Courseiva
mediumMultiple Select

CAS-004 Practice Question: A security architect is evaluating web…

A security architect is evaluating web application firewall (WAF) features to protect against common attacks. Which TWO of the following attacks can a WAF most effectively prevent?

⚠ Common exam trap

CAS-005 often tests the scope of WAF protection, and candidates frequently overestimate its ability to stop session hijacking, CSRF, or DDoS, which require different controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cross-site scripting (XSS)

A WAF is designed to inspect HTTP/HTTPS request and response payloads and apply rule sets (e.g., OWASP ModSecurity Core Rule Set) to block injection-style attacks, so option B (cross-site scripting, XSS) is correct because a WAF can detect and block malicious script payloads such as <script> tags or event handlers in parameters, headers, and bodies. Option C (SQL injection) is also correct because a WAF can match SQL meta-characters and known injection patterns like ' OR 1=1-- or UNION SELECT to stop malicious queries before they reach the database. Option A (session hijacking) is not primarily a WAF function, since it depends on stealing or predicting session tokens and is better mitigated by TLS, HttpOnly/Secure cookies, and token rotation. Option D (DDoS) is not effectively handled by a WAF alone; volumetric and network-layer floods require scrubbing centers, CDNs, or dedicated DDoS protection. Option E (CSRF) is not reliably prevented by a WAF because it exploits a victim's authenticated browser session, and the proper defenses are anti-CSRF tokens, SameSite cookies, and origin/referer validation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Session hijacking

    Why it's wrong here

    Session hijacking abuses a stolen or predicted session token after authentication, which a WAF cannot detect because the request carries valid credentials. It is tempting since WAFs inspect HTTP traffic, but they are designed to filter malicious request patterns such as SQL injection, not to validate session ownership.

  • ✓

    Cross-site scripting (XSS)

    Why this is correct

    A WAF inspects HTTP request and response payloads, so it can detect and block cross-site scripting by filtering malicious scripts before they reach the application. XSS travels in web traffic, which is exactly the layer a WAF parses and controls.

  • ✓

    SQL injection

    Why this is correct

    A WAF parses HTTP parameters and applies signature and anomaly rules to detect SQL injection payloads in requests, blocking them before they reach the database; this directly addresses the requirement to prevent common web application attacks.

  • ✗

    Distributed denial-of-service (DDoS)

    Why it's wrong here

    A WAF inspects HTTP request content to block injection and scripting payloads; volumetric DDoS floods are absorbed by edge scrubbing and rate limiting, not application-layer signature matching. It is tempting because WAFs do log and throttle malicious traffic, but DDoS mitigation belongs to dedicated network-layer services.

  • ✗

    Cross-site request forgery (CSRF)

    Why it's wrong here

    CSRF exploits a victim's browser automatically attaching their session cookie to a forged request, which appears legitimate to a WAF inspecting HTTP payloads. It is tempting because WAFs handle web-layer attacks, but CSRF is mitigated with anti-CSRF tokens and SameSite cookie attributes rather than signature filtering.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.