CAS-004 Security Architecture Practice Question
An organization is implementing network segmentation to limit lateral movement. It wants to isolate application tiers at the virtual network level in a cloud environment. Which technology enforces policies on east-west traffic between VMs in different subnets?
⚠ Common exam trap
CAS-005 often tests the confusion between connectivity technologies (VPN, TLS) and segmentation technologies (micro-segmentation) — candidates must recognise that only micro-segmentation enforces east-west policies between VMs in different subnets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Micro-segmentation
Micro-segmentation enforces security policies at the virtual network level, isolating workloads (e.g., VMs in different subnets) and controlling east-west traffic between them. It typically uses distributed firewalls or security groups applied to individual workloads, allowing granular policy enforcement regardless of subnet boundaries. This directly limits lateral movement by ensuring that even if an attacker compromises one VM, they cannot freely communicate with others.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Micro-segmentation
Why this is correct
Micro-segmentation enforces granular, workload-level policies on east-west traffic, isolating application tiers across subnets within a virtual network. Unlike perimeter controls, it inspects inter-VM flows directly, satisfying the requirement to limit lateral movement between tiers at the virtual network level.
- ✗
Transport Layer Security (TLS)
Why it's wrong here
TLS encrypts data in transit but does not enforce segmentation.
- ✗
Virtual Private Network (VPN)
Why it's wrong here
A VPN encrypts traffic over untrusted transport between endpoints or gateways; it does not apply east-west policy between subnets inside a virtual network. It is tempting because VPNs do segment remote access, and would be correct for connecting branch offices or remote users to cloud resources.
- ✗
Secure Access Service Edge (SASE)
Why it's wrong here
SASE converges WAN edge and security services for user and branch traffic to external destinations; it does not enforce subnet-level east-west rules between VMs. It is tempting because SASE includes firewall capability, and would be correct for securing distributed user access to SaaS and internet resources.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.