Courseiva
Security →easyMultiple Choice

CV0-004 Security Practice Question

A cloud administrator needs to protect a web application from common attacks such as SQL injection and cross-site scripting (XSS). Which cloud service should be implemented?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web Application Firewall (WAF)

A Web Application Firewall (WAF) is specifically designed to filter and monitor HTTP traffic, blocking common web exploits like SQL injection and XSS. Cloud providers offer WAF services (e.g., AWS WAF, Azure WAF, Cloud Armor).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DDoS protection service

    Why it's wrong here

    DDoS protection absorbs volumetric and protocol floods at the network edge; it inspects no HTTP payload, so SQL injection and XSS pass through. It tempts because it is a common web-facing security control, but it addresses availability, not application-layer input validation.

  • ✗

    Network ACL

    Why it's wrong here

    Network ACLs filter traffic by IP address, port and protocol at subnet boundaries, never parsing HTTP request content, so injection payloads traverse freely. It tempts as a cheap perimeter control, but it operates at layers 3 and 4, not layer 7.

  • ✗

    Security group

    Why it's wrong here

    Security groups are stateful layer 3/4 packet filters permitting or denying traffic by address and port; they cannot inspect HTTP bodies for injection or script payloads. It tempts as a default cloud firewall, but a web application firewall is needed at layer 7.

  • ✓

    Web Application Firewall (WAF)

    Why this is correct

    A Web Application Firewall inspects HTTP/S requests at layer 7 and blocks signatures matching SQL injection and XSS payloads before they reach the application. Network firewalls and load balancers operate at lower layers and cannot parse request content to detect these attacks.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.