Courseiva
Network Security Controls Protocols And DeviceshardMultiple ChoiceObjective-mapped

CND Practice Question: Network Security Controls Protocols And Devices

A security architect is designing a Zero Trust Network Access (ZTNA) solution to replace a legacy remote access VPN. Unlike traditional VPNs that grant network-level access upon initial authentication, how does a true service-initiated ZTNA architecture handle application access for a remote user?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It authenticates the user, verifies device posture, and brokers a secure, single-application connection without exposing the network layer.

Service-initiated ZTNA hides application infrastructure from discovery (dark cloud/dark app), requiring the user to authenticate and pass posture checks before a secure proxy broker establishes a direct, encrypted connection to the specific application, never granting broad network access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • It extends the corporate VLAN directly to the user's laptop via an encrypted tunnel.

    Why it's wrong here

    Extending VLANs is a legacy VPN behavior that violates Zero Trust micro-segmentation principles.

  • It authenticates the user, verifies device posture, and brokers a secure, single-application connection without exposing the network layer.

    Why this is correct

    ZTNA provides identity- and context-aware, least-privilege access to individual applications rather than granting network-layer connectivity.

  • It relies on static firewall access control lists pre-configured with the user's home IP address.

    Why it's wrong here

    Home IP addresses are dynamic, and static ACLs do not provide dynamic identity-based Zero Trust enforcement.

  • It assigns a private IP address from a DHCP pool managed by the internal core router.

    Why it's wrong here

    Assigning a private subnet IP address grants broad network-layer access, which contradicts Zero Trust architecture.

About these practice questions

One of 323 original CND practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.