
CompTIACloudNetX
Domain 2Objective 4
Zero Trust CNX-001 Practice Questions (Page 5)
Part of the Network security domain, which accounts for 28% of the CNX-001 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~18–31 in this domain), expect 3–5 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
8concepts
28%of the exam
Questions 21–25
- 21
A company's security team is evaluating a cloud access security broker (CASB) to gain visibility into shadow IT usage of unsanctioned cloud applications. They want to identify which applications are being used and by whom, without disrupting user productivity. Which CASB function is most relevant for this initial requirement?
Select an answer first - 22
What is the primary purpose of microsegmentation in a network?
Select an answer first - 23
What is a common deployment mode for a CASB?
Select an answer first - 24
A company is implementing ZTNA and wants to integrate it with its existing identity provider (IdP) and device management system. The goal is to enforce conditional access policies that consider user role, device compliance, and location. Which ZTNA feature is essential for this integration?
Select an answer first - 25
An organization is implementing zero trust network access (ZTNA) to replace its remote access VPN. The goal is to provide users with access only to the specific applications they are authorized to use, not the entire network. Which ZTNA deployment characteristic is essential to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CNX-001” is a trademark of its owner, used for identification only.