CAS-004 Security Architecture Practice Question
An organization is implementing a software-defined perimeter (SDP) for zero trust network access. Which THREE characteristics are typical of an SDP architecture? (Choose three.)
⚠ Common exam trap
CAS-005 often tests the misconception that SDP is just a next-gen VPN or firewall, when its defining trait is application invisibility and identity-based per-session tunnels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Applications are invisible to unauthorized users
Option B is correct because a core SDP principle is the "dark cloud" or black cloud model, where protected applications do not respond to unauthenticated probes and remain invisible until a user and device are authenticated and authorized by the controller. Option C is correct because SDP establishes dynamic, per-session encrypted connections (for example, mutual TLS or DTLS tunnels) between the initiating host and the accepting host, rather than granting broad network-level access. Option E is correct because SDP enforces device authentication and posture checks through the controller before any connection to the accepting host is brokered, which is fundamental to zero trust network access. Option A is not correct because SDP deliberately moves away from static IP-based allowlists and perimeter rules, relying instead on identity- and context-based authorization. Option D is not correct because SDP does not funnel all traffic through a single shared firewall; it uses distributed controllers and gateways to broker individualized, least-privilege connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Relies on IP-based allowlists
Why it's wrong here
SDP replaces IP-based allowlists with identity- and context-based, need-to-know access, so static address ranges contradict its core premise. It is tempting because allowlists are a familiar network control, and they would suit a traditional perimeter firewall rather than a zero trust architecture.
- ✓
Applications are invisible to unauthorized users
Why this is correct
SDP employs a deny-by-default model where the controller authenticates and authorises both endpoints before any connection is brokered, so applications never respond to unauthenticated probes. This satisfies the zero trust requirement that resources remain hidden from unauthorised users, mitigating scanning and reconnaissance.
- ✓
Creates encrypted tunnels per session
Why this is correct
SDP brokers mutually authenticated, encrypted connections between the client and gateway, typically using mTLS, with each session isolated. This satisfies the zero trust principle of per-session authorisation, preventing lateral movement and ensuring traffic confidentiality even on untrusted networks.
- ✗
Uses a single shared firewall for all traffic
Why it's wrong here
A single shared firewall contradicts SDP's per-session, identity-based microtunnels, which isolate each user-to-resource connection rather than aggregating traffic through one inspection point. It is tempting because centralised firewalls genuinely suit perimeter defence, where one chokepoint filters north-south traffic; that model, however, cannot enforce the dynamic, least-privilege access SDP requires.
- ✓
Requires device authentication before granting network access
Why this is correct
SDP enforces identity-based access at the application layer, authenticating both user and device before any connection to protected resources is brokered. Device authentication therefore satisfies the zero trust requirement that no endpoint is trusted implicitly by network location.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.