Courseiva
Security Architecture →mediumMultiple Select

CAS-004 Security Architecture Practice Question

A company is implementing a defense-in-depth strategy for its web application. Which THREE security controls should be included in the architecture? (Choose three.)

⚠ Common exam trap

It's easy for candidates to confuse availability/identity controls (load balancer, SSO) with security controls — candidates pick them because they sound 'enterprise-grade' but they do not block or contain attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web application firewall (WAF)

A web application firewall (WAF) is correct because it inspects and filters HTTP/HTTPS traffic at Layer 7, blocking common attacks such as SQL injection and cross-site scripting before they reach the application, which is a core element of defense-in-depth for a web app. Runtime application self-protection (RASP) is correct because it instruments the application from within the runtime, detecting and blocking attacks like deserialization or injection in real time based on actual execution context, complementing perimeter controls. Network segmentation is correct because it limits lateral movement by isolating the web tier from databases and internal services using VLANs, subnets, or security groups, so a compromised web server cannot freely reach other assets. A load balancer with SSL termination is not a security control in this context; it primarily provides availability and offloads TLS processing, and while it may support TLS, it does not itself enforce application-layer threat protection. Single sign-on (SSO) is an authentication convenience and access-management mechanism, not a defense-in-depth control for protecting the web application against attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Web application firewall (WAF)

    Why this is correct

    A web application firewall inspects inbound HTTP requests, blocking SQL injection, cross-site scripting and similar attacks before they reach the application. Sitting at the network edge, it forms one independent layer in defence in depth, complementing secure coding, RASP and monitoring controls.

  • ✗

    Load balancer with SSL termination

    Why it's wrong here

    SSL termination at a load balancer encrypts traffic in transit only; it provides no application-layer filtering, so injection and cross-site scripting requests still reach the web tier. It is tempting because TLS offloading is a genuine defence-in-depth component, and it would be correct when the requirement is protecting data in transit.

  • ✓

    Runtime application self-protection (RASP)

    Why this is correct

    RASP instruments the application runtime itself, detecting and blocking attacks such as injection from inside the executing process. Because it observes actual behaviour rather than network patterns, it adds a layer that remains effective even if perimeter controls are bypassed, strengthening defence in depth.

  • ✗

    Single sign-on (SSO)

    Why it's wrong here

    SSO is an authentication method, not a defense-in-depth control per se.

  • ✓

    Network segmentation

    Why this is correct

    Network segmentation divides the application into isolated zones with restricted east-west traffic, limiting lateral movement if a component is compromised. This satisfies defence in depth by adding a containment layer beyond perimeter controls, so a single breach cannot reach backend databases or management interfaces.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.