CompTIA Security+ (SY0-701)Security OperationsEasy

A company wants to protect a public-facing e-commerce web application from SQL injection and cross-site scripting attacks without modifying the application's source code. Which tool should be deployed?

  1. AHost-based firewall
  2. BWeb application firewall
  3. CNetwork-based intrusion prevention system
  4. DVPN concentrator
Show answer & explanation

Correct answer: B. Web application firewall

A web application firewall (WAF) inspects HTTP/HTTPS traffic at the application layer and can detect and block SQL injection and XSS payloads before they reach the application, without requiring code changes.

Why the other options are wrong

  • A. A host-based firewall filters traffic to/from a single host based on ports/IPs, not web-layer payloads.
  • C. A network IPS inspects broader network traffic but lacks the deep HTTP-parameter inspection a WAF provides.
  • D. A VPN concentrator manages encrypted remote-access tunnels and has no role in filtering web attacks.

Web Application Firewall (WAF)

A security appliance or service that filters, monitors, and blocks HTTP/HTTPS traffic to protect web applications from application-layer attacks.

  • Blocks SQL injection, XSS, and other OWASP Top 10 threats
  • Operates at Layer 7 (application layer)
  • Can be deployed inline, as a reverse proxy, or cloud-based
  • Complements, not replaces, secure coding practices

Memory trick: WAF Watches Application Fields for injected junk

More Security Operations questions