addresses lateral movement in the data center.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploying micro-segmentation to isolate workloads and enforce granular policies
Micro-segmentation isolates workloads and enforces granular, identity- and label-based policies on east-west traffic, which directly prevents lateral movement inside the data center. In a zero trust model, micro-segmentation operationalizes the 'never trust, always verify' principle at the workload level, so a compromised host cannot freely reach other workloads. This is the most direct and effective control for the stated objective of stopping lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a software-defined perimeter to hide network resources
Why it's wrong here
A software-defined perimeter hides resources from unauthenticated scanners, yet once a user or workload is admitted, east-west traffic between data centre segments remains reachable. It suits protecting externally exposed services; stopping lateral movement needs every request evaluated against identity and policy, not network concealment.
- ✗
Implementing identity-centric access controls across all resources
Why it's wrong here
Identity-centric controls authenticate and authorise users, yet lateral movement between workloads occurs over east-west traffic that identity alone does not segment. Microsegmentation of workload-to-workload flows is what blocks that path; identity-centric access is correct for protecting resource access from users, not server-to-server traversal.
- ✗
Applying defense-in-depth layering by adding multiple security controls
Why it's wrong here
Layering controls hardens individual assets but leaves implicit trust between them, so a compromised host can still reach peers. Defence-in-depth suits compliance baselines and breach containment generally; preventing lateral movement requires per-request, identity-based authorisation of each connection rather than stacked perimeter controls.
- ✓
Deploying micro-segmentation to isolate workloads and enforce granular policies
Why this is correct
Micro-segmentation enforces least-privilege east-west controls between individual workloads, so a compromised host cannot reach unrelated systems. This directly satisfies the stem's constraint of preventing lateral movement inside the data centre, unlike perimeter or identity-only controls that leave internal traffic largely trusted.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.