Courseiva
hardMultiple Choice

CAS-004 Practice Question: Wants to implement a zero-trust architecture for…

An organization wants to implement a zero-trust architecture for remote access. Which component is most critical for enforcing least-privilege access to internal applications?

⚠ Common exam trap

It's easy for candidates to confuse network-centric security controls (VPN, NGFW) with identity-centric zero-trust enforcement, leading candidates to pick a traditional perimeter device instead of the SDP that embodies zero-trust least-privilege access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Software-defined perimeter (SDP)

A Software-Defined Perimeter (SDP) is the most critical component for enforcing least-privilege access in a zero-trust architecture because it implements a 'need-to-know' model where resources are hidden (black cloud) until the user and device are authenticated and authorized. SDP uses a controller to broker connections, dynamically creating single-packet authorization (SPA) and mutual TLS tunnels, ensuring that only authorized users can even see the internal applications. This directly supports zero-trust principles of never trust, always verify, and least-privilege access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Virtual private network (VPN) concentrator

    Why it's wrong here

    A VPN concentrator grants broad network-level access once the tunnel is established, so it cannot enforce per-application least privilege. It is tempting because VPNs secure remote connectivity, but zero-trust requires identity-aware, per-request authorisation of each application, which a concentrator does not perform.

  • ✓

    Software-defined perimeter (SDP)

    Why this is correct

    A software-defined perimeter hides internal applications behind an identity-based, need-to-know broker, granting per-session access only after device and user verification. This directly enforces least-privilege access to internal apps, unlike network-centric controls that expose services broadly.

  • ✗

    Next-generation firewall (NGFW)

    Why it's wrong here

    An NGFW filters traffic by IP, port and protocol at the network perimeter; it cannot evaluate user identity or application-level entitlement per request, so least privilege is not enforced. It is tempting because NGFWs inspect and segment traffic, but zero-trust decisions require identity-based policy enforcement rather than network filtering.

  • ✗

    Intrusion detection system (IDS)

    Why it's wrong here

    An IDS passively detects and alerts on suspicious traffic; it neither authenticates users nor authorises access, so it cannot enforce least privilege. It is tempting because IDS supports zero-trust monitoring and visibility, but enforcement requires an identity-aware policy decision point evaluating each request, not detection alone.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.