SC-100 Practice Question: Design security solutions for applications and data
Which THREE security controls should you implement to protect a web application against common OWASP Top 10 vulnerabilities?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Input validation on all user inputs
Input validation on all user inputs (B) is correct because it directly mitigates injection flaws such as SQL injection, command injection, and cross-site scripting (XSS) by rejecting or sanitizing untrusted data before it reaches interpreters or the browser. Content Security Policy (CSP) headers (C) are correct because they restrict which scripts, styles, and other resources the browser may load, providing defense-in-depth against XSS and data injection attacks listed in the OWASP Top 10. A Web Application Firewall (WAF) (D) is correct because it inspects HTTP/HTTPS traffic and blocks common attack patterns like SQLi, XSS, and path traversal, offering a compensating control for vulnerabilities that may not yet be patched in the application. Role-Based Access Control (A) and Multi-factor authentication (E) are valuable identity and access management controls, but they address authentication and authorization concerns rather than the broad set of injection, misconfiguration, and client-side vulnerabilities targeted by the OWASP Top 10, so they are not among the three required controls here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-Based Access Control (RBAC)
Why it's wrong here
Role-Based Access Control (RBAC) governs what authenticated users can do within a system by assigning permissions to roles, but it does not analyze the content of requests or application logic. Even a perfectly implemented RBAC system will still pass a malicious SQL payload or XSS script if the requesting role happens to be authorized for that endpoint. It protects against horizontal privilege escalation, not against application-layer attacks like injection or cross-site scripting, so it cannot fulfill the security need in question.
- ✓
Input validation on all user inputs
Why this is correct
Input validation is a secure-coding control that rejects or sanitizes any user-supplied data that does not conform to expected formats, types, or lengths before the application processes it. By applying allowlist patterns and output encoding, it prevents malicious payloads from being interpreted as executable code, directly thwarting SQL injection, command injection, and stored/reflected XSS. It must be applied both on the client for UX and, critically, on the server as the authoritative enforcement point, and it is the first line of defense against the OWASP Top 10.
- ✓
Content Security Policy (CSP) headers
Why this is correct
Content Security Policy (CSP) is an HTTP response header that instructs the browser to only load, execute, or render resources from explicitly allowed origins, effectively blocking injected inline scripts and event handlers that would otherwise execute as XSS. By default, CSP can disable inline JavaScript, eval(), and unknown external sources, so even if an attacker injects a script tag into the DOM, the browser will refuse to execute it. It is a defense-in-depth layer that complements input validation by containing the blast radius of a successful injection.
- ✓
Web Application Firewall (WAF)
Why this is correct
A Web Application Firewall (WAF) is a network layer or cloud service that intercepts and inspects all HTTP/S traffic in real time, applying rule sets such as the OWASP Core Rule Set to block malicious requests before they reach the application server. It can identify and stop common attack signatures, including SQLi, XSS, and path traversal, without requiring source code changes. However, it operates on known patterns and heuristics, so it can be bypassed with obfuscation or zero-day payloads, making it a critical but not sufficient control on its own.
- ✗
Multi-factor authentication (MFA)
Why it's wrong here
Multi-factor authentication (MFA) strengthens the authentication step by requiring two or more verification factors, such as a password, a hardware token, or a biometric, to prove a user's identity. It drastically reduces the risk of account takeover from stolen credentials, but it does nothing to inspect or validate the payloads that an authenticated user submits to the application. Because OWASP Top 10 vulnerabilities like injection and XSS exist independent of identity, MFA is an identity security control, not a direct defense against application-layer attacks.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.