
EC-CouncilCloud Security Essentials
Domain 5Objective 2
Web Application Firewall (WAF) and OWASP Top Ten CSE Practice Questions (Page 1)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
65questions here
13free pages
16concepts
Questions 1–5
- 1
A company runs a global web application behind a CDN and wants to apply consistent WAF policies across all edge locations. They also want to centralize WAF logs in a single dashboard. What is the most efficient way to achieve this?
Select an answer first - 2
A company's web application uses a third-party library with a known remote code execution vulnerability. The vendor has not yet released a patch. The security team wants to use a WAF to reduce the risk. Which approach is most appropriate?
Select an answer first - 3
A company's web application has a broken access control vulnerability where users can access other users' accounts by changing an ID in the URL. The application team cannot fix the code for several weeks. The security team wants to use the WAF to mitigate this. What is the most effective WAF-based mitigation?
Select an answer first - 4
A company's WAF is blocking a legitimate API client that sends requests with a custom header that matches a WAF rule signature. The API client is used by a critical business partner and cannot be changed. The security team wants to allow this client while maintaining protection for other clients. What is the best approach?
Select an answer first - 5
A company runs a customer-facing web application in a public cloud. The security team wants to inspect all incoming HTTPS traffic for SQL injection and XSS before it reaches the application, without managing any WAF infrastructure. They also need the WAF to automatically scale during peak traffic. Which deployment model best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.