CompTIA Cloud+ (CV0-004)SecurityEasy
A cloud security engineer is implementing a solution to protect against common web exploits such as SQL injection and cross-site scripting (XSS) for a public-facing web application deployed on a cloud platform. The solution needs to operate at the application layer (Layer 7 of the OSI model). Which security service should be configured?
- AIntrusion Detection System (IDS)
- BNetwork Security Group (NSG)
- CWeb Application Firewall (WAF)
- DVirtual Private Network (VPN)
Show answer & explanationAnswer & explanation
Correct answer: C. Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to protect web applications from common web exploits like SQL injection and XSS by inspecting HTTP/HTTPS traffic at Layer 7 of the OSI model.
Why the other options are wrong
- A. An IDS detects suspicious activity but typically doesn't block it in real-time at the application layer for specific web exploits; a WAF is more focused and active in prevention.
- B. Network Security Groups (NSGs) operate at Layer 3/4 and provide basic firewalling based on IP addresses and ports, not application-layer attack detection.
- D. A VPN provides encrypted communication tunnels, primarily for secure data transmission, not for detecting and blocking web application exploits.
Web Application Firewall (WAF)
A WAF is a specific type of firewall that protects web applications from common web exploits by filtering and monitoring HTTP traffic between a web application and the internet.
- Operates at Layer 7 (application layer) of the OSI model.
- Protects against attacks like SQL injection, XSS, and CSRF.
- Can be deployed as a network appliance, host-based plugin, or cloud service.
Memory trick: WAFs guard web apps from XSS and SQL attacks.