CompTIA Cloud+ (CV0-004)DeploymentHard
A cloud engineer is designing a new cloud environment for a financial institution. Due to stringent regulatory compliance requirements (e.g., PCI DSS, HIPAA), all network traffic, including internal communication between virtual machines, must be inspected and logged. Additionally, the institution requires the ability to enforce granular, layer 7 security policies for web applications. Which network security component is best suited for both deep packet inspection and application-level filtering?
- AVirtual Private Network (VPN)
- BWeb Application Firewall (WAF)
- CNetwork Access Control List (NACL)
- DSecurity Group
Show answer & explanationAnswer & explanation
Correct answer: B. Web Application Firewall (WAF)
A Web Application Firewall (WAF) operates at Layer 7 (application layer) and is specifically designed to protect web applications from common attacks by inspecting HTTP/S traffic. It allows for granular, application-level filtering and logging, which aligns with the need for deep packet inspection and stringent compliance for web applications.
Why the other options are wrong
- A. A VPN provides secure, encrypted tunnels for network traffic but does not perform deep packet inspection or application-level filtering.
- C. NACLs operate at the subnet level (Layer 3/4) and are stateless, offering basic packet filtering but no deep inspection or Layer 7 capabilities.
- D. Security Groups operate at the instance level (Layer 3/4) and are stateful, but also lack deep packet inspection and Layer 7 capabilities.
Web Application Firewall (WAF)
A security solution that protects web applications from common web exploits and vulnerabilities by filtering and monitoring HTTP traffic.
- Operates at Layer 7 (application layer).
- Provides deep packet inspection of HTTP/S requests.
- Protects against SQL injection, XSS, and other web attacks.
Memory trick: WAF: Web App's Fine-grained Filter.