CAS-004 Security Architecture Practice Question
A security architect is reviewing the network design for a new branch office. The organization wants to ensure that all traffic from the branch is inspected for malware and that users are authenticated before accessing cloud applications, regardless of their location. Which technology should the architect recommend?
⚠ Common exam trap
The trap here is assuming that an NGFW or VPN concentrator alone can provide both malware inspection and identity-based authentication for cloud access, when they typically require backhauling and lack integrated zero trust capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Secure Access Service Edge (SASE) solution with integrated secure web gateway and zero trust network access
SASE delivers converged network and security services from the cloud, including secure web gateway for malware inspection and zero trust network access for user authentication. It enforces policy consistently for users anywhere, without backhauling traffic. This directly satisfies the branch office requirements for inspection and authentication before cloud access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A remote access VPN concentrator at headquarters with split tunneling disabled
Why it's wrong here
A VPN concentrator with split tunneling disabled forces all branch traffic through headquarters, where it can be inspected. However, this backhauling increases latency and does not provide identity-based authentication for cloud applications. It also does not scale well for cloud access, so it fails to meet the requirement for consistent, location-independent enforcement.
- ✗
A software-defined wide area network (SD-WAN) overlay with local internet breakout
Why it's wrong here
SD-WAN improves connectivity and can enable local internet breakout, but it does not inherently provide security inspection or user authentication. Without integrated security services, branch traffic could bypass inspection. The scenario requires malware inspection and authentication, which SD-WAN alone does not deliver.
- ✓
A Secure Access Service Edge (SASE) solution with integrated secure web gateway and zero trust network access
Why this is correct
SASE converges network and security functions in the cloud, providing secure web gateway for malware inspection and zero trust network access for user authentication before accessing applications. It enforces policy consistently regardless of user location, meeting the branch's needs without backhauling traffic. This makes it the correct recommendation.
- ✗
A next-generation firewall (NGFW) at the branch perimeter with IPsec VPN to headquarters
Why it's wrong here
An NGFW at the branch inspects traffic leaving the branch, but it does not provide consistent policy enforcement for users accessing cloud applications directly from the internet. It also requires backhauling traffic to headquarters for inspection, which can degrade performance. It does not inherently authenticate users before cloud access, so it does not meet the requirement.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.