Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A security administrator is configuring a web application firewall (WAF) to protect against SQL injection attacks. Which WAF feature should be enabled?

⚠ Common exam trap

CV0-004 often tests WAF feature selection, and the trap is choosing rate limiting or geo-blocking because they sound like security controls, when only the OWASP rule set actually inspects request payloads for SQL injection patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OWASP rule set

The OWASP rule set (also called OWASP Core Rule Set, CRS) is a collection of generic attack detection rules specifically designed to protect web applications against the OWASP Top 10, including SQL injection, cross-site scripting, and command injection. Enabling it on a WAF provides immediate, well-tested signatures for SQLi patterns. This directly addresses the requirement to protect against SQL injection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Geo-blocking

    Why it's wrong here

    Geo-blocking filters requests by source country, which does nothing to inspect SQL syntax inside request bodies or parameters. It is tempting because it reduces attack surface from known hostile regions, and it would be the right control when policy requires blocking traffic from specific countries.

  • ✗

    Rate limiting

    Why it's wrong here

    Rate limiting caps request volume per client or timeframe, so a slow, low-volume SQL injection payload passes untouched. It is tempting because it mitigates brute-force and denial-of-service floods, and would be correct when the requirement is throttling abusive request rates rather than inspecting query content.

  • ✓

    OWASP rule set

    Why this is correct

    The OWASP rule set supplies preconfigured signatures that detect and block SQL injection patterns in inbound requests, directly satisfying the requirement to protect the web application. Unlike generic rate limiting or IP reputation, these rules inspect payload syntax against known injection techniques, so enabling the OWASP core rule set on the WAF mitigates the attack class named in the stem.

  • ✗

    DDoS protection

    Why it's wrong here

    DDoS protection mitigates volumetric attacks that flood bandwidth or exhaust server resources, but it does not inspect HTTP request payloads for malicious SQL syntax, which is the specific vector in SQL injection. It is tempting because a WAF commonly bundles DDoS mitigation alongside application-layer filtering, and in a scenario where availability is threatened by a flood attack, enabling DDoS protection would be the correct choice.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.