CV0-004 Web Application Firewall (WAF) Practice Question
A company running a critical web application wants to protect against SQL injection and cross-site scripting attacks. The application is behind a load balancer. Which type of service should be deployed to provide this protection?
⚠ Common exam trap
It's easy for candidates to confuse a web application firewall with a DDoS protection service, thinking the latter provides application-layer attack protection. However, DDoS protection focuses on volumetric attacks while a WAF handles web-specific exploits like SQL injection and XSS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web application firewall (WAF)
A web application firewall (WAF) is designed to protect web applications from common web exploits like SQL injection and cross-site scripting. It can be integrated with load balancers to inspect HTTP/HTTPS traffic and filter malicious requests based on customizable rules. This makes it the correct choice for the described threat scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network firewall
Why it's wrong here
A network firewall filters by IP address, port and protocol at layers 3–4, so it cannot inspect HTTP payloads to detect SQL injection or XSS strings. It is tempting because firewalls are the default perimeter control, and would be correct for blocking unwanted ports or source networks rather than application-layer attacks.
- ✗
DDoS protection service
Why it's wrong here
DDoS protection absorbs volumetric and protocol floods, not application-layer injection payloads, so SQL injection and XSS requests pass through untouched. It is tempting because it defends web applications behind load balancers, and would be correct if the threat were traffic flooding rather than crafted input.
- ✗
Intrusion detection system
Why it's wrong here
An IDS only detects and alerts on malicious traffic; it neither sits inline nor rewrites requests, so SQL injection and XSS payloads still reach the application. It is tempting because signature detection covers both attack classes, and it would be right for monitoring and alerting, but blocking requires a web application firewall.
- ✓
Web application firewall (WAF)
Why this is correct
A WAF inspects HTTP/HTTPS traffic at layer 7, matching signatures to block SQL injection and cross-site scripting payloads before they reach the application. Deployed behind the load balancer, it satisfies the requirement to filter malicious web requests targeting this critical application.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.