Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

An organization is implementing a Secure Access Service Edge (SASE) architecture to support remote workers. Which key capability does SASE provide that traditional VPNs lack?

⚠ Common exam trap

Test-takers frequently confuse SASE with traditional security or networking features that are components but not the key differentiator; candidates often pick SD-WAN or encryption because they are familiar, missing the zero trust identity-based access emphasis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity-based access with zero trust principles

SASE converges networking and security functions into a cloud-delivered service, with zero trust network access (ZTNA) as a core pillar. Unlike traditional VPNs that grant broad network-level access after authentication, SASE enforces identity-based, context-aware access policies per application or resource. This aligns with zero trust principles: never trust, always verify, and least-privilege access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Software-defined WAN (SD-WAN) functionality

    Why it's wrong here

    SD-WAN optimises and routes branch and WAN traffic; it does not deliver the cloud-delivered security inspection that distinguishes SASE from VPNs. It is correct when an organisation needs dynamic path selection across multiple WAN links for branch connectivity.

  • ✗

    Network-layer encryption using IPsec

    Why it's wrong here

    IPsec encryption is already the core of most traditional VPNs, so it cannot be the capability SASE adds. It is tempting because IPsec genuinely secures site-to-site and remote-access tunnels, and would be the right answer if the question asked how legacy VPNs protect traffic in transit.

  • ✓

    Identity-based access with zero trust principles

    Why this is correct

    SASE couples identity-based, zero trust access with cloud-delivered security inspection, evaluating each session against user identity and device posture rather than granting broad network reach. Traditional VPNs authenticate once and then place the user on the network, which is the gap the stem highlights.

  • ✗

    Web content filtering and DLP

    Why it's wrong here

    Web filtering and DLP are delivered by secure web gateways and standalone DLP products, which traditional VPN stacks can integrate; SASE's distinguishing capability is converged identity-based policy enforcement at the cloud edge. Filtering would be correct if the question asked which control blocks malicious sites or data exfiltration.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.