CompTIA Cloud+ (CV0-004)SecurityEasy

A cloud security engineer is implementing a solution to protect against common web exploits such as SQL injection and cross-site scripting (XSS) for a public-facing web application deployed on a cloud platform. The solution needs to operate at the application layer (Layer 7 of the OSI model). Which security service should be configured?

  1. AIntrusion Detection System (IDS)
  2. BNetwork Security Group (NSG)
  3. CWeb Application Firewall (WAF)
  4. DVirtual Private Network (VPN)
Show answer & explanation

Correct answer: C. Web Application Firewall (WAF)

A Web Application Firewall (WAF) is specifically designed to protect web applications from common web exploits like SQL injection and XSS by inspecting HTTP/HTTPS traffic at Layer 7 of the OSI model.

Why the other options are wrong

  • A. An IDS detects suspicious activity but typically doesn't block it in real-time at the application layer for specific web exploits; a WAF is more focused and active in prevention.
  • B. Network Security Groups (NSGs) operate at Layer 3/4 and provide basic firewalling based on IP addresses and ports, not application-layer attack detection.
  • D. A VPN provides encrypted communication tunnels, primarily for secure data transmission, not for detecting and blocking web application exploits.

Web Application Firewall (WAF)

A WAF is a specific type of firewall that protects web applications from common web exploits by filtering and monitoring HTTP traffic between a web application and the internet.

  • Operates at Layer 7 (application layer) of the OSI model.
  • Protects against attacks like SQL injection, XSS, and CSRF.
  • Can be deployed as a network appliance, host-based plugin, or cloud service.

Memory trick: WAFs guard web apps from XSS and SQL attacks.

More Security questions