Courseiva
Security Operations →mediumMultiple Select

CAS-004 Security Operations Practice Question

A security engineer is configuring a web application firewall (WAF) to protect a public-facing application from common attacks. The engineer wants to ensure the WAF can detect and block SQL injection and cross-site scripting (XSS) attempts. Which TWO of the following WAF capabilities should the engineer enable? (Choose two.)

⚠ Common exam trap

The trap here is assuming that SSL/TLS termination alone provides protection against SQL injection and XSS, when it only enables inspection of encrypted traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Signature-based detection for known attack patterns

To detect and block SQL injection and XSS, the WAF should use signature-based detection to recognize known attack patterns and a positive security model to enforce strict input validation. These two capabilities directly address the attack vectors. Rate limiting, SSL termination, and IP reputation are useful but do not specifically target SQL injection or XSS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IP reputation blocking based on threat intelligence feeds

    Why it's wrong here

    IP reputation blocking denies requests from known malicious IP addresses, which can reduce overall attack volume. However, it does not specifically detect SQL injection or XSS payloads from non-blacklisted sources. Attackers can use compromised or new IPs, so this is not a primary defense against those attacks.

  • ✓

    Signature-based detection for known attack patterns

    Why this is correct

    Signature-based detection uses predefined patterns to identify known attack payloads for SQL injection and XSS. It is effective for common attacks and is a standard WAF feature. Enabling this helps block well-known malicious requests based on their structure and content.

  • ✗

    SSL/TLS termination for encrypted traffic inspection

    Why it's wrong here

    SSL/TLS termination allows the WAF to decrypt and inspect encrypted traffic, which is necessary if the application uses HTTPS. However, it is not a detection or blocking mechanism for SQL injection or XSS; it only enables visibility. Without detection rules, termination alone does not protect against these attacks.

  • ✗

    Rate limiting to prevent brute force attacks

    Why it's wrong here

    Rate limiting mitigates brute force and denial-of-service attacks by restricting the number of requests from a single source. It does not directly detect or block SQL injection or XSS payloads, as those attacks can be sent within the rate limit. Therefore, it is not the primary capability for the stated goal.

  • ✓

    Positive security model with whitelisting of allowed parameters

    Why this is correct

    A positive security model defines what is allowed, such as valid parameter formats and lengths, and blocks everything else. This is highly effective for preventing SQL injection and XSS because it rejects unexpected input. It complements signature-based detection by catching novel attacks that do not match known signatures.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.