Courseiva
easyMultiple ChoiceObjective-mapped

CRISC The primary risk if the WAF is misconfigured? Practice Question

Exhibit

Refer to the exhibit.

Exhibit: Architecture diagram description:
An e-commerce web application consists of a web server, application server, and database server in separate subnets. A WAF (Web Application Firewall) is placed in front of the web server. The web server communicates with the application server on port 8080, and the application server communicates with the database on port 3306.

What is the primary risk if the WAF is misconfigured?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SQL injection attacks

A Web Application Firewall (WAF) is designed to filter and monitor HTTP traffic to and from a web application, protecting against common web exploits like SQL injection. If misconfigured, the WAF may fail to block SQL injection attempts, leaving the application vulnerable. While unauthorized database access (B) and denial of service (C) could be consequences, the primary risk directly associated with WAF misconfiguration is exposure to SQL injection attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SQL injection attacks

    Why this is correct

    WAF misconfiguration increases vulnerability to web attacks.

  • Unauthorized database access

    Why it's wrong here

    This may result from SQL injection but is a secondary effect.

  • Denial of service

    Why it's wrong here

    DoS is possible but not the primary risk from WAF misconfiguration.

  • Network segmentation failure

    Why it's wrong here

    Misconfigured WAF does not directly affect segmentation.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.