CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is evaluating a new cloud-native application that exposes several APIs to external partners. The architect needs to protect these APIs from common web-based attacks such as SQL injection, cross-site scripting (XSS), and malicious bots, while also providing rate limiting and API security analytics. Which security control would be most effective for this purpose?
- ANetwork Access Control List (NACL)
- BSecurity Group
- CVirtual Private Cloud (VPC)
- DWeb Application Firewall (WAF)
Show answer & explanationAnswer & explanation
Correct answer: D. Web Application Firewall (WAF)
A Web Application Firewall (WAF) operates at the application layer and is specifically designed to protect web applications and APIs from common web-based attacks like SQL injection and XSS. Modern WAFs also offer features like rate limiting and API security analytics.
Why the other options are wrong
- A. NACLs operate at the subnet level and provide stateless packet filtering based on IP and port, not protection against application-layer attacks.
- B. Security Groups provide stateful packet filtering at the instance level, similar to a host firewall, but they do not understand application-layer attack patterns.
- C. A VPC provides network isolation in the cloud but does not offer application-layer protection against specific web attacks.
Web Application Firewall (WAF)
A Web Application Firewall (WAF) is a security solution that monitors and filters HTTP/HTTPS traffic between a web application and the Internet. It protects web applications from various attacks, including cross-site scripting (XSS), SQL injection, and other OWASP Top 10 vulnerabilities.
- Operates at the application layer (Layer 7 of OSI model).
- Protects against common web-based attacks.
- Can enforce security policies, perform rate limiting, and provide API security.
- Can be network-based, host-based, or cloud-based.
Memory trick: WAF Watches Web Attacks Fiercely.