hardMultiple Select
CAS-004 Practice Question: Which TWO of the following are effective defenses…
Which TWO of the following are effective defenses against Server-Side Request Forgery (SSRF) attacks? (Select TWO.)
⚠ Common exam trap
Many test-takers mistakenly believe that input validation alone is sufficient to prevent SSRF, but attackers can bypass validation via encoding, redirects, or protocol smuggling. Whitelisting outbound destinations and disabling unused URL schemes are the primary effective controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whitelist allowed outbound IP addresses and domains
Option A is correct because an allowlist (whitelist) of permitted outbound IP addresses and domains restricts the destinations a server can reach, so even if an attacker injects an internal URL like http://169.254.169.254/ or http://localhost, the request is denied before it leaves the application. Option D is correct because disabling unused URL schemes such as file://, dict://, gopher://, and ftp:// removes dangerous protocol handlers that SSRF payloads abuse to read local files or pivot to other services, leaving only the required http/https schemes. Option B is not a reliable defense because WAF signature matching is easily bypassed with encoding, DNS rebinding, or novel payloads and cannot understand application-level intent. Option C is ineffective because the Referer header is client-controlled and trivially spoofed or omitted, and it has no bearing on server-initiated requests. Option E is insufficient on its own because URL validation is notoriously hard to implement correctly (bypasses via redirects, alternate IP encodings, and DNS rebinding), so it is not one of the two strongest defenses compared with allowlisting and scheme restriction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Whitelist allowed outbound IP addresses and domains
Why this is correct
Whitelisting permitted outbound IP addresses and domains constrains where the server can send requests, so an SSRF payload cannot reach internal metadata services or arbitrary external hosts. This directly limits the destinations an attacker can abuse.
- ✗
Use a web application firewall (WAF) to block SSRF signatures
Why it's wrong here
A WAF matches request patterns, yet SSRF exploits the server's own outbound requests, which the WAF never inspects; obfuscated or internal-only URLs bypass signatures. WAFs correctly defend against inbound injection and cross-site scripting. Blocking outbound traffic to internal ranges and metadata endpoints is the effective control.
- ✗
Enforce strict referrer headers on requests
Why it's wrong here
Referrer headers are client-supplied and trivially forged or stripped, and the server's outbound fetch carries no referrer to validate. Referrer enforcement belongs in anti-CSRF and hotlink protection. SSRF is stopped by allowlisting destination hosts and denying access to link-local and private address ranges.
- ✓
Disable unused URL schemes (e.g., file://, dict://)
Why this is correct
Restricting URL schemes blocks dangerous handlers such as file:// and dict://, which SSRF exploits to reach local files or internal services. This directly satisfies the stem's requirement for an effective SSRF defence by shrinking the parser's reachable protocols.
- ✗
Implement input validation on all user-supplied URLs
Why it's wrong here
Validating user-supplied URLs helps, but string checks are bypassable via DNS rebinding, redirects, and alternate IP encodings, so it cannot be the sole defence. Input validation is correct for format and schema enforcement. Robust SSRF defence requires network-level egress allowlisting and blocking of internal metadata addresses.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.