Courseiva
easyMultiple ChoiceObjective-mapped

CAS-004 Practice Question: Wants to implement a solution that automatically…

An organization wants to implement a solution that automatically detects and blocks malicious traffic based on known signatures and behavioral anomalies. Which of the following should be deployed?

⚠ Common exam trap

Many exam-takers confuse a next-generation firewall's application control with the deep packet inspection and behavioral analysis capabilities of a dedicated IDS/IPS, overlooking that NGFWs typically lack comprehensive signature-based threat detection for non-application-layer attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Network-based IDS/IPS

A network-based IDS/IPS (Intrusion Detection/Prevention System) is designed to inspect network traffic in real time, using a combination of signature-based detection (matching known attack patterns) and behavioral/anomaly-based detection (identifying deviations from normal traffic baselines). This dual approach allows it to both detect and automatically block malicious traffic, fulfilling the organization's requirement directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Next-generation firewall with application control

    Why it's wrong here

    A firewall typically works at layers 3-4 and may not inspect application-layer anomalies effectively.

  • Web application firewall (WAF)

    Why it's wrong here

    WAF only protects web applications.

  • Security information and event management (SIEM) system

    Why it's wrong here

    SIEM is for log aggregation and analysis, not inline blocking.

  • Network-based IDS/IPS

    Why this is correct

    IDS/IPS combined provides detection and prevention for known signatures and anomalies.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.