CAS-004 Security Architecture Practice Question
An organization is migrating to a zero trust model and wants to implement identity-centric security. Which THREE of the following are key principles of an identity-centric zero trust approach? (Select THREE.)
⚠ Common exam trap
CAS-005 often tests the confusion between zero trust and traditional perimeter security — candidates pick 'implicit trust based on network location' or 'static firewall perimeter' because those are familiar concepts, missing that zero trust explicitly rejects both.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege access with just-in-time privileges
Option B is correct because identity-centric zero trust enforces least privilege access, granting users only the minimum permissions needed and elevating privileges just-in-time rather than permanently, which limits the blast radius of compromised accounts. Option C is correct because zero trust requires continuous verification of identity and device health on every access request, rather than trusting a session once authenticated, using signals such as device compliance and risk scores. Option D is correct because MFA for all users strengthens identity assurance by requiring multiple factors, directly supporting the identity-centric principle that no user is trusted by default. Option A is incorrect because implicit trust based on network location is the opposite of zero trust, which assumes no implicit trust regardless of where the request originates. Option E is incorrect because a single static firewall perimeter reflects the traditional castle-and-moat model, whereas zero trust replaces perimeter-based trust with identity- and policy-based controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implicit trust based on network location
Why it's wrong here
Implicit trust from network location contradicts zero trust, which treats every request as untrusted until verified regardless of origin. Identity-centric models verify explicitly using identity signals. Implicit network-based trust would be correct in traditional perimeter models where internal networks were considered safe.
- ✓
Least privilege access with just-in-time privileges
Why this is correct
Standing admin rights violate zero trust's assume-breach stance. Just-in-time privilege elevation grants access only when needed, then revokes it, shrinking the blast radius of compromised accounts. This directly satisfies the identity-centric requirement that entitlements are scoped and time-bound rather than permanent.
- ✓
Continuous verification of identity and device health
Why this is correct
Zero trust never grants implicit trust based on network location. Continuously re-evaluating user identity signals and device health posture on every access request satisfies the identity-centric constraint, so sessions are reauthorised rather than trusted once at login.
- ✓
Multi-factor authentication (MFA) for all users
Why this is correct
MFA enforces strong authentication for every user, removing reliance on single-factor credentials that attackers replay. Requiring a second factor satisfies the identity-centric principle that identity is the primary control plane, since access decisions hinge on verified identity rather than network perimeter.
- ✗
Single static firewall perimeter
Why it's wrong here
A single static firewall perimeter assumes everything inside is trusted, which zero trust rejects; identity-centric security evaluates each request against identity, device and context signals. Static perimeter defence would be correct for legacy castle-and-moat architectures, not for identity-centric zero trust.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.