CAS-004 Security Operations Practice Question
A security administrator is configuring a new web server and wants to ensure that it is protected against cross-site scripting (XSS) attacks. Which of the following controls should the administrator implement to BEST mitigate XSS?
⚠ Common exam trap
The trap here is assuming that a WAF or CSP alone can fully prevent XSS, when they are only additional layers and not the root fix.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Input validation and output encoding
Cross-site scripting occurs when untrusted data is included in web output without proper handling. Input validation ensures data is safe, and output encoding ensures it is rendered as text, not code. These controls directly address the vulnerability. A WAF, HTTPS, and CSP are supplementary but do not fix the underlying issue. Thus, input validation and output encoding are the best mitigations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Content Security Policy (CSP)
Why it's wrong here
CSP is a browser security mechanism that can restrict sources of executable scripts, mitigating some XSS impact, but it is not a complete solution and requires careful configuration. It does not address the root cause of input handling. While CSP is valuable as a defense-in-depth measure, it is not the best primary control to prevent XSS. Input validation and output encoding are more fundamental.
- ✗
Web application firewall (WAF) in blocking mode
Why it's wrong here
A WAF can detect and block some XSS attempts based on signatures, but it is not foolproof and can be bypassed with obfuscation or new attack vectors. Relying solely on a WAF does not address the root cause of XSS, which is improper handling of user input. While a WAF adds defense in depth, it is not the best primary mitigation.
- ✓
Input validation and output encoding
Why this is correct
Input validation ensures that user-supplied data conforms to expected formats, while output encoding (e.g., HTML entity encoding) ensures that any data rendered in the browser is treated as data, not executable code. Together, they prevent XSS by stopping malicious scripts from being injected and executed. This is a fundamental and effective mitigation for XSS.
- ✗
HTTPS with HSTS
Why it's wrong here
HTTPS encrypts data in transit and HSTS enforces secure connections, but they do not prevent XSS. XSS occurs when malicious scripts are executed in the user's browser, regardless of transport security. HTTPS protects against eavesdropping and man-in-the-middle attacks, not script injection. Therefore, it does not mitigate XSS.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.