Courseiva
easyMultiple Choice

CAS-004 Designing a new multi-tier web application Practice Question

A company is designing a new multi-tier web application. The security team recommends placing a web application firewall (WAF) in front of the web servers and a network firewall between the web and application tiers. Which security architecture principle does this represent?

⚠ Common exam trap

A common mix-up: candidates confuse 'defense in depth' with 'separation of duties' because both involve multiple layers, but separation of duties is about human roles and access control, not about stacking network security devices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defense in depth

Defense in depth. This architecture implements multiple, overlapping layers of security controls: a WAF at the application layer (Layer 7) to inspect and filter HTTP/HTTPS traffic for web-specific attacks (e.g., SQL injection, XSS), and a network firewall between the web and application tiers to enforce stateful packet inspection and access control at Layers 3/4. This layered approach ensures that if one control fails or is bypassed, another control still provides protection, embodying the core principle of defense in depth.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Defense in depth

    Why this is correct

    Layering a WAF at the application edge and a network firewall between tiers applies multiple independent controls, so compromising one layer does not expose the next. This layered approach is the definition of defence in depth.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties splits a single sensitive task across different people to prevent fraud, such as requiring two approvers for payments. Here the controls are distinct filtering devices at different tiers, which is defence in depth; no single task is being divided between individuals.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege governs identity permissions and access rights, not the placement of filtering devices between network tiers. It is tempting because it is a foundational security principle, and it would be the correct answer if the question concerned scoping IAM roles or permissions rather than segmentation.

  • ✗

    Single point of failure

    Why it's wrong here

    Layering a WAF and an internal network firewall creates defence in depth, not a single point of failure; each control independently filters different traffic. The term describes an availability weakness where one component's loss halts the service, which is the opposite of what redundant, tiered filtering achieves here.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.