easyMultiple ChoiceObjective-mapped
CAS-004 Practice Question: Wants to implement a solution that automatically…
An organization wants to implement a solution that automatically detects and blocks malicious traffic based on known signatures and behavioral anomalies. Which of the following should be deployed?
⚠ Common exam trap
Many exam-takers confuse a next-generation firewall's application control with the deep packet inspection and behavioral analysis capabilities of a dedicated IDS/IPS, overlooking that NGFWs typically lack comprehensive signature-based threat detection for non-application-layer attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network-based IDS/IPS
A network-based IDS/IPS (Intrusion Detection/Prevention System) is designed to inspect network traffic in real time, using a combination of signature-based detection (matching known attack patterns) and behavioral/anomaly-based detection (identifying deviations from normal traffic baselines). This dual approach allows it to both detect and automatically block malicious traffic, fulfilling the organization's requirement directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Next-generation firewall with application control
Why it's wrong here
A firewall typically works at layers 3-4 and may not inspect application-layer anomalies effectively.
- ✗
Web application firewall (WAF)
Why it's wrong here
WAF only protects web applications.
- ✗
Security information and event management (SIEM) system
Why it's wrong here
SIEM is for log aggregation and analysis, not inline blocking.
- ✓
Network-based IDS/IPS
Why this is correct
IDS/IPS combined provides detection and prevention for known signatures and anomalies.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.