Free CompTIA SecurityX / CASP+ CAS-005 Actual Exam Questions - Question 12 Discussion

Question No. 12
[Identity and Access Management (IAM)]
A cloud engineer needs to identify appropriate solutions to:
• Provide secure access to internal and external cloud resources.
• Eliminate split-tunnel traffic flows.
•Enable identity and access management capabilities.
Which of the following solutions arc the most appropriate? (Select two).
Select all that apply, then reveal solution.
US
NA
Noah A.
2026-02-17

C, F. SASE definitely tackles the split-tunnel issue by integrating secure networking and access in one framework. For identity and access management across different clouds and external resources, CASB makes sense since it provides visibility and control specifically over cloud apps and services, which fits better than Federation here. Federation mostly handles single sign-on but doesn’t cover cloud app security or traffic flow control like CASB does. So pairing CASB with SASE seems like a solid combo for the requirements.

0
NA
Noah A.
2026-02-14

I’m with F for sure, since SASE integrates networking and security to kill split-tunnel issues. Instead of Federation, I’d pick D (PAM) because managing privileged access is crucial for internal resources and helps tighten identity controls beyond just single sign-on. So F plus D feels like the right combo here.

0
LT
Luke T.
2026-01-27

I agree F is key to fix split-tunnel problems since SASE combines networking and security. For the IAM part, I’d pick A (Federation) because it lets users access both internal and external resources with one identity, which fits the secure access and management needs better than just CASB or PAM. So, F and A make the most sense here.

0
SI
Sohail I.
2026-01-15

C/F? Not sure if CASB covers everything here or just part.

0