Courseiva
easyMultiple Choice

CAS-004 Practice Question: A small business is designing a defense-in-depth…

A small business is designing a defense-in-depth strategy for its e-commerce website. The web server is hosted in a cloud provider and handles credit card transactions. Which of the following additional controls best complements the existing firewall and IDS?

⚠ Common exam trap

Many exam-takers confuse a SIEM or load balancer with a security control, but the question specifically asks for a control that 'complements' existing firewall and IDS by addressing the missing application-layer protection, which only a WAF provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a web application firewall (WAF)

A web application firewall (WAF) is the correct complement because it specifically protects against application-layer attacks (e.g., SQL injection, cross-site scripting) that a network firewall and IDS cannot block. Since the e-commerce site handles credit card transactions, a WAF is critical for PCI DSS compliance and to filter malicious HTTP/HTTPS traffic targeting the web application logic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up a security information and event management (SIEM) system

    Why it's wrong here

    A SIEM aggregates and correlates logs, providing detection and visibility, but the existing firewall and IDS already cover monitoring. The gap for card transactions is protecting stored and transmitted data. SIEM is the right complement when log sources are numerous and correlation across them is missing, not when payment data needs encryption or tokenisation.

  • ✗

    Add a load balancer with SSL termination

    Why it's wrong here

    SSL termination offloads TLS but provides no inspection or detection capability, so it adds no security layer against card-data threats. It tempts because load balancers improve availability and centralise certificates, yet the stem already has firewall and IDS and needs a control that detects or blocks application-layer attacks.

  • ✓

    Implement a web application firewall (WAF)

    Why this is correct

    A web application firewall inspects HTTP/S traffic, filtering SQL injection and cross-site scripting that a network firewall and IDS cannot parse at layer 7. This directly protects the credit card transaction data the e-commerce site handles, satisfying the stem's requirement for a complementary control at the application layer.

  • ✗

    Deploy a network-based antivirus on the web server

    Why it's wrong here

    Host-based antivirus on the server duplicates endpoint protection already implied and does not inspect the encrypted transaction path; a WAF or tokenisation addresses cardholder-data threats. It tempts because antivirus is a familiar defence-in-depth layer, but network-based AV cannot see TLS traffic and adds little beyond the existing IDS.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.