Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

An organization is implementing a Secure Access Service Edge (SASE) architecture. Which of the following is a key component of SASE?

⚠ Common exam trap

CAS-005 often tests whether candidates can distinguish SASE's core components (CASB, SWG, ZTNA, FWaaS, SD-WAN) from legacy security appliances like DMZ, IPS, and VPN that SASE replaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Access Security Broker (CASB)

SASE (Secure Access Service Edge) converges networking (SD-WAN) with a stack of cloud-delivered security services, and CASB is one of its core security pillars alongside SWG, ZTNA, and FWaaS. CASB provides visibility and control over cloud application usage, enforces DLP, and detects shadow IT — functions that SASE delivers from a globally distributed edge. DMZ, IPS, and VPN are traditional on-premises or point-solution constructs that SASE is explicitly designed to replace or absorb, not core defining components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Demilitarized Zone (DMZ)

    Why it's wrong here

    A DMZ is a network segmentation zone for hosting externally reachable services behind firewalls; SASE converges SD-WAN with cloud-delivered SWG, CASB, ZTNA and FWaaS. A DMZ would be the correct design element for exposing public-facing servers in a traditional perimeter architecture.

  • ✓

    Cloud Access Security Broker (CASB)

    Why this is correct

    A CASB enforces data-security policy between users and cloud services, delivering the threat protection, data-loss prevention and visibility SASE requires for cloud-bound traffic. It satisfies the stem's SASE component requirement because SASE converges networking with exactly these cloud-security functions, alongside SWG, ZTNA and FWaaS, rather than relying on on-premises appliances.

  • ✗

    Intrusion Prevention System (IPS)

    Why it's wrong here

    An IPS is a detection and prevention capability that SASE may deliver through FWaaS, but it is not itself a defining SASE component alongside SD-WAN, SWG, CASB and ZTNA. It is tempting because IPS protects traffic inline, which would be correct when securing a conventional network perimeter with dedicated appliances.

  • ✗

    Virtual Private Network (VPN)

    Why it's wrong here

    A VPN provides encrypted remote access to a network, whereas SASE replaces this hub-and-spoke model with identity-based ZTNA and cloud-delivered security services. It is tempting because VPNs are the traditional remote-access mechanism, and would be correct for connecting a small workforce to a single on-premises network.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.