Courseiva
Security Architecture →easyMultiple Select

CAS-004 Security Architecture Practice Question

Which TWO of the following are key benefits of using a software-defined perimeter (SDP) in a zero trust architecture? (Select TWO.)

⚠ Common exam trap

The trap is selecting 'eliminates the need for encryption' or 'removes firewalls' because SDP sounds like a replacement for traditional perimeter security — in reality SDP depends on encryption and coexists with firewalls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reduces the attack surface by hiding network resources

Option A is correct because SDP uses a "black cloud" or dark network approach where resources are cloaked and do not respond to unauthenticated probes, so attackers cannot see or scan them, directly shrinking the attack surface. Option D is correct because SDP enforces access decisions based on verified user and device identity (often via mutual TLS, SAML, or OIDC with a controller and gateway), which is the core identity-centric principle of zero trust. Option B is wrong because patch management is a vulnerability/patch lifecycle function, not a benefit of SDP. Option C is wrong because SDP actually depends on strong encryption such as mTLS and IPsec/TLS tunnels rather than eliminating it. Option E is wrong because SDP complements rather than removes firewalls, and it typically adds controller/gateway components instead of simplifying the architecture by deleting firewalls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reduces the attack surface by hiding network resources

    Why this is correct

    SDP uses a deny-by-default model with single-packet authorisation, keeping resources invisible to unauthenticated users. Attackers cannot scan or target what they cannot see, so the exploitable attack surface shrinks — the specific benefit the zero trust scenario requires.

  • ✗

    Automates patch management

    Why it's wrong here

    SDP brokers identity-based, need-to-know connections; it does not distribute OS patches or manage endpoint software updates. Patch management belongs to configuration management tooling, and would be the right answer only if the question asked about vulnerability remediation rather than zero trust access control.

  • ✗

    Eliminates the need for encryption

    Why it's wrong here

    SDP depends on mutually authenticated, encrypted channels between initiators and acceptors, so encryption remains mandatory rather than eliminated. SDP's controller-mediated connections replace implicit network trust; removing encryption would be correct only if the question concerned a physically isolated, dedicated circuit.

  • ✓

    Provides identity-based access control

    Why this is correct

    SDP grants access based on verified user and device identity rather than network location, replacing perimeter trust with per-session authorisation. This satisfies zero trust's core requirement that every access request be authenticated and authorised before any connection to a protected resource is established.

  • ✗

    Simplifies network architecture by removing firewalls

    Why it's wrong here

    SDP augments perimeter controls with identity-based, software-defined segmentation; it does not remove firewalls or routing infrastructure. Firewall removal would be the right answer only for a flat, fully trusted internal network, which contradicts zero trust's assumption of no implicit trust.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.