Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is implementing an API gateway to protect microservices. Which security capability is uniquely provided by an API gateway compared to a traditional web application firewall (WAF)?

⚠ Common exam trap

CAS-005 often tests the overlap between WAF and API gateway capabilities, tricking candidates into picking a generic web security control (TLS, SQLi, XSS) that both devices can perform instead of the consumer-aware capability unique to the gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rate limiting per API consumer

Rate limiting per API consumer is a capability unique to API gateways because the gateway understands API keys, OAuth tokens, and consumer identities, allowing it to enforce quotas and throttling on a per-client basis. A traditional WAF operates at the network/HTTP layer and inspects traffic patterns for attacks but does not natively identify API consumers or apply per-consumer quotas. This makes per-consumer rate limiting the distinguishing capability in this comparison.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TLS termination

    Why it's wrong here

    TLS termination is performed by load balancers, reverse proxies and WAFs alike, so it is not unique to an API gateway. It is tempting because gateways do terminate TLS, and it would be the right answer if the question asked how inbound traffic is decrypted before inspection.

  • ✗

    SQL injection prevention

    Why it's wrong here

    SQL injection prevention is a signature-based WAF function, and API gateways typically delegate it rather than provide it uniquely. It is tempting because APIs are frequent SQL injection targets, and it would be correct if the question asked which control inspects request payloads for database attack patterns.

  • ✗

    Cross-site scripting (XSS) filtering

    Why it's wrong here

    XSS filtering is a classic WAF capability, not something an API gateway uniquely supplies. It is tempting because APIs returning HTML or JSON can reflect script, and it would be the right answer if the question asked which control sanitises browser-executed content in web responses.

  • ✓

    Rate limiting per API consumer

    Why this is correct

    An API gateway understands individual consumers via keys, OAuth scopes or tokens, so it can apply quotas and throttling per client. A WAF inspects HTTP traffic for attack signatures but lacks this per-consumer identity context, making per-consumer rate limiting the unique capability.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.