CAS-004 Security Architecture Practice Question
An organization is implementing a Secure Access Service Edge (SASE) architecture to support remote workers. Which key capability does SASE provide that traditional VPNs lack?
⚠ Common exam trap
Test-takers frequently confuse SASE with traditional security or networking features that are components but not the key differentiator; candidates often pick SD-WAN or encryption because they are familiar, missing the zero trust identity-based access emphasis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity-based access with zero trust principles
SASE converges networking and security functions into a cloud-delivered service, with zero trust network access (ZTNA) as a core pillar. Unlike traditional VPNs that grant broad network-level access after authentication, SASE enforces identity-based, context-aware access policies per application or resource. This aligns with zero trust principles: never trust, always verify, and least-privilege access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Software-defined WAN (SD-WAN) functionality
Why it's wrong here
SD-WAN optimises and routes branch and WAN traffic; it does not deliver the cloud-delivered security inspection that distinguishes SASE from VPNs. It is correct when an organisation needs dynamic path selection across multiple WAN links for branch connectivity.
- ✗
Network-layer encryption using IPsec
Why it's wrong here
IPsec encryption is already the core of most traditional VPNs, so it cannot be the capability SASE adds. It is tempting because IPsec genuinely secures site-to-site and remote-access tunnels, and would be the right answer if the question asked how legacy VPNs protect traffic in transit.
- ✓
Identity-based access with zero trust principles
Why this is correct
SASE couples identity-based, zero trust access with cloud-delivered security inspection, evaluating each session against user identity and device posture rather than granting broad network reach. Traditional VPNs authenticate once and then place the user on the network, which is the gap the stem highlights.
- ✗
Web content filtering and DLP
Why it's wrong here
Web filtering and DLP are delivered by secure web gateways and standalone DLP products, which traditional VPN stacks can integrate; SASE's distinguishing capability is converged identity-based policy enforcement at the cloud edge. Filtering would be correct if the question asked which control blocks malicious sites or data exfiltration.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.