mediumMultiple Choice
200-201 Practice Question: Deploying a new web application and wants to…
A company is deploying a new web application and wants to ensure it is secure against common web attacks. Which of the following is the most effective approach to validate the security of the application before going live?
⚠ Common exam trap
Cisco often tests the distinction between validation (penetration test) and mitigation (WAF), trapping candidates who think a WAF or vulnerability scanner alone can fully validate application security before deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a penetration test by an external firm
A penetration test by an external firm is the most effective approach because it simulates a real-world attack, combining automated tools and manual exploitation techniques to identify vulnerabilities that automated scanners or static analysis might miss. Unlike a vulnerability scanner, a penetration test actively attempts to bypass security controls, test business logic flaws, and chain multiple low-risk issues into a critical exploit, providing a holistic validation of the application's security posture before going live.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a penetration test by an external firm
Why this is correct
An external penetration test simulates real attacker techniques against the deployed application, uncovering exploitable flaws such as injection or broken authentication that automated scanning may miss. It provides independent validation of security posture before go-live.
- ✗
Run a vulnerability scanner against the application
Why it's wrong here
A vulnerability scanner detects known signatures and missing patches on hosts and services, but it does not crawl and attack application logic such as injection, broken access control or session handling. It suits infrastructure and patch assessment. Validating a web application against common web attacks requires dynamic application security testing.
- ✗
Implement a web application firewall (WAF)
Why it's wrong here
A WAF filters live HTTP traffic at runtime; it cannot discover flaws in the application's own code before deployment. It is tempting because WAFs genuinely mitigate injection and cross-site scripting in production, but validating pre-launch security requires static and dynamic code testing, such as SAST or DAST scanning.
- ✗
Perform a code review with static analysis tools
Why it's wrong here
Static analysis inspects source code for insecure patterns but cannot exercise the running application, so injection, authentication and session flaws depending on runtime configuration and data flow stay hidden. It suits early development checks. Validating exploitable web attacks before go-live requires dynamic testing against the deployed application.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.