Courseiva
Network Security →hardMultiple Choice

ISC2 CC Network Security Practice Question

An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?

⚠ Common exam trap

The trap is conflating a general-purpose IPS with a WAF — candidates pick IPS because it 'prevents' attacks, but the question specifically targets HTTP application-layer protection, which is the WAF's specialized domain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WAF

A Web Application Firewall (WAF) operates at Layer 7 and inspects HTTP/HTTPS requests specifically to detect and block web application attacks such as SQL injection, XSS, and malicious payloads. It is purpose-built to understand HTTP semantics (headers, cookies, parameters, body) and apply rules like OWASP ModSecurity Core Rule Set. This directly matches the requirement to prevent malicious HTTP requests targeting a web application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NIDS

    Why it's wrong here

    NIDS passively monitors copies of network traffic and raises alerts; it cannot block or prevent malicious HTTP requests reaching the web application. It is tempting because NIDS detects web attacks, but detection without inline prevention is the wrong capability when the requirement is to stop the requests.

  • ✗

    HIDS

    Why it's wrong here

    HIDS runs on individual hosts, monitoring local files, logs and processes; it does not inspect inbound HTTP requests to a web application. It is tempting because HIDS detects intrusions, but its scope is host-level activity, not the network-facing HTTP traffic the scenario requires blocking.

  • ✓

    WAF

    Why this is correct

    A Web Application Firewall inspects HTTP and HTTPS request content, applying signatures and rules to detect and block injection, cross-site scripting and similar attacks. Network firewalls filter by port and address only, so they cannot inspect application-layer payloads.

  • ✗

    IPS

    Why it's wrong here

    An IPS inspects traffic and can block malicious requests, but it operates across protocols and signatures rather than parsing HTTP semantics, so it cannot reliably detect application-layer attacks such as SQL injection or XSS. A WAF is purpose-built for HTTP request inspection. IPS suits blocking network-layer exploits and known attack signatures.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.