CAS-004 Security Architecture Practice Question
A security architect is designing an API security strategy for a microservices-based application. The architect needs to ensure that only authenticated and authorized clients can invoke APIs, and that rate limiting is enforced to prevent abuse. Which technology should be placed in front of the microservices?
⚠ Common exam trap
CAS-005 often tests the difference between API Gateway and WAF. Candidates may choose WAF because it sounds security-focused, but WAF does not provide API authentication and rate limiting for microservices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
API Gateway
An API Gateway is designed to handle authentication, authorization, rate limiting, and other cross-cutting concerns for APIs in a microservices architecture. It acts as a single entry point for all API calls, enforcing security policies before requests reach the microservices. This centralizes API security and simplifies management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
API Gateway
Why this is correct
An API gateway terminates client requests and enforces authentication, authorisation and rate limiting centrally before forwarding to microservices, so only validated clients invoke backends. This satisfies the requirement for centralised access control and abuse prevention.
- ✗
Web Application Firewall (WAF)
Why it's wrong here
WAF protects against web application attacks but does not provide API authentication or rate limiting.
- ✗
Reverse proxy
Why it's wrong here
A reverse proxy forwards requests to backends and can terminate TLS, but plain reverse proxies do not natively validate OAuth tokens or enforce per-client quotas. It is tempting because an API gateway is a specialised reverse proxy, and a reverse proxy would be correct if the requirement were merely hiding backend topology rather than authentication and rate limiting.
- ✗
Load balancer
Why it's wrong here
A load balancer distributes connections across backend instances and performs health checks; it does not validate OAuth tokens or apply per-client rate limits. It is tempting because load balancers front microservices and can terminate TLS, and would be correct if the requirement were horizontal scaling or availability rather than authentication and abuse prevention.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.