CV0-004 Security Practice Question
A security administrator is configuring a web application firewall (WAF) to protect against SQL injection attacks. Which WAF feature should be enabled?
⚠ Common exam trap
CV0-004 often tests WAF feature selection, and the trap is choosing rate limiting or geo-blocking because they sound like security controls, when only the OWASP rule set actually inspects request payloads for SQL injection patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OWASP rule set
The OWASP rule set (also called OWASP Core Rule Set, CRS) is a collection of generic attack detection rules specifically designed to protect web applications against the OWASP Top 10, including SQL injection, cross-site scripting, and command injection. Enabling it on a WAF provides immediate, well-tested signatures for SQLi patterns. This directly addresses the requirement to protect against SQL injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Geo-blocking
Why it's wrong here
Geo-blocking filters requests by source country, which does nothing to inspect SQL syntax inside request bodies or parameters. It is tempting because it reduces attack surface from known hostile regions, and it would be the right control when policy requires blocking traffic from specific countries.
- ✗
Rate limiting
Why it's wrong here
Rate limiting caps request volume per client or timeframe, so a slow, low-volume SQL injection payload passes untouched. It is tempting because it mitigates brute-force and denial-of-service floods, and would be correct when the requirement is throttling abusive request rates rather than inspecting query content.
- ✓
OWASP rule set
Why this is correct
The OWASP rule set supplies preconfigured signatures that detect and block SQL injection patterns in inbound requests, directly satisfying the requirement to protect the web application. Unlike generic rate limiting or IP reputation, these rules inspect payload syntax against known injection techniques, so enabling the OWASP core rule set on the WAF mitigates the attack class named in the stem.
- ✗
DDoS protection
Why it's wrong here
DDoS protection mitigates volumetric attacks that flood bandwidth or exhaust server resources, but it does not inspect HTTP request payloads for malicious SQL syntax, which is the specific vector in SQL injection. It is tempting because a WAF commonly bundles DDoS mitigation alongside application-layer filtering, and in a scenario where availability is threatened by a flood attack, enabling DDoS protection would be the correct choice.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.