A city WAF blocks several obvious SQLi probe strings during testing. What is the most appropriate next methodology choice?
Select an answer to reveal the explanation.
Short Explanation
A bouncer at the door does not mean the kitchen locks are solid. When a WAF swats obvious SQLi noise, keep going — IDOR, logic bugs, and misconfigs often live past the filter. Ending early or silently turning the WAF off is not how CPTS-style web testing works.
Full Explanation
Web application assessments must cover authentication, authorization, business logic, and configuration issues in addition to injection classes. A WAF that blocks naive payloads does not prove absence of deeper flaws and should not halt testing. Unauthorized WAF disablement violates change and RoE norms. Methodologically, testers persist with high-value manual checks rather than treating evasion games as the sole objective.