CAS-004 Security Architecture Practice Question
In a zero trust architecture, which concept ensures that an attacker who compromises one segment cannot move laterally to other segments?
⚠ Common exam trap
CAS-005 often tests the confusion between micro-segmentation (the lateral-movement prevention mechanism) and SDP or defense-in-depth (broader principles), so candidates pick the more familiar-sounding architectural term.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Micro-segmentation
Micro-segmentation divides a network into granular, isolated segments — often down to individual workloads or identities — and enforces policy between each segment so that compromise of one segment does not grant lateral movement to others. In zero trust, micro-segmentation is the enforcement mechanism that operationalizes 'never trust, always verify' at the network layer, typically using software-defined policies rather than physical firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Software-defined perimeter
Why it's wrong here
A software-defined perimeter authenticates and brokers access to individual resources, but it does not itself enforce segmentation between compromised internal segments. It is tempting because SDP supports zero trust access, yet the concept that confines an attacker to one segment is microsegmentation, which applies policy between workloads.
- ✗
Defense-in-depth layering
Why it's wrong here
Layering controls of different types does not by itself stop east-west traversal; without segmentation between segments, a compromised host still reaches peers. Layering is tempting because it raises overall breach cost, and it would be correct where the requirement is resisting diverse attack classes rather than containing lateral movement.
- ✗
Identity-centric access
Why it's wrong here
Identity-centric access governs who may reach a resource per request, but it does not divide the network so that one compromised segment cannot reach another. It is tempting because zero trust centres on identity, and it would be correct where the requirement is continuous per-request authorisation rather than network containment.
- ✓
Micro-segmentation
Why this is correct
Micro-segmentation applies granular, workload-level security controls and policies between individual segments, so a compromised host cannot reach neighbouring workloads. This directly satisfies the zero trust requirement that no implicit trust exists between network segments, blocking lateral movement even after one segment falls.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.