Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 5Objective 2

Web Application Firewall (WAF) and OWASP Top Ten CSE Practice Questions (Page 2)

Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.

65questions here
13free pages
16concepts

Questions 6–10

  1. 6foundation · easy

    Which type of traffic does a Web Application Firewall (WAF) primarily inspect?

    Select an answer first
  2. 7application · medium

    A web application recently suffered a SQL injection attack via a login form. The security team has deployed a WAF and wants to block similar attacks while allowing legitimate login attempts. Which WAF rule configuration should they implement?

    Select an answer first
  3. 8expert · hard

    A company's SOC is overwhelmed by WAF alerts, most of which are false positives. They are missing real attacks because the alert volume is too high. The SOC wants to reduce alert noise while ensuring critical attacks are still detected. What is the best approach?

    Select an answer first
  4. 9foundation · easy

    Which WAF rule action would you use to allow traffic from a known good IP address while still monitoring for attacks?

    Select an answer first
  5. 10expert · hard

    A web application accepts XML from partners, and the security team has deployed a WAF. The WAF is blocking legitimate XML that contains a DOCTYPE declaration used for entity expansion. The team wants to block XXE attacks without breaking legitimate XML. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.