CAS-004 Security Operations Practice Question
A security engineer is configuring a web application firewall (WAF) to protect a public-facing application from common attacks. The engineer wants to ensure the WAF can detect and block SQL injection and cross-site scripting (XSS) attempts. Which TWO of the following WAF capabilities should the engineer enable? (Choose two.)
⚠ Common exam trap
The trap here is assuming that SSL/TLS termination alone provides protection against SQL injection and XSS, when it only enables inspection of encrypted traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Signature-based detection for known attack patterns
To detect and block SQL injection and XSS, the WAF should use signature-based detection to recognize known attack patterns and a positive security model to enforce strict input validation. These two capabilities directly address the attack vectors. Rate limiting, SSL termination, and IP reputation are useful but do not specifically target SQL injection or XSS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IP reputation blocking based on threat intelligence feeds
Why it's wrong here
IP reputation blocking denies requests from known malicious IP addresses, which can reduce overall attack volume. However, it does not specifically detect SQL injection or XSS payloads from non-blacklisted sources. Attackers can use compromised or new IPs, so this is not a primary defense against those attacks.
- ✓
Signature-based detection for known attack patterns
Why this is correct
Signature-based detection uses predefined patterns to identify known attack payloads for SQL injection and XSS. It is effective for common attacks and is a standard WAF feature. Enabling this helps block well-known malicious requests based on their structure and content.
- ✗
SSL/TLS termination for encrypted traffic inspection
Why it's wrong here
SSL/TLS termination allows the WAF to decrypt and inspect encrypted traffic, which is necessary if the application uses HTTPS. However, it is not a detection or blocking mechanism for SQL injection or XSS; it only enables visibility. Without detection rules, termination alone does not protect against these attacks.
- ✗
Rate limiting to prevent brute force attacks
Why it's wrong here
Rate limiting mitigates brute force and denial-of-service attacks by restricting the number of requests from a single source. It does not directly detect or block SQL injection or XSS payloads, as those attacks can be sent within the rate limit. Therefore, it is not the primary capability for the stated goal.
- ✓
Positive security model with whitelisting of allowed parameters
Why this is correct
A positive security model defines what is allowed, such as valid parameter formats and lengths, and blocks everything else. This is highly effective for preventing SQL injection and XSS because it rejects unexpected input. It complements signature-based detection by catching novel attacks that do not match known signatures.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.