CAS-004 Security Architecture Practice Question
An organization is adopting SASE to converge network and security functions. Which component of SASE provides secure web gateway (SWG) capabilities?
⚠ Common exam trap
CAS-005 often tests whether candidates can map each SASE capability to its correct component, so they must not confuse SWG (web filtering) with CASB (cloud app governance) or ZTNA (private app access).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure Web Gateway
Secure Web Gateway (SWG) is itself the SASE component that provides SWG capabilities — it filters web traffic, enforces URL categorization, blocks malicious content, and applies acceptable-use policies. In SASE architectures, SWG is one of the core security pillars delivered from the cloud edge, alongside CASB, ZTNA, and FWaaS. ZTNA, SD-WAN, and CASB serve different functions and do not deliver SWG's web filtering and threat inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ZTNA
Why it's wrong here
ZTNA grants per-application access based on identity and device posture; it performs no URL categorisation, TLS inspection or web content filtering. It is tempting because ZTNA is a SASE security component, but SWG functions belong to the secure web gateway.
- ✗
SD-WAN
Why it's wrong here
SD-WAN handles transport selection, path optimisation and policy-based routing between sites; it inspects no web content and enforces no URL categories. It is tempting as a SASE networking pillar, but SWG capability requires the secure web gateway.
- ✓
Secure Web Gateway
Why this is correct
The secure web gateway is the SASE component that inspects and filters web traffic, enforcing acceptable-use and malware policies. Converging it into SASE delivers SWG filtering from the cloud edge, satisfying the requirement to combine network and security functions in one architecture.
- ✗
CASB
Why it's wrong here
CASB governs sanctioned and unsanctioned cloud application usage, applying data loss and access policies to SaaS traffic rather than filtering general web destinations. It is tempting because CASB is inline at the SASE edge, but URL filtering is the secure web gateway's role.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.