mediumMultiple Choice
CAS-004 Practice Question: A security analyst discovers that a web…
A security analyst discovers that a web application is vulnerable to directory traversal. Which of the following is the MOST effective mitigation?
⚠ Common exam trap
CompTIA often tests the misconception that input validation (e.g., blocking '..') is sufficient, but the trap here is that attackers can bypass such filters with encoding or alternative traversal techniques, making a whitelist the only truly effective mitigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whitelist of allowed file paths
A whitelist of allowed file paths is the most effective mitigation because it defines an explicit set of permissible paths, preventing any unauthorized file access regardless of traversal attempts. Unlike input validation, which can be bypassed with encoding or alternative traversal sequences, a whitelist enforces a positive security model that blocks all unspecified paths, including those using '..' or symbolic links. This approach directly addresses the root cause of directory traversal by restricting the application to only known-safe resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Whitelist of allowed file paths
Why this is correct
An allowlist constrains file access to explicitly permitted paths, so traversal sequences such as ../ cannot resolve to arbitrary files outside the intended directory. This neutralises the vulnerability at the input-validation layer rather than relying on pattern filtering, which is bypassable.
- ✗
Encrypting all files on the server
Why it's wrong here
Encryption at rest protects data if files are stolen, but traversal exploits the application's own file-read logic, which decrypts whatever path it is given. It tempts as defence-in-depth for data confidentiality, and would be correct where the threat is physical disk or backup exfiltration.
- ✗
Chroot jail
Why it's wrong here
A chroot jail confines the process to a subtree, yet the vulnerable application still resolves and serves files within that jail, so traversal simply reaches other paths inside it. It tempts as OS-level isolation, and would be correct for containing a compromised daemon, not for validating user-supplied paths.
- ✗
Input validation that rejects paths containing '..'
Why it's wrong here
Rejecting '..' misses encoded variants such as %2e%2e and absolute paths, and blocks legitimate filenames containing dots. It tempts because input validation is the canonical traversal defence, and would be correct if implemented as canonicalisation followed by allow-listing against a fixed base directory.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.