Courseiva
Security Architecture →hardMultiple Select

CAS-004 Security Architecture Practice Question

An organization is migrating to a zero trust model and wants to implement identity-centric security. Which THREE of the following are key principles of an identity-centric zero trust approach? (Select THREE.)

⚠ Common exam trap

CAS-005 often tests the confusion between zero trust and traditional perimeter security — candidates pick 'implicit trust based on network location' or 'static firewall perimeter' because those are familiar concepts, missing that zero trust explicitly rejects both.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege access with just-in-time privileges

Option B is correct because identity-centric zero trust enforces least privilege access, granting users only the minimum permissions needed and elevating privileges just-in-time rather than permanently, which limits the blast radius of compromised accounts. Option C is correct because zero trust requires continuous verification of identity and device health on every access request, rather than trusting a session once authenticated, using signals such as device compliance and risk scores. Option D is correct because MFA for all users strengthens identity assurance by requiring multiple factors, directly supporting the identity-centric principle that no user is trusted by default. Option A is incorrect because implicit trust based on network location is the opposite of zero trust, which assumes no implicit trust regardless of where the request originates. Option E is incorrect because a single static firewall perimeter reflects the traditional castle-and-moat model, whereas zero trust replaces perimeter-based trust with identity- and policy-based controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implicit trust based on network location

    Why it's wrong here

    Implicit trust from network location contradicts zero trust, which treats every request as untrusted until verified regardless of origin. Identity-centric models verify explicitly using identity signals. Implicit network-based trust would be correct in traditional perimeter models where internal networks were considered safe.

  • ✓

    Least privilege access with just-in-time privileges

    Why this is correct

    Standing admin rights violate zero trust's assume-breach stance. Just-in-time privilege elevation grants access only when needed, then revokes it, shrinking the blast radius of compromised accounts. This directly satisfies the identity-centric requirement that entitlements are scoped and time-bound rather than permanent.

  • ✓

    Continuous verification of identity and device health

    Why this is correct

    Zero trust never grants implicit trust based on network location. Continuously re-evaluating user identity signals and device health posture on every access request satisfies the identity-centric constraint, so sessions are reauthorised rather than trusted once at login.

  • ✓

    Multi-factor authentication (MFA) for all users

    Why this is correct

    MFA enforces strong authentication for every user, removing reliance on single-factor credentials that attackers replay. Requiring a second factor satisfies the identity-centric principle that identity is the primary control plane, since access decisions hinge on verified identity rather than network perimeter.

  • ✗

    Single static firewall perimeter

    Why it's wrong here

    A single static firewall perimeter assumes everything inside is trusted, which zero trust rejects; identity-centric security evaluates each request against identity, device and context signals. Static perimeter defence would be correct for legacy castle-and-moat architectures, not for identity-centric zero trust.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.