ISC2 CC Network Security Practice Question
An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?
⚠ Common exam trap
The trap is conflating a general-purpose IPS with a WAF — candidates pick IPS because it 'prevents' attacks, but the question specifically targets HTTP application-layer protection, which is the WAF's specialized domain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WAF
A Web Application Firewall (WAF) operates at Layer 7 and inspects HTTP/HTTPS requests specifically to detect and block web application attacks such as SQL injection, XSS, and malicious payloads. It is purpose-built to understand HTTP semantics (headers, cookies, parameters, body) and apply rules like OWASP ModSecurity Core Rule Set. This directly matches the requirement to prevent malicious HTTP requests targeting a web application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NIDS
Why it's wrong here
NIDS passively monitors copies of network traffic and raises alerts; it cannot block or prevent malicious HTTP requests reaching the web application. It is tempting because NIDS detects web attacks, but detection without inline prevention is the wrong capability when the requirement is to stop the requests.
- ✗
HIDS
Why it's wrong here
HIDS runs on individual hosts, monitoring local files, logs and processes; it does not inspect inbound HTTP requests to a web application. It is tempting because HIDS detects intrusions, but its scope is host-level activity, not the network-facing HTTP traffic the scenario requires blocking.
- ✓
WAF
Why this is correct
A Web Application Firewall inspects HTTP and HTTPS request content, applying signatures and rules to detect and block injection, cross-site scripting and similar attacks. Network firewalls filter by port and address only, so they cannot inspect application-layer payloads.
- ✗
IPS
Why it's wrong here
An IPS inspects traffic and can block malicious requests, but it operates across protocols and signatures rather than parsing HTTP semantics, so it cannot reliably detect application-layer attacks such as SQL injection or XSS. A WAF is purpose-built for HTTP request inspection. IPS suits blocking network-layer exploits and known attack signatures.
Go deeper
Related to this question
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.