Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard

A cybersecurity team is performing a penetration test against a cloud-native application. During their reconnaissance phase, they discover that one of the application's API endpoints is vulnerable to SQL injection and cross-site scripting (XSS) attacks. To mitigate these specific threats at the edge of the network before they reach the application, which cloud security technology should the team recommend?

  1. ACloud Security Posture Management (CSPM)
  2. BCloud Workload Protection Platform (CWPP)
  3. CWeb Application Firewall (WAF)
  4. DNetwork Access Control List (NACL)
Show answer & explanation

Correct answer: C. Web Application Firewall (WAF)

A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection and XSS by filtering HTTP/S traffic at the application layer (Layer 7) before it reaches the application server, making it ideal for mitigating these threats at the network edge.

Why the other options are wrong

  • A. CSPM monitors configuration and compliance, not real-time application-layer attack detection and blocking.
  • B. CWPPs protect workloads (VMs, containers) at a deeper level, but a WAF is the primary 'edge' defense for web application-specific attacks.
  • D. NACLs operate at the network layer (Layer 4) and cannot detect application-layer attacks like SQL injection or XSS.

Web Application Firewall (WAF)

A security solution that monitors, filters, and blocks HTTP traffic to and from a web application, protecting against common web-based attacks like SQL injection and XSS.

  • Operates at the application layer (Layer 7)
  • Protects against specific web exploits
  • Deployed at the edge of the network

Memory trick: WAF is your web app's personal bodyguard.

More Cloud Security questions