Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A security engineer is configuring a web application firewall (WAF) to protect against injection attacks. The application uses a relational database and reflects user input in HTML pages. The engineer must choose a WAF rule set that provides the BEST protection with minimal false positives. Which approach should the engineer take?

⚠ Common exam trap

The trap here is assuming that the most aggressive blocking configuration always provides the best protection, when in practice tuning and targeted rules are needed to avoid false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy the WAF in learning mode to baseline normal traffic, then enable targeted rules for SQL injection and XSS with virtual patching for known vulnerabilities.

The best approach is to use learning mode to understand normal traffic, then enable targeted SQL injection and XSS rules along with virtual patching for known vulnerabilities. This minimizes false positives while providing strong protection. Generic blocking rules, overly broad regex, or disabling WAF rules entirely either cause operational issues or reduce defense-in-depth.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy the WAF in learning mode to baseline normal traffic, then enable targeted rules for SQL injection and XSS with virtual patching for known vulnerabilities.

    Why this is correct

    Learning mode establishes a baseline of legitimate traffic, allowing the engineer to tune rules and reduce false positives. Targeted rules for SQL injection and XSS address the specific threats, and virtual patching protects against known vulnerabilities until code fixes are deployed. This approach balances protection with operational stability.

  • ✗

    Create custom regular expression rules that block any request containing single quotes, double quotes, or angle brackets.

    Why it's wrong here

    Blocking all requests with these characters will cause significant false positives, as legitimate input often includes quotes and angle brackets. This approach is overly broad and does not distinguish between malicious and benign contexts. It also fails to address other injection vectors like encoded payloads or SQL keywords without quotes.

  • ✗

    Enable the WAF's generic SQL injection and cross-site scripting (XSS) rules in blocking mode with a default action of deny.

    Why it's wrong here

    Generic rules often produce false positives because they match patterns that may be legitimate in some applications. Blocking mode with a default deny can disrupt normal traffic. Without tuning or learning mode, this approach risks breaking the application and eroding trust in the WAF. It also may not cover application-specific input contexts.

  • ✗

    Rely solely on the database's parameterized queries and disable all WAF injection rules to avoid false positives.

    Why it's wrong here

    Parameterized queries are an excellent defense, but disabling WAF rules removes a layer of defense-in-depth. The WAF can catch attacks that bypass parameterization due to coding errors or other vulnerabilities. The requirement is to choose a WAF rule set that provides the best protection, not to eliminate WAF protection entirely.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.