CAS-004 Security Architecture Practice Question
A security architect is implementing a zero trust model for a financial services company. The goal is to prevent lateral movement in the data center. Which approach best achieves this objective?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploying micro-segmentation to isolate workloads and enforce granular policies
Micro-segmentation divides the network into small, isolated segments to restrict lateral movement, which is a key zero trust principle. Software-defined perimeter (SDP) focuses on user-to-resource access, but micro-segmentation directly limits east-west traffic. Defense-in-depth is broader and not specific to lateral movement. Identity-centric access controls user authentication but does not prevent lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a software-defined perimeter to hide network resources
Why it's wrong here
Software-defined perimeter hides resources from unauthorized users but does not segment internal traffic to prevent lateral movement.
- ✗
Implementing identity-centric access controls across all resources
Why it's wrong here
Identity-centric access controls focus on authentication and authorization but do not directly segment the network to prevent lateral movement.
- ✗
Applying defense-in-depth layering by adding multiple security controls
Why it's wrong here
Defense-in-depth is a general strategy involving multiple layers of defense, but it does not specifically address lateral movement like micro-segmentation does.
- ✓
Deploying micro-segmentation to isolate workloads and enforce granular policies
Why this is correct
Micro-segmentation creates small network segments, allowing fine-grained policy enforcement that restricts lateral movement between workloads.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.