mediumMultiple Select
CAS-004 Practice Question: A security architect is evaluating web…
A security architect is evaluating web application firewall (WAF) features to protect against common attacks. Which TWO of the following attacks can a WAF most effectively prevent?
⚠ Common exam trap
CAS-005 often tests the scope of WAF protection, and candidates frequently overestimate its ability to stop session hijacking, CSRF, or DDoS, which require different controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cross-site scripting (XSS)
A WAF is designed to inspect HTTP/HTTPS request and response payloads and apply rule sets (e.g., OWASP ModSecurity Core Rule Set) to block injection-style attacks, so option B (cross-site scripting, XSS) is correct because a WAF can detect and block malicious script payloads such as <script> tags or event handlers in parameters, headers, and bodies. Option C (SQL injection) is also correct because a WAF can match SQL meta-characters and known injection patterns like ' OR 1=1-- or UNION SELECT to stop malicious queries before they reach the database. Option A (session hijacking) is not primarily a WAF function, since it depends on stealing or predicting session tokens and is better mitigated by TLS, HttpOnly/Secure cookies, and token rotation. Option D (DDoS) is not effectively handled by a WAF alone; volumetric and network-layer floods require scrubbing centers, CDNs, or dedicated DDoS protection. Option E (CSRF) is not reliably prevented by a WAF because it exploits a victim's authenticated browser session, and the proper defenses are anti-CSRF tokens, SameSite cookies, and origin/referer validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session hijacking
Why it's wrong here
Session hijacking abuses a stolen or predicted session token after authentication, which a WAF cannot detect because the request carries valid credentials. It is tempting since WAFs inspect HTTP traffic, but they are designed to filter malicious request patterns such as SQL injection, not to validate session ownership.
- ✓
Cross-site scripting (XSS)
Why this is correct
A WAF inspects HTTP request and response payloads, so it can detect and block cross-site scripting by filtering malicious scripts before they reach the application. XSS travels in web traffic, which is exactly the layer a WAF parses and controls.
- ✓
SQL injection
Why this is correct
A WAF parses HTTP parameters and applies signature and anomaly rules to detect SQL injection payloads in requests, blocking them before they reach the database; this directly addresses the requirement to prevent common web application attacks.
- ✗
Distributed denial-of-service (DDoS)
Why it's wrong here
A WAF inspects HTTP request content to block injection and scripting payloads; volumetric DDoS floods are absorbed by edge scrubbing and rate limiting, not application-layer signature matching. It is tempting because WAFs do log and throttle malicious traffic, but DDoS mitigation belongs to dedicated network-layer services.
- ✗
Cross-site request forgery (CSRF)
Why it's wrong here
CSRF exploits a victim's browser automatically attaching their session cookie to a forged request, which appears legitimate to a WAF inspecting HTTP payloads. It is tempting because WAFs handle web-layer attacks, but CSRF is mitigated with anti-CSRF tokens and SameSite cookie attributes rather than signature filtering.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.