SY0-701 Security Architecture Practice Question
A security architect is evaluating a zero trust architecture (ZTA) for a remote workforce. Which three of the following components are essential to the implementation? (Choose three.)
⚠ Common exam trap
The SY0-701 exam often tests the misconception that a VPN is a core component of zero trust, but ZTA actually replaces VPNs with more granular, identity-based access controls that do not assume network-level trust.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A policy engine that continuously evaluates trust based on user identity, device health, and context.
A policy engine is essential in zero trust architecture (ZTA) because it continuously evaluates trust based on user identity, device health, and context, dynamically granting or denying access. Microsegmentation is critical as it enforces granular access controls between workloads, preventing lateral movement even after an initial breach. Encrypting all traffic, including east-west communications, ensures data confidentiality and integrity across the network, aligning with the ZTA principle of never trusting and always verifying.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A policy engine that continuously evaluates trust based on user identity, device health, and context.
Why this is correct
The policy engine is the decision point that grants or denies each request by continuously evaluating identity, device health and contextual signals, rather than trusting once at the perimeter. This satisfies zero trust's core requirement of dynamic, per-session authorisation for remote users.
- ✗
A single, static firewall rule that allows all traffic from the corporate VPN IP range.
Why it's wrong here
A static rule permitting the whole VPN range grants network-level access without per-session identity or device evaluation, contradicting zero trust's verify-each-request principle. It is tempting because VPN-range allowlisting is common perimeter hardening, but ZTA requires dynamic, identity-based policy decisions rather than fixed IP trust.
- ✓
Microsegmentation to limit lateral movement even after initial access is granted.
Why this is correct
Microsegmentation enforces granular, per-workload access controls so that once an attacker gains a foothold, they cannot move laterally to other resources. This directly satisfies the zero trust requirement of assuming breach and containing blast radius for the remote workforce.
- ✗
A mandatory VPN for all remote users before accessing any resource.
Why it's wrong here
A mandatory VPN grants broad network access once connected, rather than evaluating each resource request against identity, device posture and context. Zero trust uses per-application access, not tunnel-based trust. It is tempting because VPNs are the traditional remote-access control, but they establish the implicit network trust ZTA removes.
- ✓
Encryption of all traffic, including internal east-west communications.
Why this is correct
Encrypting all traffic, including east-west flows between internal workloads, removes implicit trust in the internal network and protects data in transit even if a segment is compromised. This satisfies the zero trust requirement that no communication path be treated as inherently trusted.
- ✗
Implicit trust for all devices that are connected to the internal network.
Why it's wrong here
Zero trust removes implicit trust entirely; every request must be authenticated and authorised regardless of network location. Treating internal-network devices as trusted recreates the perimeter model ZTA exists to eliminate. It is tempting because legacy designs granted broad internal access, but that approach is precisely what a remote-workforce ZTA replaces.
Go deeper
Related to this question
Learn chapter
Third-Party Risk in Architecture
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.