CS0-004 - Security Operations - Section 1.1

Explain concepts related to system and network architecture in security operations.

Explain how system and network architecture shapes what a security operations team can see and defend, including on-premises, cloud, hybrid, virtualisation, containerisation, serverless, and network design choices such as segmentation, zero trust and secure access. Recognise how logging, identity and asset management flow from these architecture decisions, and why an analyst's visibility depends on where sensors and log sources sit.

network segmentationzero trustcloud and hybrid architecturecontainerisation and virtualisationlogging and telemetry sources

Practice question for this objective

Free sampleSecurity Operationsmedium

A security analyst is documenting how the organisation's zero trust model treats network location. Which statement best captures the defining principle of zero trust as it applies to that documentation?

  • AEvery access request is authenticated and authorised on its own merits, regardless of whether it originates inside or outside the corporate network. Correct
  • BTraffic that has already crossed the perimeter firewall is treated as trusted so that internal east-west flows are not slowed by repeated checks.
  • CA hardened VPN concentrator is placed at the edge so remote users inherit the same trust level as staff sitting in the office.
  • DDevices enrolled in mobile device management are permanently trusted for the life of their certificate without further evaluation.
Zero trust removes implicit network-location trust and verifies every access request on identity, device and context. Zero trust assumes the network is already hostile, so trust is never granted by location; each request is verified continuously using identity, device posture and contextual signals before access is allowed.

Why A is correct: This is correct because zero trust removes implicit trust based on network position and evaluates identity, device posture and context per request.

Why B is wrong: This is tempting because it describes the traditional castle-and-moat model, but it is the exact assumption zero trust rejects; internal traffic is not implicitly trusted.

Why C is wrong: This is tempting because VPNs are common, yet granting broad inherited trust after a single tunnel login is the flat-trust model zero trust is designed to replace.

Why D is wrong: This is tempting because device enrolment matters, but permanent trust contradicts the continuous, per-request verification that zero trust requires.

See more CS0-004 practice questions, answers explained.

More in this domain

Back to all Security Operations objectives, or the CS0-004 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.