Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

An organization is implementing network segmentation to limit lateral movement. It wants to isolate application tiers at the virtual network level in a cloud environment. Which technology enforces policies on east-west traffic between VMs in different subnets?

⚠ Common exam trap

CAS-005 often tests the confusion between connectivity technologies (VPN, TLS) and segmentation technologies (micro-segmentation) — candidates must recognise that only micro-segmentation enforces east-west policies between VMs in different subnets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Micro-segmentation

Micro-segmentation enforces security policies at the virtual network level, isolating workloads (e.g., VMs in different subnets) and controlling east-west traffic between them. It typically uses distributed firewalls or security groups applied to individual workloads, allowing granular policy enforcement regardless of subnet boundaries. This directly limits lateral movement by ensuring that even if an attacker compromises one VM, they cannot freely communicate with others.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Micro-segmentation

    Why this is correct

    Micro-segmentation enforces granular, workload-level policies on east-west traffic, isolating application tiers across subnets within a virtual network. Unlike perimeter controls, it inspects inter-VM flows directly, satisfying the requirement to limit lateral movement between tiers at the virtual network level.

  • ✗

    Transport Layer Security (TLS)

    Why it's wrong here

    TLS encrypts data in transit but does not enforce segmentation.

  • ✗

    Virtual Private Network (VPN)

    Why it's wrong here

    A VPN encrypts traffic over untrusted transport between endpoints or gateways; it does not apply east-west policy between subnets inside a virtual network. It is tempting because VPNs do segment remote access, and would be correct for connecting branch offices or remote users to cloud resources.

  • ✗

    Secure Access Service Edge (SASE)

    Why it's wrong here

    SASE converges WAN edge and security services for user and branch traffic to external destinations; it does not enforce subnet-level east-west rules between VMs. It is tempting because SASE includes firewall capability, and would be correct for securing distributed user access to SaaS and internet resources.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.