hardMultiple SelectObjective-mapped
Zero Trust Architecture — Micro-Segmentation, Least Privilege, Continuous Monitoring
A company is implementing a zero-trust network architecture. Which THREE of the following are critical components of this approach?
Quick Answer
The answer is micro-segmentation of network resources, continuous authentication, and least privilege. These three components are critical because zero trust architecture components enforce the principle that no entity—inside or outside the network—is inherently trusted; micro-segmentation divides the network into isolated zones to contain lateral movement, continuous authentication verifies identity and device health at every access request, and least privilege restricts permissions to only what is necessary for a task. On the CompTIA SecurityX CAS-004 exam, this question tests your ability to distinguish core zero-trust mechanisms from supporting technologies like VPNs or firewalls, which are often used as distractors. A common trap is assuming that a single strong perimeter defense, such as a next-gen firewall, satisfies zero trust—but the exam emphasizes that trust must be continuously verified, not assumed based on location. Remember the mnemonic “MCL” for Micro-segmentation, Continuous authentication, and Least privilege to recall the triad that eliminates implicit trust.
⚠ Common exam trap
It's easy for candidates to confuse VPNs with secure remote access in zero-trust, but ZTA replaces VPNs with identity-aware proxies (e.g., Zscaler, Cloudflare Access) that enforce per-session authentication and least privilege, not persistent tunnels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Default-deny access policies (least privilege)
Zero-trust architecture (ZTA) explicitly mandates default-deny access policies based on least privilege. This means no user or device is trusted by default, regardless of network location; access is granted only after verifying identity, device health, and context, and is limited to the minimum necessary resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPN for all remote access
Why it's wrong here
VPNs provide network-level trust, which contradicts zero-trust; instead, application-level access is preferred.
- ✓
Default-deny access policies (least privilege)
Why this is correct
Users and devices are given only the access necessary.
- ✓
Continuous monitoring and authentication
Why this is correct
All access requests are verified regardless of location.
- ✓
Micro-segmentation of network resources
Why this is correct
Isolates resources to limit lateral movement.
- ✗
A single perimeter firewall
Why it's wrong here
Zero-trust eliminates the concept of a trusted internal network; a single perimeter firewall is insufficient.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CAS-005
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is migrating to a zero trust architecture. Which of the following is a key principle of zero trust?
hard- A.Allow all traffic within the corporate network
- ✓ B.Assume breach and verify every request
- C.Trust devices based on their IP address
- D.Trust but verify for all internal traffic
Why B: Zero trust architecture is built on the principle of 'never trust, always verify,' which explicitly requires that every access request—regardless of origin—be authenticated, authorized, and continuously validated. Option B ('Assume breach and verify every request') captures this core tenet, as it mandates that no implicit trust is granted based on network location or device status, and every request must be treated as potentially malicious until proven otherwise.
Variation 2. Which THREE of the following are key components of a zero-trust security architecture? (Select THREE).
hard- A.VPN concentrator
- ✓ B.Micro-segmentation
- C.Implicit trust for internal network traffic
- ✓ D.Least privilege access control
- ✓ E.Continuous monitoring of user and device behavior
Why B: Micro-segmentation is a core component of zero-trust architecture because it divides the network into isolated zones, each requiring separate authentication and authorization for any cross-zone traffic. This enforces the 'never trust, always verify' principle by preventing lateral movement even if an attacker compromises a single segment, unlike traditional flat networks where internal traffic is implicitly trusted.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.