Courseiva
Security Architecture →hardMultiple Select

CAS-004 Security Architecture Practice Question

An organization is implementing a software-defined perimeter (SDP) for zero trust network access. Which THREE characteristics are typical of an SDP architecture? (Choose three.)

⚠ Common exam trap

CAS-005 often tests the misconception that SDP is just a next-gen VPN or firewall, when its defining trait is application invisibility and identity-based per-session tunnels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Applications are invisible to unauthorized users

Option B is correct because a core SDP principle is the "dark cloud" or black cloud model, where protected applications do not respond to unauthenticated probes and remain invisible until a user and device are authenticated and authorized by the controller. Option C is correct because SDP establishes dynamic, per-session encrypted connections (for example, mutual TLS or DTLS tunnels) between the initiating host and the accepting host, rather than granting broad network-level access. Option E is correct because SDP enforces device authentication and posture checks through the controller before any connection to the accepting host is brokered, which is fundamental to zero trust network access. Option A is not correct because SDP deliberately moves away from static IP-based allowlists and perimeter rules, relying instead on identity- and context-based authorization. Option D is not correct because SDP does not funnel all traffic through a single shared firewall; it uses distributed controllers and gateways to broker individualized, least-privilege connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Relies on IP-based allowlists

    Why it's wrong here

    SDP replaces IP-based allowlists with identity- and context-based, need-to-know access, so static address ranges contradict its core premise. It is tempting because allowlists are a familiar network control, and they would suit a traditional perimeter firewall rather than a zero trust architecture.

  • ✓

    Applications are invisible to unauthorized users

    Why this is correct

    SDP employs a deny-by-default model where the controller authenticates and authorises both endpoints before any connection is brokered, so applications never respond to unauthenticated probes. This satisfies the zero trust requirement that resources remain hidden from unauthorised users, mitigating scanning and reconnaissance.

  • ✓

    Creates encrypted tunnels per session

    Why this is correct

    SDP brokers mutually authenticated, encrypted connections between the client and gateway, typically using mTLS, with each session isolated. This satisfies the zero trust principle of per-session authorisation, preventing lateral movement and ensuring traffic confidentiality even on untrusted networks.

  • ✗

    Uses a single shared firewall for all traffic

    Why it's wrong here

    A single shared firewall contradicts SDP's per-session, identity-based microtunnels, which isolate each user-to-resource connection rather than aggregating traffic through one inspection point. It is tempting because centralised firewalls genuinely suit perimeter defence, where one chokepoint filters north-south traffic; that model, however, cannot enforce the dynamic, least-privilege access SDP requires.

  • ✓

    Requires device authentication before granting network access

    Why this is correct

    SDP enforces identity-based access at the application layer, authenticating both user and device before any connection to protected resources is brokered. Device authentication therefore satisfies the zero trust requirement that no endpoint is trusted implicitly by network location.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.