CV0-004 Security Practice Question
A cloud architect is designing a network to protect a web application from common attacks such as SQL injection and cross-site scripting. Which cloud service should be used?
⚠ Common exam trap
CV0-004 often tests the confusion between Layer 3/4 controls (Security Groups, NACLs, DDoS Protection) and Layer 7 controls (WAF) — candidates pick Security Groups or NACLs because they sound like firewalls, but only a WAF inspects application payloads for SQLi/XSS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic and block application-layer attacks such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 threats. It operates at Layer 7 and applies rule sets or signatures to web requests and responses. This makes it the correct cloud service for protecting a web application from these attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DDoS Protection
Why it's wrong here
DDoS Protection absorbs volumetric and protocol floods at the network edge, but SQL injection and XSS arrive as well-formed HTTP requests, so scrubbing capacity never inspects their payloads. It is tempting because it is the standard edge hardening for public web endpoints, and would be correct against SYN floods or amplification attacks.
- ✗
Network ACL
Why it's wrong here
Network ACLs filter traffic by IP address, port and protocol at the subnet boundary, so they cannot inspect HTTP payloads for SQL injection or XSS strings. They are tempting because they cheaply segment tiers and block unwanted CIDR ranges, which is the right control for restricting lateral movement or locking down administrative ports.
- ✓
Web Application Firewall (WAF)
Why this is correct
A WAF inspects HTTP/S traffic at the application layer, filtering injection and scripting payloads via managed rule sets. Network firewalls and security groups operate at lower layers and cannot parse request content, so they miss these attacks. This directly satisfies the requirement to protect the web application.
- ✗
Security Group
Why it's wrong here
A security group is a stateful virtual firewall filtering traffic by IP, port and protocol at the network layer; it cannot inspect HTTP payloads to detect SQL injection or cross-site scripting. Network filtering is tempting for perimeter control, and would be correct for restricting inbound ports rather than application-layer attack inspection.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.