Courseiva
mediumMultiple Choice

CAS-004 Practice Question: A company deploys a web application behind a WAF

A company deploys a web application behind a WAF. The security team discovers that the WAF allows traffic from a known malicious IP. After investigating, they find the WAF is configured to allow all traffic from a specific country for business reasons. Which of the following is the BEST course of action?

⚠ Common exam trap

The trap here is the instinct to 'remove the risky rule' or 'add another device,' when the exam expects the least-disruptive, most precise fix — a specific deny exception that preserves the business-justified allow rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a specific deny rule for the malicious IP within the country allow rule, using an exception list.

The country-based allow rule exists for legitimate business reasons, so removing it outright would break required traffic. The correct approach is to preserve the business-justified allow rule while layering a more specific deny exception for the known malicious IP, since WAF rule precedence evaluates more specific rules before broader ones. This achieves both security and business continuity without disrupting legitimate users from that country.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy an additional IPS device to block the IP.

    Why it's wrong here

    An extra IPS device does not remove the country-wide WAF allow rule that permits the malicious IP, so the traffic still passes. Layered blocking is tempting because defence in depth is valid, and would be correct if the WAF rule were already narrowed and residual risk needed covering.

  • ✗

    Remove the country-based allow rule immediately.

    Why it's wrong here

    Removing the country allow rule outright also drops legitimate business traffic, so the malicious IP stays blocked only by coincidence. Geo-blocking rules exist to restrict traffic by region; the correct fix is a higher-priority deny for that specific IP, preserving the country allowance.

  • ✓

    Add a specific deny rule for the malicious IP within the country allow rule, using an exception list.

    Why this is correct

    A deny rule for the malicious IP placed above or within the country allow rule creates an exception, so legitimate country traffic still passes while that address is blocked. This satisfies the business constraint of retaining the country allow list without permitting a known threat.

  • ✗

    Change the WAF from detection mode to blocking mode.

    Why it's wrong here

    Switching to blocking mode does not help because the country allow rule is an explicit exception that still permits the malicious IP through. Blocking mode is tempting since it stops attacks generally, and would be correct if the WAF were merely logging rather than enforcing.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.