easyMultiple Choice
CAS-004 Practice Question: Wants to implement a zero-trust architecture for…
An organization wants to implement a zero-trust architecture for remote access. Which of the following is the MOST important component?
⚠ Common exam trap
The trap here is that candidates often mistake a VPN concentrator as the core of zero-trust remote access because it provides encryption and authentication, but zero-trust requires micro-segmentation to enforce least-privilege access and prevent lateral movement, which a traditional VPN alone cannot achieve.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Micro-segmentation
Micro-segmentation is the most important component for zero-trust remote access because it enforces granular, identity-based access controls that limit lateral movement within the network. Unlike perimeter-based models, zero-trust assumes no implicit trust, and micro-segmentation ensures that even after authentication, each remote session is isolated to only the specific resources required, reducing the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RAID 5
Why it's wrong here
RAID 5 provides disk-level redundancy against hardware failure; it has no role in authenticating users, devices or sessions, so it cannot enforce zero-trust access decisions. It tempts because resilience and availability matter in security architectures, and RAID 5 is the right answer when the requirement is fault tolerance.
- ✗
Syslog server
Why it's wrong here
A Syslog server centralises log collection for auditing and correlation; it records events but enforces no authentication or authorisation, so it cannot gate access. It tempts because visibility underpins zero-trust monitoring, and it would be correct when the requirement is centralised event logging.
- ✗
VPN concentrator
Why it's wrong here
A VPN concentrator terminates encrypted tunnels and extends network access to authenticated users, which contradicts zero trust's per-request verification and least-privilege model. It tempts because it is the traditional remote-access solution, and it would be correct when the requirement is encrypted connectivity rather than continuous verification.
- ✓
Micro-segmentation
Why this is correct
Micro-segmentation enforces zero trust by dividing the network into isolated zones with granular, workload-level policies, so lateral movement after compromise is contained. For remote access, it satisfies the requirement that no user or device is implicitly trusted once inside the perimeter.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.