PSE-SASE · Question #5
What is a benefit of a cloud-based secure access service edge (SASE) infrastructure over a Zero Trust Network Access (ZTNA) product based on a software-defined perimeter (SDP) model?
The correct answer is A. Users, devices, and apps are identified no matter where they connect from. SASE's defining advantage is its cloud-native architecture, which enforces identity-aware access for users, devices, and applications regardless of their physical location - because the policy engine lives in the cloud, not tied to a perimeter. ZTNA/SDP solutions also use…
Question
What is a benefit of a cloud-based secure access service edge (SASE) infrastructure over a Zero Trust Network Access (ZTNA) product based on a software-defined perimeter (SDP) model?
Options
- AUsers, devices, and apps are identified no matter where they connect from.
- BConnection to physical SD-WAN hubs in ther locations provides increased interconnectivity
- CComplexity of connecting to a gateway is increased, providing additional protection.
- DVirtual private network (VPN) services are used for remote access to the internal data center, but
How the community answered
(37 responses)- A84% (31)
- B8% (3)
- C5% (2)
- D3% (1)
Explanation
SASE's defining advantage is its cloud-native architecture, which enforces identity-aware access for users, devices, and applications regardless of their physical location - because the policy engine lives in the cloud, not tied to a perimeter. ZTNA/SDP solutions also use identity verification, but they tend to be narrower in scope (focused on specific app access) and may still rely on on-premises components, whereas SASE natively extends consistent policy enforcement across web, cloud, and private-app traffic from any location.
Why the distractors are wrong:
- B is wrong because SASE is explicitly cloud-based and moves away from physical SD-WAN hubs - physical hubs belong to legacy WAN architectures.
- C is wrong because increased complexity is never a security benefit; SASE actually reduces connection complexity by consolidating security functions in the cloud.
- D is wrong because SASE is specifically designed to replace VPN-based remote access, not continue using it.
Memory tip: Think of SASE as "security that travels with the user" - since it lives in the cloud, it follows any user, device, or app anywhere. The keyword in the question is "cloud-based": that's what enables the universal identity enforcement in option A that a more localized SDP/ZTNA product can't match at the same scale.
Topics
Community Discussion
No community discussion yet for this question.