Courseiva
mediumMultiple Choice

CAS-004 Practice Question: A security architect is reviewing the…

A security architect is reviewing the architecture of a critical web application that handles sensitive financial transactions. The application is deployed across three tiers: a web server, an application server, and a database server. The application is protected by a web application firewall (WAF) and a network-based intrusion detection system (IDS). Recent penetration testing identified a SQL injection vulnerability in the application's search feature. The architect needs to propose a remediation that minimizes performance impact and maintains defense in depth. The development team is slow to fix code due to legacy dependencies. What should the security architect recommend as the MOST effective immediate control?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a WAF rule to block common SQL injection payloads and signatures.

The development team is slow to fix the SQL injection vulnerability in code, so an immediate control is needed. Adding a WAF rule (option C) can block common SQL injection payloads at the perimeter without code changes, minimizing performance impact and maintaining defense in depth. Option A (disable search) is too disruptive. Option B (isolate database server) is a good defense-in-depth measure but does not address the vulnerability at the application layer. Option D (increase IDS sensitivity) only detects, not prevents. Therefore, C is the most effective immediate control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the search feature until the code is fixed.

    Why it's wrong here

    Disabling search removes functionality entirely rather than applying a compensating control, and the stem asks for remediation minimising performance impact while preserving defence in depth. It is tempting as a guaranteed stopgap, but it is availability-destroying and unnecessary when a WAF can filter the injection pattern.

  • ✗

    Isolate the database server on a separate network segment with strict firewall rules.

    Why it's wrong here

    Segmenting the database server restricts lateral movement but does not stop SQL injection reaching the database through the legitimate application path. It is tempting as defence in depth, yet the injection arrives over permitted application traffic, so network rules cannot distinguish malicious queries from normal ones.

  • ✓

    Add a WAF rule to block common SQL injection payloads and signatures.

    Why this is correct

    A WAF rule blocks SQL injection payloads at the perimeter without touching legacy code, giving immediate virtual patching while developers work. It satisfies the constraint of minimising performance impact and preserving defence in depth alongside the existing IDS and network controls.

  • ✗

    Increase the IDS sensitivity to detect SQL injection attempts and automatically block them.

    Why it's wrong here

    A network IDS passively inspects traffic; raising sensitivity generates alerts and cannot reliably block SQL injection, and inline prevention would require IPS placement. It is tempting because IDS already monitors the traffic, but signature tuning yields false positives without the application-layer parsing a WAF performs.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.