CAS-004 Security Engineering Practice Question
A security engineer is implementing a zero trust architecture for a corporate network. The engineer must ensure that all access requests are continuously verified and that least privilege is enforced. Which TWO components are essential to achieve these goals? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse network security devices like VPNs and firewalls with the core zero trust control plane components that actually enforce dynamic access decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A policy administrator that establishes and maintains the trust relationship between the subject and the resource.
Zero trust architecture relies on a policy engine to make dynamic access decisions based on context, and a policy administrator to enforce those decisions by configuring the data plane. These two components form the control plane and are essential for continuous verification and least privilege. Other options like VPN, NGFW, and SIEM are supporting technologies but not core to the zero trust access decision process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A VPN concentrator that provides encrypted tunnels for all remote access.
Why it's wrong here
A VPN concentrator provides encrypted connectivity but does not inherently enforce continuous verification or least privilege. Traditional VPNs often grant broad network access once authenticated, which contradicts zero trust principles. While encryption is important, a VPN alone does not satisfy the requirement for dynamic, context-aware access control.
- ✗
A next-generation firewall (NGFW) that inspects all traffic at the network perimeter.
Why it's wrong here
An NGFW provides perimeter defense and deep packet inspection, but zero trust assumes no trusted network perimeter. Relying solely on an NGFW does not provide continuous verification of user and device identity for each access request. It is a component of defense in depth but not essential for the core zero trust access decision and enforcement.
- ✓
A policy administrator that establishes and maintains the trust relationship between the subject and the resource.
Why this is correct
The policy administrator is responsible for executing the decisions made by the policy engine. It configures the data plane to allow or deny connections, often by instructing gateways or agents. It is essential for enforcing least privilege because it dynamically provisions access based on the policy engine's verdict. Together with the policy engine, it forms the control plane.
- ✗
A security information and event management (SIEM) system that aggregates logs for analysis.
Why it's wrong here
A SIEM is valuable for monitoring and detecting threats, but it is not a core component for enforcing access decisions. It does not participate in the real-time allow/deny decision for each request. While it supports continuous monitoring, it is not essential for the continuous verification and least privilege enforcement mechanisms themselves.
- ✓
A policy engine that evaluates access requests based on identity, device posture, and context.
Why this is correct
A policy engine is the decision-making component in zero trust. It evaluates each access request against policies that consider user identity, device health, location, and other contextual factors. Without it, continuous verification and least privilege cannot be enforced dynamically. It is a core component of the zero trust control plane.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.