Courseiva
Security Architecture →mediumMultiple Select

SY0-701 Security Architecture Practice Question

A security architect is evaluating a zero trust architecture (ZTA) for a remote workforce. Which three of the following components are essential to the implementation? (Choose three.)

⚠ Common exam trap

The SY0-701 exam often tests the misconception that a VPN is a core component of zero trust, but ZTA actually replaces VPNs with more granular, identity-based access controls that do not assume network-level trust.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A policy engine that continuously evaluates trust based on user identity, device health, and context.

A policy engine is essential in zero trust architecture (ZTA) because it continuously evaluates trust based on user identity, device health, and context, dynamically granting or denying access. Microsegmentation is critical as it enforces granular access controls between workloads, preventing lateral movement even after an initial breach. Encrypting all traffic, including east-west communications, ensures data confidentiality and integrity across the network, aligning with the ZTA principle of never trusting and always verifying.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A policy engine that continuously evaluates trust based on user identity, device health, and context.

    Why this is correct

    The policy engine is the decision point that grants or denies each request by continuously evaluating identity, device health and contextual signals, rather than trusting once at the perimeter. This satisfies zero trust's core requirement of dynamic, per-session authorisation for remote users.

  • ✗

    A single, static firewall rule that allows all traffic from the corporate VPN IP range.

    Why it's wrong here

    A static rule permitting the whole VPN range grants network-level access without per-session identity or device evaluation, contradicting zero trust's verify-each-request principle. It is tempting because VPN-range allowlisting is common perimeter hardening, but ZTA requires dynamic, identity-based policy decisions rather than fixed IP trust.

  • ✓

    Microsegmentation to limit lateral movement even after initial access is granted.

    Why this is correct

    Microsegmentation enforces granular, per-workload access controls so that once an attacker gains a foothold, they cannot move laterally to other resources. This directly satisfies the zero trust requirement of assuming breach and containing blast radius for the remote workforce.

  • ✗

    A mandatory VPN for all remote users before accessing any resource.

    Why it's wrong here

    A mandatory VPN grants broad network access once connected, rather than evaluating each resource request against identity, device posture and context. Zero trust uses per-application access, not tunnel-based trust. It is tempting because VPNs are the traditional remote-access control, but they establish the implicit network trust ZTA removes.

  • ✓

    Encryption of all traffic, including internal east-west communications.

    Why this is correct

    Encrypting all traffic, including east-west flows between internal workloads, removes implicit trust in the internal network and protects data in transit even if a segment is compromised. This satisfies the zero trust requirement that no communication path be treated as inherently trusted.

  • ✗

    Implicit trust for all devices that are connected to the internal network.

    Why it's wrong here

    Zero trust removes implicit trust entirely; every request must be authenticated and authorised regardless of network location. Treating internal-network devices as trusted recreates the perimeter model ZTA exists to eliminate. It is tempting because legacy designs granted broad internal access, but that approach is precisely what a remote-workforce ZTA replaces.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.