easyMultiple Choice
CAS-004 Designing a new multi-tier web application Practice Question
A company is designing a new multi-tier web application. The security team recommends placing a web application firewall (WAF) in front of the web servers and a network firewall between the web and application tiers. Which security architecture principle does this represent?
⚠ Common exam trap
A common mix-up: candidates confuse 'defense in depth' with 'separation of duties' because both involve multiple layers, but separation of duties is about human roles and access control, not about stacking network security devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defense in depth
Defense in depth. This architecture implements multiple, overlapping layers of security controls: a WAF at the application layer (Layer 7) to inspect and filter HTTP/HTTPS traffic for web-specific attacks (e.g., SQL injection, XSS), and a network firewall between the web and application tiers to enforce stateful packet inspection and access control at Layers 3/4. This layered approach ensures that if one control fails or is bypassed, another control still provides protection, embodying the core principle of defense in depth.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Defense in depth
Why this is correct
Layering a WAF at the application edge and a network firewall between tiers applies multiple independent controls, so compromising one layer does not expose the next. This layered approach is the definition of defence in depth.
- ✗
Separation of duties
Why it's wrong here
Separation of duties splits a single sensitive task across different people to prevent fraud, such as requiring two approvers for payments. Here the controls are distinct filtering devices at different tiers, which is defence in depth; no single task is being divided between individuals.
- ✗
Least privilege
Why it's wrong here
Least privilege governs identity permissions and access rights, not the placement of filtering devices between network tiers. It is tempting because it is a foundational security principle, and it would be the correct answer if the question concerned scoping IAM roles or permissions rather than segmentation.
- ✗
Single point of failure
Why it's wrong here
Layering a WAF and an internal network firewall creates defence in depth, not a single point of failure; each control independently filters different traffic. The term describes an availability weakness where one component's loss halts the service, which is the opposite of what redundant, tiered filtering achieves here.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.