Courseiva
mediumMultiple ChoiceObjective-mapped

CISA Practice Question: Is planning to deploy a web application firewall…

An organization is planning to deploy a web application firewall (WAF) to protect a critical application. Which deployment mode should be used to ensure that the WAF can block malicious traffic without introducing a single point of failure?

⚠ Common exam trap

It's easy for candidates to confuse 'high-availability clustering' with 'active-passive clustering,' assuming both eliminate single points of failure equally, but active-passive still has a failover delay and potential traffic loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Inline with high-availability clustering.

Inline with high-availability clustering ensures the WAF can actively inspect and block malicious traffic in real time while eliminating a single point of failure through automatic failover between clustered appliances. This mode maintains traffic flow even if one WAF node fails, meeting both security and availability requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Inline with high-availability clustering.

    Why this is correct

    Provides blocking and redundancy.

  • Out-of-band monitoring only.

    Why it's wrong here

    Cannot block traffic.

  • Transparent inline without failover.

    Why it's wrong here

    Single point of failure.

  • Reverse proxy with active-passive clustering.

    Why it's wrong here

    Active-passive introduces failover delay; inline clustering is better.

About these practice questions

Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.