CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is evaluating a new cloud-native application that exposes several APIs for internal and external consumption. The architect aims to protect these APIs from common web-based attacks such as SQL injection, XSS, and DDoS, while also providing API authentication, authorization, and rate limiting. The solution should be scalable and easily integrated into the CI/CD pipeline. Which security component is best suited for this purpose?
- ASecurity Information and Event Management (SIEM)
- BNetwork Intrusion Detection System (NIDS)
- CWeb Application Firewall (WAF)
- DHost-based Intrusion Prevention System (HIPS)
Show answer & explanationAnswer & explanation
Correct answer: C. Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to protect web applications and APIs from common attacks like SQL injection, XSS, and other OWASP Top 10 vulnerabilities. Modern WAFs also offer API authentication, authorization, and rate limiting capabilities, making them ideal for securing API endpoints in a scalable, cloud-native environment.
Why the other options are wrong
- A. SIEM aggregates logs for analysis and threat detection but does not directly protect APIs from attacks or provide real-time blocking.
- B. NIDS monitors network traffic for anomalies but doesn't actively block application-layer attacks or provide API-specific authentication/authorization.
- D. HIPS protects individual hosts from malware and unauthorized activity but doesn't provide centralized API protection or web application-specific attack mitigation.
Web Application Firewall (WAF)
A security solution that monitors, filters, and blocks HTTP traffic to and from a web application or API. It protects against common web vulnerabilities such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF).
- Protects web applications and APIs.
- Filters malicious HTTP/S traffic.
- Mitigates OWASP Top 10 attacks.
- Can provide API authentication, authorization, rate limiting.
Memory trick: WAF is like a bouncer for your APIs, checking every request for trouble.