CV0-004 · Question #220
A cross-site request forgery vulnerability exploited a web application that was hosted in a public laaS network. A security engineer determined that deploying a WAF in blocking mode at a CDN would pre
Sign in or unlock CV0-004 to reveal the answer and full explanation for question #220. The question stem and answer options stay visible for context.
Question
A cross-site request forgery vulnerability exploited a web application that was hosted in a public laaS network. A security engineer determined that deploying a WAF in blocking mode at a CDN would prevent the application from being exploited again. However, a week after implementing the WAF, the application was exploited again. Which of the following should the security engineer do to make the WAF control effective?
Options
- AConfigure the DDoS protection on the CDN.
- BInstall endpoint protection software on the VMs
- CAdd an ACL to the VM subnet.
- DDeploy an IDS on the laaS network.
Unlock CV0-004 to see the answer
You've previewed enough free CV0-004 questions. Unlock CV0-004 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.