Courseiva
Security Architecture →mediumMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is implementing network segmentation in a hybrid cloud environment. Which TWO controls are most effective for reducing east-west traffic risks?

⚠ Common exam trap

The trap is mixing north-south and east-west controls — candidates select perimeter firewalls or VPN concentrators, which protect the boundary or remote access, instead of controls that specifically govern lateral internal traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Micro-segmentation

Micro-segmentation (A) is correct because it applies granular, workload-level security policies—typically via host-based agents or SDN constructs—that restrict lateral (east-west) movement between workloads even inside the same subnet or VPC, directly reducing east-west risk. East-west traffic inspection (D) is correct because it examines internal traffic flows (e.g., via next-generation firewalls, IDS/IPS, or virtual taps) to detect and block lateral movement, malicious scanning, and exfiltration that perimeter controls would miss. VPN concentrator (B) is not correct because it secures remote-access or site-to-site north-south connectivity, not internal lateral traffic. NAT gateway (C) is not correct because it provides outbound internet address translation and does not inspect or segment internal east-west flows. Perimeter firewall (E) is not correct because it primarily enforces north-south boundary controls and does not address lateral movement within the segmented environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Micro-segmentation

    Why this is correct

    Micro-segmentation enforces granular firewall rules at the workload or pod level, using distributed virtual firewalls or network security groups to restrict lateral movement between application tiers. This directly reduces east-west traffic risks in a hybrid cloud by limiting the blast radius of a compromised host, satisfying the constraint of controlling internal, cross-subnet communication rather than perimeter ingress.

  • ✗

    VPN concentrator

    Why it's wrong here

    A VPN concentrator terminates encrypted tunnels for remote or site-to-site connectivity, not internal segmentation between workloads. It is tempting because it sits on the network path, and it would be correct for securing traffic between an on-premises site and the cloud over an untrusted link.

  • ✗

    NAT gateway

    Why it's wrong here

    A NAT gateway translates source addresses for outbound internet access; it enforces no policy between internal segments. It is tempting because it is a network component in the traffic path, and it would be correct for giving private subnets outbound internet connectivity without exposing them inbound.

  • ✓

    East-west traffic inspection

    Why this is correct

    East-west traffic inspection examines lateral traffic between internal workloads, detecting compromised hosts, lateral movement and policy violations that perimeter controls miss. This directly reduces east-west risk in the segmented hybrid environment described in the stem.

  • ✗

    Perimeter firewall

    Why it's wrong here

    A perimeter firewall filters north-south traffic crossing the network boundary, so it cannot inspect lateral east-west flows between internal segments. It is tempting because it is the classic edge defence, and it would be correct for controlling traffic entering or leaving the environment from the internet.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.