Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Which THREE security controls should you implement to protect a web application against common OWASP Top 10 vulnerabilities?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Input validation on all user inputs

Input validation on all user inputs (B) is correct because it directly mitigates injection flaws such as SQL injection, command injection, and cross-site scripting (XSS) by rejecting or sanitizing untrusted data before it reaches interpreters or the browser. Content Security Policy (CSP) headers (C) are correct because they restrict which scripts, styles, and other resources the browser may load, providing defense-in-depth against XSS and data injection attacks listed in the OWASP Top 10. A Web Application Firewall (WAF) (D) is correct because it inspects HTTP/HTTPS traffic and blocks common attack patterns like SQLi, XSS, and path traversal, offering a compensating control for vulnerabilities that may not yet be patched in the application. Role-Based Access Control (A) and Multi-factor authentication (E) are valuable identity and access management controls, but they address authentication and authorization concerns rather than the broad set of injection, misconfiguration, and client-side vulnerabilities targeted by the OWASP Top 10, so they are not among the three required controls here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-Based Access Control (RBAC)

    Why it's wrong here

    Role-Based Access Control (RBAC) governs what authenticated users can do within a system by assigning permissions to roles, but it does not analyze the content of requests or application logic. Even a perfectly implemented RBAC system will still pass a malicious SQL payload or XSS script if the requesting role happens to be authorized for that endpoint. It protects against horizontal privilege escalation, not against application-layer attacks like injection or cross-site scripting, so it cannot fulfill the security need in question.

  • ✓

    Input validation on all user inputs

    Why this is correct

    Input validation is a secure-coding control that rejects or sanitizes any user-supplied data that does not conform to expected formats, types, or lengths before the application processes it. By applying allowlist patterns and output encoding, it prevents malicious payloads from being interpreted as executable code, directly thwarting SQL injection, command injection, and stored/reflected XSS. It must be applied both on the client for UX and, critically, on the server as the authoritative enforcement point, and it is the first line of defense against the OWASP Top 10.

  • ✓

    Content Security Policy (CSP) headers

    Why this is correct

    Content Security Policy (CSP) is an HTTP response header that instructs the browser to only load, execute, or render resources from explicitly allowed origins, effectively blocking injected inline scripts and event handlers that would otherwise execute as XSS. By default, CSP can disable inline JavaScript, eval(), and unknown external sources, so even if an attacker injects a script tag into the DOM, the browser will refuse to execute it. It is a defense-in-depth layer that complements input validation by containing the blast radius of a successful injection.

  • ✓

    Web Application Firewall (WAF)

    Why this is correct

    A Web Application Firewall (WAF) is a network layer or cloud service that intercepts and inspects all HTTP/S traffic in real time, applying rule sets such as the OWASP Core Rule Set to block malicious requests before they reach the application server. It can identify and stop common attack signatures, including SQLi, XSS, and path traversal, without requiring source code changes. However, it operates on known patterns and heuristics, so it can be bypassed with obfuscation or zero-day payloads, making it a critical but not sufficient control on its own.

  • ✗

    Multi-factor authentication (MFA)

    Why it's wrong here

    Multi-factor authentication (MFA) strengthens the authentication step by requiring two or more verification factors, such as a password, a hardware token, or a biometric, to prove a user's identity. It drastically reduces the risk of account takeover from stolen credentials, but it does nothing to inspect or validate the payloads that an authenticated user submits to the application. Because OWASP Top 10 vulnerabilities like injection and XSS exist independent of identity, MFA is an identity security control, not a direct defense against application-layer attacks.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.