Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

An organization is adopting SASE to converge network and security functions. Which component of SASE provides secure web gateway (SWG) capabilities?

⚠ Common exam trap

CAS-005 often tests whether candidates can map each SASE capability to its correct component, so they must not confuse SWG (web filtering) with CASB (cloud app governance) or ZTNA (private app access).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secure Web Gateway

Secure Web Gateway (SWG) is itself the SASE component that provides SWG capabilities — it filters web traffic, enforces URL categorization, blocks malicious content, and applies acceptable-use policies. In SASE architectures, SWG is one of the core security pillars delivered from the cloud edge, alongside CASB, ZTNA, and FWaaS. ZTNA, SD-WAN, and CASB serve different functions and do not deliver SWG's web filtering and threat inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ZTNA

    Why it's wrong here

    ZTNA grants per-application access based on identity and device posture; it performs no URL categorisation, TLS inspection or web content filtering. It is tempting because ZTNA is a SASE security component, but SWG functions belong to the secure web gateway.

  • ✗

    SD-WAN

    Why it's wrong here

    SD-WAN handles transport selection, path optimisation and policy-based routing between sites; it inspects no web content and enforces no URL categories. It is tempting as a SASE networking pillar, but SWG capability requires the secure web gateway.

  • ✓

    Secure Web Gateway

    Why this is correct

    The secure web gateway is the SASE component that inspects and filters web traffic, enforcing acceptable-use and malware policies. Converging it into SASE delivers SWG filtering from the cloud edge, satisfying the requirement to combine network and security functions in one architecture.

  • ✗

    CASB

    Why it's wrong here

    CASB governs sanctioned and unsanctioned cloud application usage, applying data loss and access policies to SaaS traffic rather than filtering general web destinations. It is tempting because CASB is inline at the SASE edge, but URL filtering is the secure web gateway's role.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.