Courseiva
mediumMultiple Choice

200-201 Practice Question: Deploying a new web application and wants to…

A company is deploying a new web application and wants to ensure it is secure against common web attacks. Which of the following is the most effective approach to validate the security of the application before going live?

⚠ Common exam trap

Cisco often tests the distinction between validation (penetration test) and mitigation (WAF), trapping candidates who think a WAF or vulnerability scanner alone can fully validate application security before deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a penetration test by an external firm

A penetration test by an external firm is the most effective approach because it simulates a real-world attack, combining automated tools and manual exploitation techniques to identify vulnerabilities that automated scanners or static analysis might miss. Unlike a vulnerability scanner, a penetration test actively attempts to bypass security controls, test business logic flaws, and chain multiple low-risk issues into a critical exploit, providing a holistic validation of the application's security posture before going live.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conduct a penetration test by an external firm

    Why this is correct

    An external penetration test simulates real attacker techniques against the deployed application, uncovering exploitable flaws such as injection or broken authentication that automated scanning may miss. It provides independent validation of security posture before go-live.

  • ✗

    Run a vulnerability scanner against the application

    Why it's wrong here

    A vulnerability scanner detects known signatures and missing patches on hosts and services, but it does not crawl and attack application logic such as injection, broken access control or session handling. It suits infrastructure and patch assessment. Validating a web application against common web attacks requires dynamic application security testing.

  • ✗

    Implement a web application firewall (WAF)

    Why it's wrong here

    A WAF filters live HTTP traffic at runtime; it cannot discover flaws in the application's own code before deployment. It is tempting because WAFs genuinely mitigate injection and cross-site scripting in production, but validating pre-launch security requires static and dynamic code testing, such as SAST or DAST scanning.

  • ✗

    Perform a code review with static analysis tools

    Why it's wrong here

    Static analysis inspects source code for insecure patterns but cannot exercise the running application, so injection, authentication and session flaws depending on runtime configuration and data flow stay hidden. It suits early development checks. Validating exploitable web attacks before go-live requires dynamic testing against the deployed application.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.