Courseiva
hardMultiple SelectObjective-mapped

CAS-004 Practice Question: A security architect is reviewing the network…

A security architect is reviewing the network security controls for a critical industrial control system (ICS) environment. The architect must select two controls that are most effective at preventing unauthorized access to the ICS network from the corporate IT network, while still allowing necessary monitoring traffic. Which TWO controls should be implemented? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates choose a VPN (Option A) thinking encryption equals security, but encryption does not prevent unauthorized access—it only protects data in transit, and a VPN still allows bidirectional communication, which is the opposite of what is needed for ICS isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy a unidirectional gateway (data diode) between the networks

A unidirectional gateway (data diode) physically enforces one-way data flow, ensuring that no traffic can originate from the corporate IT network into the ICS network. This prevents unauthorized access while allowing monitoring data (e.g., syslog, SNMP traps) to be sent out from the ICS side. It is the most effective control for preventing any inbound attack vectors while preserving outbound monitoring traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure a site-to-site VPN from the corporate network to the ICS network

    Why it's wrong here

    VPN would allow inbound connections, increasing risk.

  • Implement a network-based intrusion prevention system (IPS) on the ICS network

    Why it's wrong here

    IPS is reactive and may not prevent all unauthorized access.

  • Deploy a unidirectional gateway (data diode) between the networks

    Why this is correct

    Ensures traffic can only flow out, preventing inbound access.

  • Place a bastion host in a DMZ accessible from both networks for monitoring traffic

    Why this is correct

    Allows necessary monitoring without exposing the ICS network directly.

  • Segment the networks using VLANs only

    Why it's wrong here

    VLANs without additional controls can be bypassed.

About these practice questions

One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.