Courseiva
Security Engineering →hardMultiple Select

CAS-004 Security Engineering Practice Question

A security engineer is deploying a zero trust architecture for a hybrid cloud environment. The organization wants to enforce least privilege access to internal APIs. The engineer must select TWO mechanisms that provide continuous authentication and authorization for each API request. (Choose two.)

⚠ Common exam trap

The trap here is equating network-level controls like IP allowlisting or long-lived tokens with continuous per-request identity verification, which zero trust explicitly rejects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mutual TLS (mTLS) with short-lived client certificates issued by an internal CA.

Continuous authentication and authorization in zero trust require identity-based mechanisms that evaluate every request. Mutual TLS with short-lived certificates verifies the client's identity cryptographically, while a service mesh sidecar enforces per-request authorization policies based on workload identity. Together, they ensure that each API call is authenticated and authorized based on dynamic policy, not static network trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mutual TLS (mTLS) with short-lived client certificates issued by an internal CA.

    Why this is correct

    mTLS ensures that both the client and server authenticate each other using certificates. Short-lived certificates limit the window of compromise and force frequent re-authentication, aligning with zero trust principles. This mechanism provides strong identity verification for each API request, and when combined with a policy engine, enables continuous authorization decisions based on certificate attributes.

  • ✗

    OAuth 2.0 access tokens with a one-hour expiry and no refresh tokens.

    Why it's wrong here

    While OAuth 2.0 tokens can carry authorization claims, a one-hour expiry without refresh tokens does not provide continuous authentication per request; the token remains valid until expiry. It also does not authenticate the client device or user beyond the initial token issuance. For continuous authorization, token introspection or short-lived tokens with frequent reissuance would be needed, but this option alone is insufficient.

  • ✗

    Static API keys stored in a configuration file and rotated every 90 days.

    Why it's wrong here

    Static API keys are long-lived credentials that do not provide continuous authentication or authorization. If compromised, they can be used until rotated, and they are often shared across services, violating least privilege. They do not carry identity context for per-request policy decisions, making them unsuitable for a zero trust architecture.

  • ✓

    A service mesh sidecar proxy that enforces per-request authorization policies based on workload identity.

    Why this is correct

    A service mesh sidecar intercepts every request and can enforce fine-grained authorization policies based on workload identity (e.g., SPIFFE IDs). This provides continuous authorization at the request level, independent of network location. It aligns with zero trust by verifying identity and policy for each call, and it can integrate with external policy engines for dynamic decisions.

  • ✗

    IP allowlisting based on the source subnet of the API caller.

    Why it's wrong here

    IP allowlisting relies on network location, which is explicitly discouraged in zero trust because it assumes the network is trustworthy. It does not authenticate the user or workload and can be bypassed through compromised hosts within the allowed subnet. It also fails to provide per-request authorization or identity verification.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.