mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: A company has implemented a new web application…
A company has implemented a new web application firewall (WAF) and wants to test its effectiveness. Which of the following testing methods would provide the MOST accurate assessment?
⚠ Common exam trap
Test-takers frequently choose Option D (automated scanner with WAF enabled) thinking it tests the WAF in a live environment, but they overlook that automated scanners typically do not attempt sophisticated bypass techniques and may be blocked, giving a false sense of security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a penetration test that includes attempts to bypass the WAF.
A penetration test that actively attempts to bypass the WAF provides the most accurate assessment because it simulates a real attacker's behavior, testing the WAF's ability to detect and block evasion techniques such as HTTP parameter pollution, encoding obfuscation, and SQL injection payload splitting. This method validates the WAF's effectiveness under realistic adversarial conditions, revealing gaps that passive or disabled-state testing cannot uncover.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a penetration test that includes attempts to bypass the WAF.
Why this is correct
Conducting a penetration test that specifically includes attempts to bypass the WAF is the most effective method because it simulates real-world attacker behavior. Skilled penetration testers employ various evasion techniques, such as encoding, obfuscation, and exploiting WAF logic flaws, to circumvent the WAF's defenses. This approach provides a realistic assessment of the WAF's configuration, rule sets, and overall resilience against sophisticated, targeted attacks, revealing its true protective capabilities.
- ✗
Perform a vulnerability scan on the web application with the WAF disabled.
Why it's wrong here
Performing a vulnerability scan on the web application with the WAF disabled fundamentally fails to assess the WAF's effectiveness. While this might identify underlying vulnerabilities within the application itself, it provides no insight into whether the WAF is correctly configured to detect, block, or mitigate those specific threats when active. The primary objective is to evaluate the WAF as a security control, which necessitates its operational presence during testing.
- ✗
Review the WAF logs for any blocked attacks.
Why it's wrong here
Reviewing WAF logs for blocked attacks is a reactive monitoring activity that shows what the WAF has already successfully detected and prevented based on its current rules and known attack signatures. However, it does not proactively test the WAF's robustness against novel attack vectors, zero-day exploits, or sophisticated evasion techniques that might not yet be present in its threat intelligence or behavioral models. This method provides historical data rather than a forward-looking assessment of its resilience against evolving threats.
- ✗
Run an automated web application scanner against the application with the WAF enabled.
Why it's wrong here
Running an automated web application scanner against the application with the WAF enabled is insufficient for a comprehensive WAF effectiveness test. Automated scanners typically use predictable attack patterns and payloads that WAFs are often specifically tuned to detect, making them less effective at identifying advanced bypass techniques. These tools lack the adaptive intelligence and creative problem-solving capabilities of a human attacker who can modify payloads, encode data, or exploit logical flaws to circumvent WAF defenses.
Go deeper
Related to this question
Learn chapter
Security Assessment and Testing
Key term
Web Application Firewall
A Web Application Firewall (WAF) is a security tool that monitors, filters, and blocks HTTP traffic to and from a web application to protect it from common attacks.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.