Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: A company has implemented a new web application…

A company has implemented a new web application firewall (WAF) and wants to test its effectiveness. Which of the following testing methods would provide the MOST accurate assessment?

⚠ Common exam trap

Test-takers frequently choose Option D (automated scanner with WAF enabled) thinking it tests the WAF in a live environment, but they overlook that automated scanners typically do not attempt sophisticated bypass techniques and may be blocked, giving a false sense of security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a penetration test that includes attempts to bypass the WAF.

A penetration test that actively attempts to bypass the WAF provides the most accurate assessment because it simulates a real attacker's behavior, testing the WAF's ability to detect and block evasion techniques such as HTTP parameter pollution, encoding obfuscation, and SQL injection payload splitting. This method validates the WAF's effectiveness under realistic adversarial conditions, revealing gaps that passive or disabled-state testing cannot uncover.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct a penetration test that includes attempts to bypass the WAF.

    Why this is correct

    Conducting a penetration test that specifically includes attempts to bypass the WAF is the most effective method because it simulates real-world attacker behavior. Skilled penetration testers employ various evasion techniques, such as encoding, obfuscation, and exploiting WAF logic flaws, to circumvent the WAF's defenses. This approach provides a realistic assessment of the WAF's configuration, rule sets, and overall resilience against sophisticated, targeted attacks, revealing its true protective capabilities.

  • Perform a vulnerability scan on the web application with the WAF disabled.

    Why it's wrong here

    Performing a vulnerability scan on the web application with the WAF disabled fundamentally fails to assess the WAF's effectiveness. While this might identify underlying vulnerabilities within the application itself, it provides no insight into whether the WAF is correctly configured to detect, block, or mitigate those specific threats when active. The primary objective is to evaluate the WAF as a security control, which necessitates its operational presence during testing.

  • Review the WAF logs for any blocked attacks.

    Why it's wrong here

    Reviewing WAF logs for blocked attacks is a reactive monitoring activity that shows what the WAF has already successfully detected and prevented based on its current rules and known attack signatures. However, it does not proactively test the WAF's robustness against novel attack vectors, zero-day exploits, or sophisticated evasion techniques that might not yet be present in its threat intelligence or behavioral models. This method provides historical data rather than a forward-looking assessment of its resilience against evolving threats.

  • Run an automated web application scanner against the application with the WAF enabled.

    Why it's wrong here

    Running an automated web application scanner against the application with the WAF enabled is insufficient for a comprehensive WAF effectiveness test. Automated scanners typically use predictable attack patterns and payloads that WAFs are often specifically tuned to detect, making them less effective at identifying advanced bypass techniques. These tools lack the adaptive intelligence and creative problem-solving capabilities of a human attacker who can modify payloads, encode data, or exploit logical flaws to circumvent WAF defenses.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.