GSEC Network Security Devices Practice Question
A network security team is deploying a web application firewall (WAF) in front of an e-commerce site. The security architect wants the WAF to learn normal application behavior and block deviations without manually writing signatures for every new attack. Which WAF deployment and configuration approach best matches this requirement?
⚠ Common exam trap
Many exam-takers confuse a positive security model, which requires explicit allow rules, with anomaly detection, which learns normal behavior and flags deviations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the WAF in reverse proxy mode with anomaly detection and a learning period that builds a baseline of normal application behavior before enforcement.
Behavioral anomaly detection in a reverse proxy WAF builds a baseline of normal application behavior during a learning period, then flags and blocks requests that deviate from that baseline. This reduces reliance on manually written signatures and matches the architect's goal. Transparent bridge with a positive model still needs explicit definitions, monitor-only mode cannot block, and host-based static rules do not learn, so the reverse proxy anomaly approach is the only one that satisfies all stated requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy the WAF in reverse proxy mode with anomaly detection and a learning period that builds a baseline of normal application behavior before enforcement.
Why this is correct
Reverse proxy mode places the WAF inline for HTTP/HTTPS traffic, and anomaly detection with a learning period builds a behavioral baseline of legitimate requests. After the baseline is established, deviations from normal parameters, methods, and request patterns can be blocked without hand-written signatures. This directly matches the architect's requirement to learn normal behavior and block deviations, while reverse proxy mode gives the WAF full visibility and control over application traffic.
- ✗
Deploy the WAF as a host-based agent on each web server with a static rule set based on the OWASP Core Rule Set.
Why it's wrong here
A host-based agent with a static rule set relies on predefined signatures, not behavioral learning. The OWASP Core Rule Set is valuable but requires tuning and does not automatically learn each application's normal traffic. Host-based deployment also consumes server resources and may not see traffic before it reaches the application. This approach does not satisfy the requirement to learn normal behavior and block deviations without writing new signatures.
- ✗
Deploy the WAF in monitor-only mode with signature-based rules and alert on known attack patterns.
Why it's wrong here
Monitor-only mode does not block traffic, so it cannot meet the requirement to block deviations. Signature-based rules also require manual updates and do not learn normal application behavior. While monitoring is useful during tuning, the scenario explicitly asks for a configuration that blocks deviations after learning normal behavior. This option provides visibility but not enforcement or behavioral learning, so it fails the stated goal.
- ✗
Deploy the WAF in transparent bridge mode with a positive security model that only allows explicitly defined methods, parameters, and content types.
Why it's wrong here
A positive security model can be very strong, but it requires explicit definition of all allowed behavior and does not learn deviations automatically. It can cause extensive false positives when the application changes, and it typically needs manual maintenance. The requirement is to learn normal behavior and block deviations without writing signatures, which is closer to anomaly-based or behavioral learning than to a strict positive model.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.