mediumMultiple ChoiceObjective-mapped
Zero-Trust Micro-Segmentation Essential Component: SDN with Distributed Firewalls
A company is implementing a zero-trust network architecture. Which of the following components is essential for enforcing micro-segmentation?
Quick Answer
The correct choice is software-defined networking (SDN) with distributed firewalls, as this combination is the essential component for enforcing zero-trust micro-segmentation. Micro-segmentation works by dividing the network into isolated, granular zones, each with its own security controls, and SDN enables dynamic, software-based policy enforcement at the hypervisor or virtual switch layer rather than relying on physical hardware. Distributed firewalls then apply these policies directly to each segment, ensuring that traffic is inspected and restricted regardless of network topology. On the CompTIA SecurityX CAS-004 exam, this question tests your understanding that zero-trust micro-segmentation is fundamentally a network control function, not an authentication or logging task—a common trap is confusing it with NAC or MFA. Remember the memory tip: SDN is the “brain” that defines the segments, and distributed firewalls are the “muscle” that enforces the rules within each zone.
⚠ Common exam trap
Watch out — candidates often confuse network access control (NAC) with micro-segmentation, but NAC controls access at the network edge (e.g., port-based authentication) rather than providing the workload-level, distributed traffic filtering that SDN with distributed firewalls enables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Software-defined networking (SDN) with distributed firewalls
Software-defined networking (SDN) with distributed firewalls is essential for enforcing micro-segmentation because it enables granular, policy-based traffic control at the virtual network layer, independent of physical topology. SDN centralizes policy management and pushes firewall rules to hypervisor-level or host-level enforcement points, allowing east-west traffic to be segmented between individual workloads or application tiers without relying on traditional perimeter firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security information and event management (SIEM) system
Why it's wrong here
SIEM provides monitoring and analysis, not enforcement of segmentation.
- ✓
Software-defined networking (SDN) with distributed firewalls
Why this is correct
SDN allows granular, policy-driven segmentation at the virtual network level.
- ✗
Multi-factor authentication (MFA)
Why it's wrong here
MFA strengthens identity verification but does not segment traffic.
- ✗
Network access control (NAC)
Why it's wrong here
NAC enforces authentication and posture compliance but does not create network segments.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CAS-005
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A financial services company is implementing a zero-trust architecture. The security architect needs to ensure that all network traffic between application tiers is inspected and logged regardless of source location. Which of the following should be implemented?
medium- ✓ A.Implement microsegmentation using a next-generation firewall
- B.Deploy a site-to-site VPN across all tiers
- C.Use a single, centralized firewall for all traffic
- D.Place all application servers in a DMZ
Why A: Microsegmentation using a next-generation firewall (NGFW) is the correct approach because it enforces granular, per-application-tier security policies that inspect and log all traffic regardless of source location. NGFWs provide deep packet inspection (DPI), application-level visibility, and logging capabilities, which are essential for zero-trust architecture where no implicit trust is granted to any network segment.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.