hardMultiple Choice
CAS-004 Practice Question: Wants to implement a zero-trust architecture for…
An organization wants to implement a zero-trust architecture for remote access. Which component is most critical for enforcing least-privilege access to internal applications?
⚠ Common exam trap
It's easy for candidates to confuse network-centric security controls (VPN, NGFW) with identity-centric zero-trust enforcement, leading candidates to pick a traditional perimeter device instead of the SDP that embodies zero-trust least-privilege access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Software-defined perimeter (SDP)
A Software-Defined Perimeter (SDP) is the most critical component for enforcing least-privilege access in a zero-trust architecture because it implements a 'need-to-know' model where resources are hidden (black cloud) until the user and device are authenticated and authorized. SDP uses a controller to broker connections, dynamically creating single-packet authorization (SPA) and mutual TLS tunnels, ensuring that only authorized users can even see the internal applications. This directly supports zero-trust principles of never trust, always verify, and least-privilege access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Virtual private network (VPN) concentrator
Why it's wrong here
A VPN concentrator grants broad network-level access once the tunnel is established, so it cannot enforce per-application least privilege. It is tempting because VPNs secure remote connectivity, but zero-trust requires identity-aware, per-request authorisation of each application, which a concentrator does not perform.
- ✓
Software-defined perimeter (SDP)
Why this is correct
A software-defined perimeter hides internal applications behind an identity-based, need-to-know broker, granting per-session access only after device and user verification. This directly enforces least-privilege access to internal apps, unlike network-centric controls that expose services broadly.
- ✗
Next-generation firewall (NGFW)
Why it's wrong here
An NGFW filters traffic by IP, port and protocol at the network perimeter; it cannot evaluate user identity or application-level entitlement per request, so least privilege is not enforced. It is tempting because NGFWs inspect and segment traffic, but zero-trust decisions require identity-based policy enforcement rather than network filtering.
- ✗
Intrusion detection system (IDS)
Why it's wrong here
An IDS passively detects and alerts on suspicious traffic; it neither authenticates users nor authorises access, so it cannot enforce least privilege. It is tempting because IDS supports zero-trust monitoring and visibility, but enforcement requires an identity-aware policy decision point evaluating each request, not detection alone.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.