CAS-004 Security Architecture Practice Question
A security architect is implementing an API gateway to protect microservices. Which security capability is uniquely provided by an API gateway compared to a traditional web application firewall (WAF)?
⚠ Common exam trap
CAS-005 often tests the overlap between WAF and API gateway capabilities, tricking candidates into picking a generic web security control (TLS, SQLi, XSS) that both devices can perform instead of the consumer-aware capability unique to the gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rate limiting per API consumer
Rate limiting per API consumer is a capability unique to API gateways because the gateway understands API keys, OAuth tokens, and consumer identities, allowing it to enforce quotas and throttling on a per-client basis. A traditional WAF operates at the network/HTTP layer and inspects traffic patterns for attacks but does not natively identify API consumers or apply per-consumer quotas. This makes per-consumer rate limiting the distinguishing capability in this comparison.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TLS termination
Why it's wrong here
TLS termination is performed by load balancers, reverse proxies and WAFs alike, so it is not unique to an API gateway. It is tempting because gateways do terminate TLS, and it would be the right answer if the question asked how inbound traffic is decrypted before inspection.
- ✗
SQL injection prevention
Why it's wrong here
SQL injection prevention is a signature-based WAF function, and API gateways typically delegate it rather than provide it uniquely. It is tempting because APIs are frequent SQL injection targets, and it would be correct if the question asked which control inspects request payloads for database attack patterns.
- ✗
Cross-site scripting (XSS) filtering
Why it's wrong here
XSS filtering is a classic WAF capability, not something an API gateway uniquely supplies. It is tempting because APIs returning HTML or JSON can reflect script, and it would be the right answer if the question asked which control sanitises browser-executed content in web responses.
- ✓
Rate limiting per API consumer
Why this is correct
An API gateway understands individual consumers via keys, OAuth scopes or tokens, so it can apply quotas and throttling per client. A WAF inspects HTTP traffic for attack signatures but lacks this per-consumer identity context, making per-consumer rate limiting the unique capability.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.