Courseiva
Security Architecture →easyMultiple Choice

CAS-004 Security Architecture Practice Question

In a zero trust architecture, which concept ensures that an attacker who compromises one segment cannot move laterally to other segments?

⚠ Common exam trap

CAS-005 often tests the confusion between micro-segmentation (the lateral-movement prevention mechanism) and SDP or defense-in-depth (broader principles), so candidates pick the more familiar-sounding architectural term.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Micro-segmentation

Micro-segmentation divides a network into granular, isolated segments — often down to individual workloads or identities — and enforces policy between each segment so that compromise of one segment does not grant lateral movement to others. In zero trust, micro-segmentation is the enforcement mechanism that operationalizes 'never trust, always verify' at the network layer, typically using software-defined policies rather than physical firewalls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Software-defined perimeter

    Why it's wrong here

    A software-defined perimeter authenticates and brokers access to individual resources, but it does not itself enforce segmentation between compromised internal segments. It is tempting because SDP supports zero trust access, yet the concept that confines an attacker to one segment is microsegmentation, which applies policy between workloads.

  • ✗

    Defense-in-depth layering

    Why it's wrong here

    Layering controls of different types does not by itself stop east-west traversal; without segmentation between segments, a compromised host still reaches peers. Layering is tempting because it raises overall breach cost, and it would be correct where the requirement is resisting diverse attack classes rather than containing lateral movement.

  • ✗

    Identity-centric access

    Why it's wrong here

    Identity-centric access governs who may reach a resource per request, but it does not divide the network so that one compromised segment cannot reach another. It is tempting because zero trust centres on identity, and it would be correct where the requirement is continuous per-request authorisation rather than network containment.

  • ✓

    Micro-segmentation

    Why this is correct

    Micro-segmentation applies granular, workload-level security controls and policies between individual segments, so a compromised host cannot reach neighbouring workloads. This directly satisfies the zero trust requirement that no implicit trust exists between network segments, blocking lateral movement even after one segment falls.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.