easyMultiple ChoiceObjective-mapped
CAS-004 Practice Question: Wants to implement a zero-trust architecture for…
An organization wants to implement a zero-trust architecture for remote access. Which of the following is the MOST important component?
⚠ Common exam trap
The trap here is that candidates often mistake a VPN concentrator as the core of zero-trust remote access because it provides encryption and authentication, but zero-trust requires micro-segmentation to enforce least-privilege access and prevent lateral movement, which a traditional VPN alone cannot achieve.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Micro-segmentation
Micro-segmentation is the most important component for zero-trust remote access because it enforces granular, identity-based access controls that limit lateral movement within the network. Unlike perimeter-based models, zero-trust assumes no implicit trust, and micro-segmentation ensures that even after authentication, each remote session is isolated to only the specific resources required, reducing the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RAID 5
Why it's wrong here
RAID 5 provides disk fault tolerance, not network security.
- ✗
Syslog server
Why it's wrong here
Syslog is for centralized logging, not a zero-trust control.
- ✗
VPN concentrator
Why it's wrong here
VPN concentrators are a perimeter technology, not aligned with zero-trust principles.
- ✓
Micro-segmentation
Why this is correct
Micro-segmentation enforces granular access controls and limits lateral movement, a core zero-trust concept.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.