Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is designing a defense-in-depth strategy for a web application. Which combination of controls provides overlapping protection against SQL injection attacks?

⚠ Common exam trap

CAS-005 often tests defense-in-depth by presenting perimeter controls (WAF, IDS) as tempting answers — candidates must recognize that overlapping protection against a specific application flaw requires controls at the application layer, not just the network layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Input validation and parameterized queries

Input validation and parameterized queries provide overlapping, defense-in-depth protection against SQL injection: input validation rejects malformed or malicious input at the application boundary, while parameterized queries ensure user input is treated as data, not executable SQL, even if validation is bypassed. Together they address the root cause of SQLi at multiple layers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encryption and hashing

    Why it's wrong here

    Encryption and hashing protect data confidentiality at rest and in transit, and password storage respectively; neither parses SQL syntax, so injected statements still reach the database. They tempt because they are standard defence-in-depth controls, but parameterised queries and input validation are what actually neutralise injection.

  • ✓

    Input validation and parameterized queries

    Why this is correct

    Input validation rejects malformed or suspicious input at the boundary, while parameterised queries ensure user-supplied values are treated as data, never executable SQL. Together they provide overlapping defence: if validation is bypassed, parameterisation still prevents injected statements from altering query structure.

  • ✗

    Intrusion detection system (IDS) and antivirus

    Why it's wrong here

    An IDS detects malicious traffic patterns and antivirus targets host malware; neither interprets SQL statements, so injection payloads pass through as legitimate queries. They tempt as familiar layered controls, but parameterised queries and input validation are the mechanisms that prevent injected SQL from executing.

  • ✗

    Web application firewall (WAF) and network segmentation

    Why it's wrong here

    A WAF filters HTTP requests for injection signatures, but network segmentation only isolates subnets and does nothing to inspect SQL payloads, so the layers do not overlap on the same attack vector. Segmentation is tempting because it limits lateral movement after a breach, which is the right goal for containing compromised hosts, not for blocking SQL injection.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.