CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is designing a system for a highly distributed global manufacturing company that uses numerous IoT devices, operational technology (OT) systems, and cloud-based applications. The challenge is to establish a consistent security policy and enforce it across all these diverse endpoints, regardless of their location or underlying technology, without relying on traditional network perimeters. Which architectural paradigm is best suited to address this challenge?

  1. AZero Trust Architecture (ZTA)
  2. BCloud Access Security Broker (CASB)
  3. CPerimeter-based Security
  4. DDemilitarized Zone (DMZ)
Show answer & explanation

Correct answer: A. Zero Trust Architecture (ZTA)

Zero Trust Architecture (ZTA) is fundamentally designed for environments where traditional network perimeters are insufficient due to distributed assets (IoT, OT, cloud). It enforces a 'never trust, always verify' principle, meaning every access request from any endpoint to any resource is continuously authenticated, authorized, and validated based on granular policies, regardless of its location. This directly addresses the challenge of consistent security across diverse, borderless environments.

Why the other options are wrong

  • B. A CASB focuses on enforcing security policies for cloud application usage and data, but it does not encompass the broad scope of securing IoT devices, OT systems, and internal applications in a unified, perimeter-less model like ZTA.
  • C. Perimeter-based Security relies on a defined network boundary, which is ineffective for highly distributed IoT, OT, and cloud environments that lack a single, clear perimeter.
  • D. A DMZ is a network segment used to expose public-facing services while isolating internal networks; it does not provide a comprehensive security model for distributed, diverse endpoints.

Zero Trust Architecture (ZTA)

A security model based on the principle of 'never trust, always verify,' where every user, device, and application attempting to access resources must be authenticated and authorized, regardless of whether it is inside or outside the traditional network perimeter.

  • Eliminates implicit trust and assumes breach.
  • Enforces granular access control based on context (user, device, location, data sensitivity).
  • Ideal for securing hybrid, multi-cloud, and highly distributed environments.

Memory trick: Architectural paradigms are like blueprints for building security, from old 'castles' to new 'transparent houses'.

More Security Architecture questions