nerdexam
CompTIA

CV0-004 · Question #220

A cross-site request forgery vulnerability exploited a web application that was hosted in a public laaS network. A security engineer determined that deploying a WAF in blocking mode at a CDN would pre

Sign in or unlock CV0-004 to reveal the answer and full explanation for question #220. The question stem and answer options stay visible for context.

Security

Question

A cross-site request forgery vulnerability exploited a web application that was hosted in a public laaS network. A security engineer determined that deploying a WAF in blocking mode at a CDN would prevent the application from being exploited again. However, a week after implementing the WAF, the application was exploited again. Which of the following should the security engineer do to make the WAF control effective?

Options

  • AConfigure the DDoS protection on the CDN.
  • BInstall endpoint protection software on the VMs
  • CAdd an ACL to the VM subnet.
  • DDeploy an IDS on the laaS network.

Unlock CV0-004 to see the answer

You've previewed enough free CV0-004 questions. Unlock CV0-004 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#WAF#ACL#Application Security#Cloud Security
Full CV0-004 Practice