CompTIA SecurityX (CAS-005)Security ArchitectureEasy

A security architect is designing a new cloud-native application that exposes several APIs for external partners. The application needs to validate incoming API requests for proper formatting, enforce rate limiting to prevent abuse, and block known malicious payloads and SQL injection attempts before requests reach the backend services. Which type of security control should be implemented in front of the API endpoints?

  1. ANetwork Access Control List (NACL)
  2. BVirtual Private Cloud (VPC)
  3. CWeb Application Firewall (WAF)
  4. DIntrusion Detection System (IDS)
Show answer & explanation

Correct answer: C. Web Application Firewall (WAF)

A Web Application Firewall (WAF) is specifically designed to protect web applications and APIs from common web-based attacks like SQL injection, cross-site scripting, and other OWASP Top 10 threats. It can also enforce rate limiting and validate request formatting.

Why the other options are wrong

  • A. NACLs operate at the subnet level and provide stateless packet filtering, which is too coarse-grained for application-layer attacks like SQL injection.
  • B. VPC provides network isolation in the cloud but does not offer application-layer protection or API specific validation.
  • D. An IDS detects malicious activity but typically does not block it in real-time or perform application-layer validation and rate limiting.

Web Application Firewall (WAF)

A security solution that protects web applications and APIs from common web-based attacks by filtering, monitoring, and blocking malicious HTTP/HTTPS traffic.

  • Operates at Layer 7 (application layer) of the OSI model.
  • Protects against OWASP Top 10 vulnerabilities (e.g., SQL injection, XSS).
  • Can enforce rate limiting, access control, and API security policies.

Memory trick: WAF: Your Web App's First Line of Defense.

More Security Architecture questions