Courseiva
Security Engineering →hardMultiple Select

CAS-004 Security Engineering Practice Question

A security team is deploying a zero trust architecture for an enterprise campus. The design must verify every request as though it originated from an untrusted network and must limit lateral movement after a workstation compromise. Which TWO capabilities are essential to this design? (Choose two.)

⚠ Common exam trap

The trap here is assuming that strong authentication at the perimeter, such as 802.1X or VPN login, constitutes zero trust, when the model requires ongoing per-session authorization and internal segmentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsegmentation of workloads so that east-west traffic is denied by default and allowed only by explicit policy.

Zero trust replaces location-based trust with continuous, per-session evaluation of identity and device posture, enforced by policy decision and enforcement points. Microsegmentation supports that model by denying east-west traffic by default and permitting only explicitly authorized flows, which together prevent an intruder from moving freely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implicit trust for traffic originating from the internal corporate VLAN.

    Why it's wrong here

    Implicit trust based on network location is the opposite of zero trust, which treats all requests as potentially hostile regardless of origin. Trusting the internal VLAN would let a compromised workstation move laterally without further checks, defeating the stated goal.

  • ✓

    Microsegmentation of workloads so that east-west traffic is denied by default and allowed only by explicit policy.

    Why this is correct

    Microsegmentation enforces least privilege between workloads, so a compromised workstation cannot freely reach other systems. Combined with default-deny rules, it contains an intruder and is a core mechanism for limiting lateral movement in a zero trust design.

  • ✓

    Policy decision and enforcement points that evaluate device posture and user identity for each session.

    Why this is correct

    Zero trust requires a policy decision point to evaluate context such as user identity and device health, and a policy enforcement point to allow or deny each session. This per-session evaluation is what replaces implicit trust in a network location and directly limits lateral movement.

  • ✗

    A VPN concentrator that grants full internal access after a single successful login.

    Why it's wrong here

    Granting broad access after one authentication event is the castle-and-moat model that zero trust explicitly rejects. A VPN can be part of access delivery, but full internal access after a single login violates continuous verification and enables lateral movement.

  • ✗

    A flat internal network with 802.1X port authentication at the access layer.

    Why it's wrong here

    802.1X authenticates devices to the network, which is useful, but a flat internal network still permits broad lateral movement once a device is admitted. Zero trust requires segmentation and per-session policy, not a design that assumes trust after port authentication.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.