CAS-004 Security Architecture Practice Question
Which TWO of the following are key benefits of using a software-defined perimeter (SDP) in a zero trust architecture? (Select TWO.)
⚠ Common exam trap
The trap is selecting 'eliminates the need for encryption' or 'removes firewalls' because SDP sounds like a replacement for traditional perimeter security — in reality SDP depends on encryption and coexists with firewalls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduces the attack surface by hiding network resources
Option A is correct because SDP uses a "black cloud" or dark network approach where resources are cloaked and do not respond to unauthenticated probes, so attackers cannot see or scan them, directly shrinking the attack surface. Option D is correct because SDP enforces access decisions based on verified user and device identity (often via mutual TLS, SAML, or OIDC with a controller and gateway), which is the core identity-centric principle of zero trust. Option B is wrong because patch management is a vulnerability/patch lifecycle function, not a benefit of SDP. Option C is wrong because SDP actually depends on strong encryption such as mTLS and IPsec/TLS tunnels rather than eliminating it. Option E is wrong because SDP complements rather than removes firewalls, and it typically adds controller/gateway components instead of simplifying the architecture by deleting firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reduces the attack surface by hiding network resources
Why this is correct
SDP uses a deny-by-default model with single-packet authorisation, keeping resources invisible to unauthenticated users. Attackers cannot scan or target what they cannot see, so the exploitable attack surface shrinks — the specific benefit the zero trust scenario requires.
- ✗
Automates patch management
Why it's wrong here
SDP brokers identity-based, need-to-know connections; it does not distribute OS patches or manage endpoint software updates. Patch management belongs to configuration management tooling, and would be the right answer only if the question asked about vulnerability remediation rather than zero trust access control.
- ✗
Eliminates the need for encryption
Why it's wrong here
SDP depends on mutually authenticated, encrypted channels between initiators and acceptors, so encryption remains mandatory rather than eliminated. SDP's controller-mediated connections replace implicit network trust; removing encryption would be correct only if the question concerned a physically isolated, dedicated circuit.
- ✓
Provides identity-based access control
Why this is correct
SDP grants access based on verified user and device identity rather than network location, replacing perimeter trust with per-session authorisation. This satisfies zero trust's core requirement that every access request be authenticated and authorised before any connection to a protected resource is established.
- ✗
Simplifies network architecture by removing firewalls
Why it's wrong here
SDP augments perimeter controls with identity-based, software-defined segmentation; it does not remove firewalls or routing infrastructure. Firewall removal would be the right answer only for a flat, fully trusted internal network, which contradicts zero trust's assumption of no implicit trust.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.