mediumMultiple Choice
Zero-Trust Micro-Segmentation Essential Component: SDN with Distributed Firewalls
A company is implementing a zero-trust network architecture. Which of the following components is essential for enforcing micro-segmentation?
Quick Answer
The correct choice is software-defined networking (SDN) with distributed firewalls, as this combination is the essential component for enforcing zero-trust micro-segmentation. Micro-segmentation works by dividing the network into isolated, granular zones, each with its own security controls, and SDN enables dynamic, software-based policy enforcement at the hypervisor or virtual switch layer rather than relying on physical hardware. Distributed firewalls then apply these policies directly to each segment, ensuring that traffic is inspected and restricted regardless of network topology. On the CompTIA SecurityX CAS-004 exam, this question tests your understanding that zero-trust micro-segmentation is fundamentally a network control function, not an authentication or logging task—a common trap is confusing it with NAC or MFA. Remember the memory tip: SDN is the “brain” that defines the segments, and distributed firewalls are the “muscle” that enforces the rules within each zone.
⚠ Common exam trap
Watch out — candidates often confuse network access control (NAC) with micro-segmentation, but NAC controls access at the network edge (e.g., port-based authentication) rather than providing the workload-level, distributed traffic filtering that SDN with distributed firewalls enables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Software-defined networking (SDN) with distributed firewalls
Software-defined networking (SDN) with distributed firewalls is essential for enforcing micro-segmentation because it enables granular, policy-based traffic control at the virtual network layer, independent of physical topology. SDN centralizes policy management and pushes firewall rules to hypervisor-level or host-level enforcement points, allowing east-west traffic to be segmented between individual workloads or application tiers without relying on traditional perimeter firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security information and event management (SIEM) system
Why it's wrong here
SIEM aggregates and correlates log data for detection and response; it does not enforce traffic policy between workloads. It would be correct for centralised monitoring and alerting, not for placing policy enforcement points between individual segments.
- ✓
Software-defined networking (SDN) with distributed firewalls
Why this is correct
SDN centralises control-plane policy while distributed firewalls enforce it at each workload's vNIC, delivering the east-west isolation micro-segmentation demands. This satisfies zero trust's requirement to verify every flow between segments rather than trusting perimeter placement.
- ✗
Multi-factor authentication (MFA)
Why it's wrong here
MFA verifies user identity at authentication, but micro-segmentation enforces east-west traffic control between workloads via policy at the network layer, which MFA cannot inspect or block. It is tempting because MFA is a core zero-trust identity control, and it would be correct when the requirement is strengthening user login assurance rather than workload isolation.
- ✗
Network access control (NAC)
Why it's wrong here
NAC governs device admission to the network at connect time, typically at the edge or switch port, not ongoing east-west flows between workloads. It would be correct for compliance-based onboarding of endpoints, not for micro-segmentation enforcement.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CAS-005
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A financial services company is implementing a zero-trust architecture. The security architect needs to ensure that all network traffic between application tiers is inspected and logged regardless of source location. Which of the following should be implemented?
medium- ✓ A.Implement microsegmentation using a next-generation firewall
- B.Deploy a site-to-site VPN across all tiers
- C.Use a single, centralized firewall for all traffic
- D.Place all application servers in a DMZ
Why A: Microsegmentation using a next-generation firewall (NGFW) is the correct approach because it enforces granular, per-application-tier security policies that inspect and log all traffic regardless of source location. NGFWs provide deep packet inspection (DPI), application-level visibility, and logging capabilities, which are essential for zero-trust architecture where no implicit trust is granted to any network segment.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.