Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

An organization is adopting a SASE architecture to provide secure access to cloud applications. Which component is essential for enforcing security policies based on user identity and device posture?

⚠ Common exam trap

CAS-005 often tests the confusion between SASE components. Candidates may select CASB or SWG because they are also part of SASE, but only ZTNA enforces policies based on user identity and device posture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Zero Trust Network Access (ZTNA)

Zero Trust Network Access (ZTNA) is essential for enforcing security policies based on user identity and device posture in a SASE architecture. ZTNA provides secure, identity-based access to applications, ensuring that only authenticated and authorized users with compliant devices can connect, regardless of location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Zero Trust Network Access (ZTNA)

    Why this is correct

    ZTNA brokers each session, verifying user identity and device posture before granting least-privilege access to specific applications rather than the whole network. This identity- and posture-based policy enforcement satisfies the SASE requirement, unlike IP-centric VPNs or proxy-only controls.

  • ✗

    Firewall as a Service (FWaaS)

    Why it's wrong here

    FWaaS filters traffic by IP, port and protocol at the network layer; it cannot evaluate user identity or device posture, which requires a policy engine consuming identity-provider and endpoint signals. It is tempting because FWaaS delivers the cloud-delivered perimeter controls SASE consolidates, and would be correct where the requirement is uniform network-level filtering rather than identity-aware access decisions.

  • ✗

    Secure Web Gateway (SWG)

    Why it's wrong here

    SWG filters web traffic and enforces acceptable use policies, but not specifically identity-based access.

  • ✗

    Cloud Access Security Broker (CASB)

    Why it's wrong here

    CASB enforces data and threat policy on sanctioned cloud services, discovering shadow IT and applying DLP, but it does not itself evaluate device posture to gate access. It is tempting because CASB is a SASE pillar handling cloud-application security, and would be correct where the requirement is governing SaaS usage and data flows rather than identity-plus-posture admission control.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.